<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xml:lang="ru">
	<channel>
		<title>Еженедельник OSM</title>
		<link>https://hugo.weeklyosm.eu/ru/</link>
		<description>Recent content on Еженедельник OSM</description>
		<generator>Hugo</generator>
		<language>ru</language>
		
			<managingEditor>info@weeklyosm.eu (weeklyteam)</managingEditor>
		
		
			<webMaster>info@weeklyosm.eu (weeklyteam)</webMaster>
		
		
		<image>
			<url>https://hugo.weeklyosm.eu/icons/favicon-32x32.png</url>
			<title>Еженедельник OSM</title>
			<link>https://hugo.weeklyosm.eu/ru/</link>
		</image>
		
			<lastBuildDate>Thu, 25 Jun 2026 00:00:00 +0000</lastBuildDate>
		
			<atom:link href="https://hugo.weeklyosm.eu/ru/feed.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Еженедельник OSM 832</title>
				<link>https://hugo.weeklyosm.eu/ru/archives/0832/</link>
				<pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/archives/0832/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/07/832.jpg" alt="Еженедельник OSM 832" /> 25.06.2026-01.07.2026
Картографирование Идёт голосование:
railway=balise — стационарные транспондеры, устанавливаемые на рельсах и взаимодействующих с бортовыми компьютерами ж/д составов для передачи местоположения и эксплуатационной информации, до 10 июля.
Картографические акции 24 июня на севере Венесуэлы произошло два сильных землетрясения. HOTOSM уже добавил в менеджер задач проекты для сбора и обмена информацией по ликвидации последствий чрезвычайной ситуации. Текущие мероприятия включают в себя сбор спутниковых снимков до и после землетрясения, координацию картографирования с привлечением широкой общественности, а также проведение полевых кампаний по документированию повреждённых сооружений с указанием их местоположения, фотографиями и видеозаписями. Сообщество [1] theobcl18 разработал интерактивную карту-глобус «Coupe du Monde 2026 Globe 3D» , на которой отображены стадионы всех 16 стадионов Чемпионата мира по футболу, а также 48 стран-участниц. На ней также есть подробная информация о каждой команде, вместимость каждого стадиона и результаты последних матчей.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/07/832.jpg" alt="Еженедельник OSM 832" /></p> <p>25.06.2026-01.07.2026</p>
<h2 id="картографирование">Картографирование</h2>
<ul>
<li>
<p><a id="wn832_34901"></a>
   Идёт голосование:</p>
</li>
<li>
<p><a href="https://wiki.openstreetmap.org/wiki/Proposal%3ATag%3Arailway%3Dbalise"><code>railway=balise</code></a> — стационарные транспондеры, устанавливаемые на рельсах и взаимодействующих с бортовыми компьютерами ж/д составов для передачи местоположения и эксплуатационной информации, до 10 июля.</p>
</li>
</ul>
<h2 id="картографические-акции">Картографические акции</h2>
<ul>
<li><a id="wn832_34897"></a>
   24 июня на севере Венесуэлы произошло <a href="https://ru.wikipedia.org/wiki/%D0%97%D0%B5%D0%BC%D0%BB%D0%B5%D1%82%D1%80%D1%8F%D1%81%D0%B5%D0%BD%D0%B8%D1%8F_%D0%B2_%D0%92%D0%B5%D0%BD%D0%B5%D1%81%D1%83%D1%8D%D0%BB%D0%B5_%5C%282026%5C%29">два сильных землетрясения</a>. HOTOSM уже <a href="https://www.hotosm.org/en/projects/2026-venezuela-earthquake-response/">добавил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в менеджер задач проекты для сбора и обмена информацией по ликвидации последствий чрезвычайной ситуации. Текущие мероприятия включают в себя сбор спутниковых снимков до и после землетрясения, координацию картографирования с привлечением широкой общественности, а также проведение полевых кампаний по документированию повреждённых сооружений с указанием их местоположения, фотографиями и видеозаписями.</li>
</ul>
<h2 id="сообщество">Сообщество</h2>
<ul>
<li>
<p><a id="wn832_34926"></a>
   [1] theobcl18 разработал интерактивную карту-глобус «<a href="https://theobcl18.github.io/SiteWeb-Portfolio/projects_list/Projet-WebSIG-Coupe-du-Monde-2026.html">Coupe du Monde 2026 Globe 3D</a>»<figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, на которой отображены стадионы всех 16 стадионов Чемпионата мира по футболу, а также 48 стран-участниц. На ней также есть подробная информация о каждой команде, вместимость каждого стадиона и результаты последних матчей.</p>
</li>
<li>
<p><a id="wn832_34893"></a>
   Паскаль Нейс <a href="https://neis-one.org/2026/06/checking-osm-notes-for-potentially-problematic-language/">изучил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, могут ли языковые модели помочь в анализе текста заметок на сайте OSM и выявлении проблемных формулировок (спама, раскрытия личной информации, оскорблений).</p>
</li>
<li>
<p><a id="wn832_34911"></a>
   Франйо Лукежич <a href="https://bf5.eu/post/osm/author-mapping/highway-steps/">продолжил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 работу над следующей эвристикой для работы в поле. В этот раз он рассказывает, как исследовать лестницы (<code>highway=steps</code>). Кроме того, он работает над <a href="https://bf5.eu/cookbooks/bfs-field-survey-heuristic/">сборником</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 всех существующих эвристик (в том числе и той, о которой мы <a href="https://weeklyosm.eu/ru/archives/18622#wn828_34749">сообщали</a> ранее).</p>
</li>
<li>
<p><a id="wn832_34913"></a>
   Биньям Деле <a href="https://www.linkedin.com/feed/update/urn:li:activity:7476350632925417472/">представил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 проект «Ambalay Maps» на недавней конференции «State of the Map Africa 2026».</p>
</li>
<li>
<p><a id="wn832_34881"></a>
   Матеуш Конечны <a href="https://community.openstreetmap.org/t/is-there-anything-wrong-with-waterway-stream-end-inclusion-into-id-presets-is-planned/144894">поинтересовался</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, почему добавление тега <code>waterway=stream_end</code> в число пресетов iD было отменено.</p>
</li>
<li>
<p><a id="wn832_34891"></a>
   Кристоф Хорманн <a href="https://imagico.de/blog/en/mapping-of-populated-places-in-openstreetmap/">рассказал</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 о несколько необычной ситуации, связанной с нанесением населённых пунктов на карту OpenStreetMap.</p>
</li>
<li>
<p><a id="wn832_34900"></a>
   Ракель Дезидерио Соуто поделилась в <a href="https://www.linkedin.com/posts/raquel-deziderio-souto-phd-28b9a752_weeklyosm-opendata-weeklyosm-ugcPost-7476668688478416896-XfbG/">LinkedIn</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/pt.svg"
      
      
    />

  </picture>
</figure>



<figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 и <a href="https://mastodon.social/@raquel_ivides_org/116823101488763130">Mastodon</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 видеозаписью своего <a href="https://pretalx.com/state-of-the-map-africa-2025/talk/XEDHMP/">выступления</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 «weeklyOSM-stats: анализ новостей в weeklyOSM за последние десять лет с помощью PostgreSQL» на конференции «State of the Map Africa 2026».</p>
</li>
<li>
<p><a id="wn832_34910"></a>
   Проект Geofabrik <a href="https://blog.geofabrik.de/index.php/2026/06/30/new-in-osm-inspector-turn-restrictions/">добавил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в <a href="https://tools.geofabrik.de/osmi/?view=turn_restrictions">OSM Inspector</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 функцию обзора действующих и неработающих ограничений направления движения и поворотов на перекрёстках.</p>
</li>
<li>
<p><a id="wn832_34883"></a>
   Килкенни <a href="https://community.openstreetmap.org/t/osint-osm/144877/">поделился</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2021/02/uk.svg"
      
      
    />

  </picture>
</figure>



, как собирать и проверять данные из открытых источников для картографирования небольших населённых пунктов на примере посёлка <a href="https://www.openstreetmap.org/#map=14/49.25755/24.49780">Букачёвцы</a> и близлежащих охраняемых природных территорий. Он продемонстрировал, как объединять данные из кадастра, сайтов местных сообществ, Викимедии, Википедии, Wayback Machine и других источников, не забывая при этом о необходимости соблюдения условий лицензирования.</p>
</li>
<li>
<p><a id="wn832_34903"></a>
   Silvi715 <a href="https://www.openstreetmap.org/user/Silvi715/diary/408944">рассказывает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



 о картографических мерах по предотвращению наводнений в Вилья-Моисес (город <a href="https://www.openstreetmap.org/node/198432657">Венадо-Туэрто</a>, Аргентина). В результате была создана <a href="https://umap.hotosm.org/en/map/mapa-del-barrio-esfuerzo-propio-asentamiento-villa_3111#17/-33.764530/-61.944941">uMap-карта</a>.</p>
</li>
<li>
<p><a id="wn832_34889"></a>
   9_tab написал пост <a href="https://www.openstreetmap.org/user/9_tab/diary/408971">«Супермаркеты Женевы от A до Z (или, вернее, от А до М)»</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



. В нём отмечается как широкий охват магазинов <a href="https://www.openstreetmap.org/#map=14/46.2050/6.1431">города</a>, так и несоответствия в определениях брендов по умолчанию (NSI) для Швейцарии.</p>
</li>
<li>
<p><a id="wn832_34885"></a>
   To55 <a href="https://wiki.openstreetmap.org/wiki/Talk:Key:addr:*#Issue_with_Romanian_apartment_block_addresses_%5C%28%22bloc%22_and_%22scara%22%5C%29">спросил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, как нанести на карту адреса квартир в Румынии.</p>
</li>
<li>
<p><a id="wn832_34907"></a>
   «Викиданные Тайвань» <a href="https://g0v.social/@wikidatataiwan/116814474819487240">анонсировало</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2020/08/zh-tw-black.svg"
      
      
    />

  </picture>
</figure>



 ежемесячный митап OpenStreetMap и Викиданных, который состоится 13 июля в районе Chongqing South Road (Чжунчжэн, Тайбэй). Вы можете <a href="https://www.wikidata.org/wiki/Wikidata:Events/Taiwan">посмотреть</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2020/08/zh-tw-black.svg"
      
      
    />

  </picture>
</figure>



 список мероприятий и <a href="https://www.wikidata.org/wiki/Wikidata:WikiProject_Taiwan">страницу</a> сообщества WikiProject Taiwan.</p>
</li>
</ul>
<h2 id="фонд-openstreetmap">Фонд OpenStreetMap</h2>
<ul>
<li><a id="wn832_34912"></a>
   Рабочая группа конференции «State of the Map» <a href="https://blog.openstreetmap.org/2026/06/30/state-of-the-map-2026-call-for-posters/">объявила</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 о приёме заявок на участие в выставке плакатов для SotM 2026, связанных с OSM и имеющих открытую лицензию. Срок подачи заявок — 31 июля. Формат — A0.</li>
</ul>
<h2 id="местные-отделения-osmf">Местные отделения OSMF</h2>
<ul>
<li><a id="wn832_34892"></a>
   Кристоф Хорманн <a href="https://imagico.de/blog/en/fossgis-membership-dues-the-end-of-the-story/">решил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 не продлевать своё членство в FOSSGIS в конце этого года из-за увеличения членских взносов.</li>
</ul>
<h2 id="события">События</h2>
<ul>
<li><a id="wn832_34888"></a>
   Хироюки Хорин из компании «Sakura Internet» (это спонсор инфраструктуры японского отделения Фонда OSM) опубликовал <a href="https://knowledge.sakura.ad.jp/49616/">подробный отчёт</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/ja.svg"
      
      
    />

  </picture>
</figure>



 о саммите Mappers Summit 2026, который состоялся 1 февраля одном из офисов компании. Юи Китамура, выступившая на мероприятии, поделилась материалами своей <a href="https://yui-kitamura.eng.pro/private/opensource/osm/20260201_mappers">презентации</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/ja.svg"
      
      
    />

  </picture>
</figure>



. Smellman <a href="https://osm.connpass.com/event/380259/presentation/">рассказал</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/ja.svg"
      
      
    />

  </picture>
</figure>



 о реализации сервера тайлов, а alt9800 выступил с докладом, посвящённым созданию скриншотов. Yuiseki сообщил, что они разработали <a href="https://scrapbox.io/yuiseki/AI%E3%81%A8%E5%85%B1%E3%81%AB%E7%B7%A8%E9%9B%86%E3%81%99%E3%82%8B%E3%80%81%E8%87%AA%E5%AE%85%E3%81%AB%E3%81%82%E3%82%8B%E6%83%91%E6%98%9F%E3%80%8C%E5%9C%B0%E7%90%83%E3%80%8D">утилиту</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/ja.svg"
      
      
    />

  </picture>
</figure>



 командной строки для ИИ-агентов, способную вызывать самостоятельно размещённые API Nominatim, TagInfo, Overpass и Valhalla.</li>
</ul>
<h2 id="oбразование">Oбразование</h2>
<ul>
<li><a id="wn832_34899"></a>
   Организация IVIDES DATA <a href="https://www.linkedin.com/posts/ivides-data_openstreetmap-opendata-openscrience-activity-7476412972144250880-ZX8d">опубликовала</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/pt.svg"
      
      
    />

  </picture>
</figure>



 четвёртый семинар из <a href="https://ivides.org/ciclo-oficinas-osm-2026">серии OSM 2026</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/pt.svg"
      
      
    />

  </picture>
</figure>



. В нём объясняется, как можно использовать KoboToolbox для создания и внедрения веб-форм с геолокацией, работающих в любом веб-браузере и на любом устройстве. Организаторы отмечают, что те, кто завершит серию семинаров до 17 июля, получат право на бесплатное наставничества на проектах совместного картографирования.</li>
</ul>
<h2 id="osm-в-науке">OSM в науке</h2>
<ul>
<li><a id="wn832_34879"></a>
   HeiGIT <a href="https://heigit.org/use-case-combining-openrouteservice-with-emission-model-data-to-visualize-emissions-along-a-route/">демонстрирует</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, как сервис «openrouteservice» можно сочетать с данными о дорогах из OpenStreetMap и данными эмиссии CO₂ и NO₂ от Федерального агентства по картографии и геодезии Германии.</li>
</ul>
<h2 id="карты">Карты</h2>
<ul>
<li>
<p><a id="wn832_34884"></a>
   Стиль «Versatiles Colorful» на сайте OpenStreetMap.org <a href="https://www.openstreetmap.org/#map=16/-6.78/39.20451&amp;layers=S">был заменён</a> на стиль SVWD03, <a href="https://www.openstreetmap.org/user/SomeoneElse/diary/407760">разработанный</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 SomeoneElse и основанный на <a href="https://shortbread-tiles.org/">«Shortbread»</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 — открытой схеме векторных тайлов.</p>
</li>
<li>
<p><a id="wn832_34915"></a>
   Фрэнсис Миранда <a href="https://ismif-municipiorio.streamlit.app/">создал</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/pt.svg"
      
      
    />

  </picture>
</figure>



 интерактивную веб-карту на основе OSM, Python и Streamlit, которая демонстрирует пространственное распределение индекса ISMIF, отражающего уязвимость школ к наводнениям. Индекс был рассчитан для школ, расположенных в Рио-де-Жанейро (Бразилия). Код <a href="https://github.com/CyberBantu/ISMIF_Schools">доступен</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/pt.svg"
      
      
    />

  </picture>
</figure>



<figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 на GitHub.</p>
</li>
<li>
<p><a id="wn832_34887"></a>
   Франсуа Андро <a href="https://www.linkedin.com/posts/francois-andrieux_rte-electricitaez-reseaux-share-7474840593156775936-towC/">рассказывает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



 о <a href="https://rte.smartblock.be/">THT</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



 — веб-карте, на которой отображается информация об энергетических ресурсах и инфраструктуре Франции. Сервис позволяет выбрать участок земли и быстро вычислить расстояние до ближайшей сети оператора <a href="https://en.wikipedia.org/wiki/R%C3%A9seau_de_Transport_d%27%C3%89lectricit%C3%A9">RTE</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 и его подстанций. Веб-карта использует OpenStreetMap.</p>
</li>
</ul>
<h2 id="osm-в-деле">OSM в деле</h2>
<ul>
<li><a id="wn832_34909"></a>
   <a href="https://mapfuel.ru">MapFuel.ru</a> и <a href="https://gdebenz.ru">GdeBENZ.ru</a> — краудсорсинговые платформы, на которых пользователи публикуют отчеты о наличии топлива на АЗС по всей России.</li>
</ul>
<h2 id="открытые-данные">Открытые данные</h2>
<ul>
<li><a id="wn832_34905"></a>
   Грант Слейтер <a href="https://en.osm.town/@Firefishy/116815844415714796">сообщил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, что он обновил сайт <a href="https://aerial.openstreetmap.org.za/">aerial.openstreetmap.org.za</a>, добавив на него свежие аэрофотоснимки, предоставленные Генеральным директоратом национальной геопространственной информации Южно-Африканской Республики. Значительно улучшена производительность сайта, оптимизирован процесс обновления данных, снимки доступны в редакторах iD и JOSM и имеют разрешение в 25 см.</li>
</ul>
<h2 id="программы">Программы</h2>
<ul>
<li>
<p><a id="wn832_34914"></a>
   Новое приложение <a href="https://play.google.com/store/apps/details?id=app.trufi.navigator">Trufi V5</a> для неформального транспорта в Кочабамбе (Боливия) <a href="https://www.trufi-association.org/trufi-app-v5-for-cochabamba/">позволяет загружать</a> данные OSM для использования в автономном режиме (ведь не у всех есть возможность постоянно находиться в сети).</p>
</li>
<li>
<p><a id="wn832_34886"></a>
   Korben (Мануэль Дорн) <a href="https://korben.info/en/os9map-openstreetmap-mac-os-9.html">сообщил</a>, что компания Yllan выпустила OS9Map — приложение, которое отображает карты OpenStreetMap, для Mac OS 9.</p>
</li>
<li>
<p><a id="wn832_34906"></a>
   Пьер Дандумон <a href="https://www.macg.co/macos/2026/06/os9map-des-cartes-openstreetmap-pour-les-power-macintosh-du-siecle-dernier-309433">опубликовал</a> книгу <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



, ► <a href="https://www-macg-co.translate.goog/macos/2026/06/os9map-des-cartes-openstreetmap-pour-les-power-macintosh-du-siecle-dernier-309433?_x_tr_sl=auto&amp;_x_tr_tl=RU"><figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/09/ru-green.svg"
      
      
    />

  </picture>
</figure>



</a> на сайте MacGeneration статью «OS9Map: карты OpenStreetMap для компьютеров Power Macintosh прошлого века», посвящённую OS9Map — клиенту Mastodon для MacOS 9 (а не для OS X Mavericks 10.9). О статье также <a href="https://social.macg.co/@macgeneration/116815588204189890">сообщалось</a> в Mastodon.</p>
</li>
<li>
<p><a id="wn832_34880"></a>
   В блоге OsmAnd <a href="https://osmand.net/blog/nautical-maps">рассказали</a> о режиме просмотра морских карт — функцию, предназначенную для планирования путешествий по воде, занятий водными видами спорта и ознакомления с объектами интереса, связанными с прибрежными районами. Этот инструмент предоставляет данные о глубине, информацию о морском дне, маяках, навигационных огнях, буях и сведения о фарватерах.</p>
</li>
<li>
<p><a id="wn832_34894"></a>
   Проект OSRM <a href="https://en.osm.town/@osrm/116828907734614233">обновил</a> требования для сборочного окружения. В качестве базовых дистрибутивов Linux теперь используются Debian 13 и Ubuntu 26.04 LTS, и компиляторы Clang 18 или GCC 14. Для сборки под Windows теперь используется Visual Studio 2025.</p>
</li>
<li>
<p><a id="wn832_34895"></a>
   Стив Виньо полностью <a href="https://nuxx.net/blog/2026/06/25/trailmaps-app-map-generator/">переработал</a> сайт trailmaps.app — карту, которая объединяет указатели на маршрутах и официальные карты маршрутов с данными OpenStreetMap. Вместо ведения отдельных карт платформа теперь использует систему генерации карт, которая автоматически интегрирует данные из OpenStreetMap и других общедоступных источников для создания статического, кэшируемого картографического контента, доступного даже при отсутствии мобильной связи.</p>
</li>
</ul>
<h2 id="программирование">Программирование</h2>
<ul>
<li><a id="wn832_34908"></a>
   Тимоте Жиро <a href="https://fosstodon.org/@rcarto/116810220954135406">опубликовал</a> шпаргалку, в которой <a href="https://zenodo.org/records/20842874/files/cheatsheet_osm_r.pdf">рассказывает</a>, как использовать данные OpenStreetMap и сопутствующие инструменты в языке R для геокодирования, прокладки маршрутов, а также загрузки базовых карт и наборов данных.</li>
</ul>
<h2 id="релизы">Релизы</h2>
<ul>
<li><a id="wn832_34904"></a>
   Проект Freemap Europe <a href="https://en.osm.town/@FreemapSlovakia/116816127417049500">сообщил</a> о крупном обновлении сайта <a href="https://www.freemap.eu/#map=9/-22.920100/-43.081100&amp;layers=X">Freemap.eu</a> для любителей активного отдыха и всех, у кого есть картографические файлы. Вы можете <a href="https://oz.freemap.sk/">посетить</a> страницу фонда, стоящего за проектом. Файлы <a href="https://github.com/FreemapSlovakia/freemap-v3-react">доступны</a> на GitHub.</li>
</ul>
<h2 id="osm-в-прессе">OSM в прессе</h2>
<ul>
<li><a id="wn832_34882"></a>
   clubic <a href="https://www.clubic.com/actualite-618514-avec-cartes-gouv-fr-la-france-lance-son-google-maps-souverain-et-il-est-bien-plus-complet-qu-on-ne-le-croit.html">сообщает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



, что IGN запустил сайт <a href="https://cartes.gouv.fr/explorer-les-cartes">cartes.gouv.fr</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



, посвящённый картам Франции. Также сообщается о сотрудничестве с OSM Франции и интеграции панорам улиц от Panoramax, о чём мы писали <a href="https://weeklyosm.eu/archives/16974#wn702_29714">ранее</a>. Грегори Пужоль <a href="https://www.journaldugeek.com/2026/06/26/letat-vient-de-lancer-son-propre-google-maps-et-il-fait-des-choses-que-google-ne-vous-montrera-jamais">публикует</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



 статью в <em>Journal du Geek</em> об этом запуске, в которой подчёркиваются преимущества использования этого сервиса по сравнению с картами Google.</li>
</ul>
<h2 id="разное-о-картах">Разное о картах</h2>
<ul>
<li>
<p><a id="wn832_34898"></a>
   Королевское географическое общество Испании <a href="https://realsociedadgeografica.com/conferencia-el-atlas-rojo-los-mapas-sovieticos-del-estrecho-de-gibraltar/">анонсировало</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



 о книгу <em>El Atlas rojo: los mapas soviéticos del estrecho de Gibraltar</em> («Красный атлас: советские карты Гибралтарского пролива») за авторством Агустина Т. де Вильяр Иглесиаса. В работе рассматривается масштабный секретный проект Советского Союза во время Холодной войны по картографированию Андалусии и Гибралтара. Стоит отметить удивительно точные карты городов с переводом русских обозначений, цветовую маркировку стратегически важных объектов и подробные военно-географические справки на оборотной стороне. <a href="https://institutoecg.es/wp-content/uploads/2026/06/El-atlas-rojo.pdf">Книгу</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



 и <a href="https://ibercarto.ign.es/resources/documentos/encuentros/11/S05_2-2.pdf">пояснения к ней</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



 можно бесплатно скачать в формате PDF с сайта RSG.</p>
</li>
<li>
<p><a id="wn832_34890"></a>
   clubic <a href="https://www.clubic.com/actualite-618901-hylight-le-drone-dirigeable-made-in-france-qui-veut-mettre-l-helicoptere-d-inspection-a-la-retraite.html">сообщает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



 о HyLight — французском воздушном дроне длиной в 12 метров и весом в 2 кг с нулевым углеродным следом, который заменяет вертолеты для ежедневной инспекции сотен километров инфраструктуры. Технология лидара позволяет получать важную информацию об инфраструктуре, такой как железные дороги и линии электропередач.</p>
</li>
</ul>
<h2 id="предстоящие-события">Предстоящие события</h2>
<table>
	<thead>
			<tr>
					<th>Страна</th>
					<th>Где</th>
					<th>Адрес</th>
					<th>Что</th>
					<th>Когда</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>MapCup Asia Pacific 2026 <a href="https://osmcal.org/event/4911/">:osmcalpic:</a></td>
					<td>2026-07-01 - 2026-07-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/06/sk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Žilina</td>
					<td>Fakulta riadenia a informatiky UNIZA</td>
					<td>Missing Maps mapathon Žilina #23 a StreetComplete Žilina #3 <a href="https://osmcal.org/event/4870/">:osmcalpic:</a></td>
					<td>2026-07-02 - 2026-07-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Gent</td>
					<td>Nerdlab</td>
					<td>IntroLAB ✦ OpenStreetMap <a href="https://osmcal.org/event/4895/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Angers</td>
					<td>L’Arrière Train, 3 rue de Frémur, Angers</td>
					<td>Angers : Rencontre mensuelle OpenStreetMap <a href="https://osmcal.org/event/4855/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bar Le Schmilblik</td>
					<td>Rencontre mensuelle des contributeurs Paris sud <a href="https://osmcal.org/event/4882/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/co.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bogotá</td>
					<td>Universidad Nacional de Colombia</td>
					<td>State of the Map Colombia (SotMCol) 2026 <a href="https://osmcal.org/event/4794/">:osmcalpic:</a></td>
					<td>2026-07-03 - 2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Mapas Web com uMap <a href="https://osmcal.org/event/4764/">:osmcalpic:</a></td>
					<td>2026-07-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum0 Hackspace</td>
					<td>Braunschweiger OSM-Treffen Mappingtour: Zusammen Braunschweig mappen <a href="https://osmcal.org/event/4860/">:osmcalpic:</a></td>
					<td>2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4886/">:osmcalpic:</a></td>
					<td>2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Greater London</td>
					<td>University College London</td>
					<td>London Data Week: Mapping festival with Missing Maps Mapathon <a href="https://osmcal.org/event/4915/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Salzburg</td>
					<td>Bewohnerservice Elisabeth-Vorstadt</td>
					<td>OSM-Treffpunkt <a href="https://osmcal.org/event/4469/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bern</td>
					<td>TBD</td>
					<td>OSM-Znacht in Bern <a href="https://osmcal.org/event/4820/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mapathon (with Training) Beginner Friendly  (Online) [eng] <a href="https://osmcal.org/event/4235/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2015/07/nl.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Groningen</td>
					<td>Groningen</td>
					<td>FOSS4GNL <a href="https://osmcal.org/event/4863/">:osmcalpic:</a></td>
					<td>2026-07-08 - 2026-07-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Trento</td>
					<td>Università di Trento - Facoltà di Sociologia</td>
					<td>FOSS4G IT &amp; OSMit 2026 <a href="https://osmcal.org/event/4827/">:osmcalpic:</a></td>
					<td>2026-07-09 - 2026-07-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>KGA Johannisberg, Parzelle III/23b</td>
					<td>217. OSM-Stammtisch Berlin-Brandenburg <a href="https://osmcal.org/event/4925/">:osmcalpic:</a></td>
					<td>2026-07-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zürich</td>
					<td>Bitwäscherei Zürich</td>
					<td>189. OSM-Stammtisch Zürich <a href="https://osmcal.org/event/4929/">:osmcalpic:</a></td>
					<td>2026-07-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>HTW Berlin</td>
					<td>Indoor OSM Workshop 2026 <a href="https://osmcal.org/event/4892/">:osmcalpic:</a></td>
					<td>2026-07-11 - 2026-07-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Chaayos, Paschim Vihar West, Delhi</td>
					<td>OSM Delhi Mapping Party No.30 (West Zone) <a href="https://osmcal.org/event/4351/">:osmcalpic:</a></td>
					<td>2026-07-12</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSM Chennai Mapping Party – Tambaram Market <a href="https://osmcal.org/event/4916/">:osmcalpic:</a></td>
					<td>2026-07-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #90 <a href="https://osmcal.org/event/4326/">:osmcalpic:</a></td>
					<td>2026-07-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>München</td>
					<td>Echardinger Einkehr</td>
					<td>Münchner OSM-Treffen <a href="https://osmcal.org/event/4919/">:osmcalpic:</a></td>
					<td>2026-07-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hamburg</td>
					<td>Voraussichtlich: &ldquo;Variable&rdquo;, Karolinenstraße 23</td>
					<td>Hamburger Mappertreffen <a href="https://osmcal.org/event/4696/">:osmcalpic:</a></td>
					<td>2026-07-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>temporärhaus</td>
					<td>OSM-Stammtisch Ulm/Neu-Ulm <a href="https://osmcal.org/event/4723/">:osmcalpic:</a></td>
					<td>2026-07-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Tours</td>
					<td>Étape 84</td>
					<td>Tours : Rencontre locale <a href="https://osmcal.org/event/4923/">:osmcalpic:</a></td>
					<td>2026-07-15</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Online Mapathon von ÄRZTE OHNE GRENZEN <a href="https://osmcal.org/event/4647/">:osmcalpic:</a></td>
					<td>2026-07-15</td>
			</tr>
	</tbody>
</table>
<p><em>Над этим выпуском работали: <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, <a href="https://www.openstreetmap.org/user/TrickyFoxy">TrickyFoxy</a>, <a href="https://www.openstreetmap.org/user/derFred">derFred</a>, <a href="https://www.osm.org/user/izen57">izen57</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>Еженедельник OSM 831</title>
				<link>https://hugo.weeklyosm.eu/ru/archives/0831/</link>
				<pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/archives/0831/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/06/831.webp" alt="Еженедельник OSM 831" /> 18.06.2026-24.06.2026
О нас [1] Пожалуйста, не переживайте, если вы заметили частые проверки на бота на сайте. Из-за огромной нагрузки со стороны ИИ-скраперов на базе искусственного интеллекта, мы подключили Anubis . Сообщество В рамках инициативы «UN Mappers Chapters» Модо Лево Энгельберт Стив, в качестве посла, имел честь возглавить проект CityMapper Externship, в ходе которого молодые африканцы обучались решать местные проблемы и вносить вклад в развитие OpenStreetMap на глобальном уровне. Он подчеркивает, что эта инициатива не состоялась бы без помощи партнёров: IVIDES DATA, GeOsm Family, Geospatial Girls &amp; Kids (GGK), Humanitarian OpenStreetMap Team (HOT) и TomTom. SeverinGeo рассказывает, с чего всё начиналось.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/06/831.webp" alt="Еженедельник OSM 831" /></p> <p>18.06.2026-24.06.2026</p>
<h2 id="о-нас">О нас</h2>
<ul>
<li><a id="wn831_34877"></a>
   [1] Пожалуйста, не переживайте, если вы заметили частые проверки на бота на сайте. Из-за огромной нагрузки со стороны <a href="https://ru.wikipedia.org/wiki/%D0%92%D0%B5%D0%B1-%D1%81%D0%BA%D1%80%D0%B5%D0%B9%D0%BF%D0%B8%D0%BD%D0%B3">ИИ-скраперов</a> на базе искусственного интеллекта, мы подключили <a href="https://github.com/TecharoHQ/anubis">Anubis</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



.</li>
</ul>
<h2 id="сообщество">Сообщество</h2>
<ul>
<li>
<p><a id="wn831_34856"></a>
   В рамках инициативы «UN Mappers Chapters» Модо Лево Энгельберт Стив, в качестве посла, имел честь <a href="https://www.openstreetmap.org/user/ENGELBERT%20MODO/diary/408919">возглавить</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 проект CityMapper Externship, в ходе которого молодые африканцы обучались решать местные проблемы и вносить вклад в развитие OpenStreetMap на глобальном уровне. Он подчеркивает, что эта инициатива не состоялась бы без помощи партнёров: IVIDES DATA, GeOsm Family, Geospatial Girls &amp; Kids (GGK), Humanitarian OpenStreetMap Team (HOT) и TomTom. SeverinGeo <a href="https://mastodon.social/@SeverinGeo/116790299304417902">рассказывает</a>, с чего всё начиналось.</p>
</li>
<li>
<p><a id="wn831_34848"></a>
   Pnorman <a href="https://www.openstreetmap.org/user/pnorman/diary/408895">сообщил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, что откат ошибок вследствие массового импорта в OpenStreetMap привёл к задержкам репликации данных между несколькими сервисами.</p>
</li>
<li>
<p><a id="wn831_34855"></a>
   StephanT извлёк данные из обеих версий «Договора между Федеративной Республикой Германией и Чешской Республикой о совместной государственной границе» (<a href="https://www.bundesrat.de/drs.html?id=99-26">версия Германии</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



, <a href="https://www.psp.cz/sqw/text/tiskt.sqw?o=10&amp;ct=185&amp;ct1=0">версия Чехии</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2020/08/cz-black.svg"
      
      
    />

  </picture>
</figure>



), сравнил их и подробно описал <a href="https://community.openstreetmap.org/t/vertrag-zwischen-der-bundesrepublik-deutschland-und-der-tschechischen-republik-uber-die-gemeinsame-staatsgrenze/144595/35">на форуме</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



 обнаруженные несоответствия, расхождения и ошибки .</p>
</li>
</ul>
<h2 id="фонд-openstreetmap">Фонд OpenStreetMap</h2>
<ul>
<li><a id="wn831_34853"></a>
   6–7 июня члены Совета директоров Фонда OpenStreetMap <a href="https://blog.openstreetmap.org/2026/06/19/2026-board-face-to-face-f2f-in-madrid-spain/">собрались</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в мадридском офисе компании TomTom на двухдневное рабочее заседание, посвящённое обсуждению приоритетных задач и мер, которые необходимо реализовать в течение следующих 12 месяцев.</li>
</ul>
<h2 id="события">События</h2>
<ul>
<li>
<p><a id="wn831_34862"></a>
   Программа конференции «State of the Map 2026» уже доступна онлайн. Конференция <a href="https://2026.stateofthemap.org/programme/">начнётся</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в пятницу, 28 августа церемонией открытия, после которой состоится специальный доклад «State of Panoramax» от Адриена Пави и Кристиана Квеста. Подробнее об этом <a href="https://en.osm.town/@sotm/116799800434591478">можно прочитать</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в Mastodon.</p>
</li>
<li>
<p><a id="wn831_34861"></a>
   Канадский саммит по открытым данным (The Canadian Open Data Summit) <a href="https://opendatasummit.ca/program/">состоится</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 14, 15 и 16 октября этого года в городе Уинсор (Онтарио), а в настоящее время <a href="https://docs.google.com/forms/d/e/1FAIpQLSdIJCAkMIVWwwaAFaMu8jdAj2u3FboC3RmZhDt9Zn0BvYxwfQ/viewform">открыт</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 приём заявок. Группы и отдельные лица приглашаются на проведение семинаров, дискуссий, блиц-докладов или презентаций на английском и французском языках.</p>
</li>
</ul>
<h2 id="oбразование">Oбразование</h2>
<ul>
<li><a id="wn831_34854"></a>
   IVIDES DATA® <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408904">провела</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 третье занятие в рамках серии семинаров «OSM 2026», посвящённое плагинам QGIS для OSM. В ходе семинара были рассмотрены практические примеры, касающиеся доступности, озеленения городских территорий и геолокации зданий, расположенных вблизи зон оползней.</li>
</ul>
<h2 id="карты">Карты</h2>
<ul>
<li><a id="wn831_34868"></a>
   Жанета Пясецкая <a href="https://www.linkedin.com/posts/%C5%BCanetapiasecka_gis-python-folium-share-7475519258328952833-TPpX/">рассказала</a> об <a href="https://piaseckazaneta.github.io/world-cup-map/">интерактивной карте</a>, которую она сделала сама, чтобы ответить на вопросы по Чемпионату мира по футболу 2026 года. Где именно расположены эти стадионы и насколько они отвечают критериям доступности? Находятся ли они в центрах городов или в их пригородах?</li>
</ul>
<h2 id="osm-в-деле">OSM в деле</h2>
<ul>
<li>
<p><a id="wn831_34865"></a>
   Сайт velowire.com <a href="https://www.velowire.com/blogcat/35/en/openstreetmap-google-earth.html">публикует</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 список маршрутов нескольких велогонок, предельно точно нанесённых на OpenStreetMap, с возможностью скачать его в формате <code>.KML</code> и открыть его не только в Google Планете Земля, но и в редакторе iD или любой другой программе, поддерживающей этот формат, например, в <a href="https://apps.gnome.org/en/Maps/">Gnome Картах</a>.</p>
</li>
<li>
<p><a id="wn831_34847"></a>
   <a href="https://www.powerpro.id/">Power Pro</a> — ПО для управления гостиницами — <a href="https://mastodon.social/@rphyrin/116776264926385444">использует</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 данные OpenStreetMap для определения местоположения заявок на техническое обслуживание.</p>
</li>
</ul>
<h2 id="программы">Программы</h2>
<ul>
<li>
<p><a id="wn831_34859"></a>
   <a href="https://mappinggis.com/2026/06/geoserver-3-0-la-mayor-modernizacion-de-la-plataforma-en-anos/">Выпущена</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



 версия GeoServer 3.0, которая, по словам Аурелио Моралеса (автора поста в блоге Mapping GIS), получила большие изменения.</p>
</li>
<li>
<p><a id="wn831_34851"></a>
   На недавней конференции <a href="https://fahrplan.do-byte.de/do-byte-2026/">DO_BYTE 2026</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



, организованной Chaos Computer Club, Марк <a href="https://media.ccc.de/v/do-byte-2026-17-panoramax-streetview-selber-hosten">рассказывал</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



 про проект Panoramax, поделившись опытом повседневной эксплуатации и практическими рекомендациями по созданию панорамных изображений.</p>
</li>
<li>
<p><a id="wn831_34860"></a>
   Иан Вагнер <a href="https://stadiamaps.com/blog/precision-meets-privacy-consumer-search-experience/">написал</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в блоге Stadia Maps о том, что разработка приложения с поддержкой геолокации часто начинается с простого — помочь пользователям найти место, куда им нужно добраться. Он рассматривает конкретные недостатки современных решений в области геокодирования и рассказывает, как команда Stadia Maps разработала более надёжный подход к решению этой задачи.</p>
</li>
</ul>
<h2 id="а-вы-знаете-">А вы знаете …</h2>
<ul>
<li>
<p><a id="wn831_34876"></a>
   &hellip; что Совет Фонда OpenStreetMap утвердил для себя <a href="https://osmfoundation.org/wiki/Board_Rules_of_Order">свод правил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, регулирующих порядок его работы?</p>
</li>
<li>
<p><a id="wn831_34866"></a>
   &hellip; что <a href="https://www.openstreetbrowser.org/#map=10/-22.9201/-43.0811&amp;basemap=osm-mapnik">OpenStreetBrowser</a> в категории «Культура — СМИ/Викиданные» (в разделе «Проверка качества OpenStreetMap») теперь проверяет наличие ссылок по названию объекта, его этимологии, архитектору и так далее? Подробнее об этом можно <a href="https://blog.openstreetbrowser.org/node/106">прочитать</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в статье от <em>plepe</em>.</p>
</li>
</ul>
<h2 id="разное-о-картах">Разное о картах</h2>
<ul>
<li>
<p><a id="wn831_34864"></a>
   20 июня 2026 года <a href="https://actualitte.com/article/132163/auteurs/yves-lacoste-fondateur-de-la-revue-herodote-est-mort">скончался</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



 Ив Лакост, один из самых выдающихся учёных в области геополитики и критической географии. Именно он ввёл в оборот в своих трудах знаменитые и противоречивые выражения, например: «География служит, прежде всего, для ведения войны» (перевод) (1976). Будучи основателем журнала <a href="https://www.herodote.org/">«Геродот»</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



, он на протяжении десятилетий <a href="https://ru.wikipedia.org/wiki/%D0%9B%D0%B0%D0%BA%D0%BE%D1%81%D1%82,_%D0%98%D0%B2">посвятил себя</a> тому, чтобы доказать, что в геополитических отношениях нет нейтралитета, подчёркивая неравенство в балансе сил между государствами.</p>
</li>
<li>
<p><a id="wn831_34850"></a>
   Сайт Space.com <a href="https://www.space.com/space-exploration/satellites/its-quite-a-bit-more-than-we-expected-satellite-reveals-immense-scale-of-gps-signal-tampering">сообщил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, что экспериментальный спутник составил карту зоны действия GPS-помех на территории Европы и Ближнего Востока.</p>
</li>
<li>
<p><a id="wn831_34857"></a>
   Esri España <a href="https://www.esri.es/es-es/acerca-de/eventos/cesri26/cesri26-mapasenaccion">открыла</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



 приём заявок на участие в конкурсе «Maps in Action» 2026 года; срок подачи заявок — до 21 сентября. Победивший проект будет представлен на конференции Esri Spain 2026, которая состоится с 30 сентября по 1 октября.</p>
</li>
<li>
<p><a id="wn831_34863"></a>
   <a href="https://community.kobotoolbox.org/t/new-release-and-final-removal-of-v1-api/76423">Выпущена</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 новая версия KoboToolbox (2.026.23), <a href="https://github.com/kobotoolbox/kpi/releases/tag/2.026.23">содержащая</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 ряд исправлений и небольших обновлений. Это значит, что сервисы, использующие API v1, больше не работают. Вы <a href="https://support.kobotoolbox.org/migrating_api.html">можете ознакомиться</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 c кратким руководством по переходу с API v1 на v2.</p>
</li>
<li>
<p><a id="wn831_34858"></a>
   Агентство Reuters <a href="https://www.reuters.com/graphics/CLIMATE-AUTOMATED/MONITOR/akpeykqqapr/">запустило</a> «Reuters Climate Monitor» — интерактивную веб-панель в виде глобуса, которая демонстрирует соотношение текущих температур и исторических средних значений по всему миру.</p>
</li>
<li>
<p><a id="wn831_34849"></a>
   Компания Rakeda <a href="https://news.ycombinator.com/item?id=48556082">разработала</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 Metiq — 3D-платформу, которая визуализирует более 100 общедоступных датасетов.</p>
</li>
<li>
<p><a id="wn831_34869"></a>
   Пользователь <a href="https://www.reddit.com/user/Evilgrandma03/">u/Evilgrandma03</a> на Реддите <a href="https://www.reddit.com/r/MapPorn/comments/1uaeagg/language_map_of_switzerland_excluding_uninhabited/">сообщил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 о <a href="https://ru.wikipedia.org/wiki/%D0%AF%D0%B7%D1%8B%D0%BA%D0%B8_%D0%A8%D0%B2%D0%B5%D0%B9%D1%86%D0%B0%D1%80%D0%B8%D0%B8">карте языков Швейцарии</a>, исключающей незаселённые горные районы, которая была создана путём наложения официальной карты Федерального статистического управления Швейцарии (FSO) на карту гор.</p>
</li>
<li>
<p><a id="wn831_34875"></a>
   Издание «Net Zero Frontiers» <a href="https://www.linkedin.com/posts/climateaction-urbanheatisland-sustainability-share-7473263979667042304-H_G4/">сообщает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, что исследовательница организации «Гринпис» Нибедита Саха с помощью тепловизора измерила разницы температур в нескольких городских районах и обнаружила, что в тенях от деревьев температура может быть на 20 ℃ ниже, чем на поверхностях под прямыми лучами солнца. Это подчёркивает важную роль озеленения для смягчения эффекта городского острова тепла.</p>
</li>
<li>
<p><a id="wn831_34852"></a>
   secara.teratur <a href="https://secarateratur.medium.com/foursquare-appreciation-post-02333c9378b9">проанализировал</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/09/id.svg"
      
      
    />

  </picture>
</figure>



 несколько популярных в Индонезии платформ, основанных на добровольно предоставляемых географических данных (VGI), таких как OpenStreetMap, Local Guides и Foursquare.</p>
</li>
</ul>
<h2 id="предстоящие-события">Предстоящие события</h2>
<table>
	<thead>
			<tr>
					<th>Страна</th>
					<th>Где</th>
					<th>Адрес</th>
					<th>Что</th>
					<th>Когда</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2017/11/tz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Dar es-Salaam</td>
					<td></td>
					<td>State of the Map Africa 2026 <a href="https://osmcal.org/event/3663/">:osmcalpic:</a></td>
					<td>2026-06-26 - 2026-06-28</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4876/">:osmcalpic:</a></td>
					<td>2026-06-26</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Formulários Web com KoboToolbox <a href="https://osmcal.org/event/4763/">:osmcalpic:</a></td>
					<td>2026-06-26</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Düsseldorf</td>
					<td>Online bei <a href="https://meet.jit.si/OSM-DUS-2026">https://meet.jit.si/OSM-DUS-2026</a></td>
					<td>Düsseldorfer OpenStreetMap-Treffen (online) <a href="https://osmcal.org/event/4386/">:osmcalpic:</a></td>
					<td>2026-06-26</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/ru.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Москва</td>
					<td>Москва</td>
					<td>Московская картопати <a href="https://osmcal.org/event/4896/">:osmcalpic:</a></td>
					<td>2026-06-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Biblioteca Alda Merini in via Edmondo De Amicis</td>
					<td>Mapathon @ Casorate Sempione <a href="https://osmcal.org/event/4778/">:osmcalpic:</a></td>
					<td>2026-06-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Navi Mumbai</td>
					<td>Blue Tokai Coffee Roasters, CBD Belapur</td>
					<td>OSM Mumbai Mapping Party No.11 (Navi Mumbai) <a href="https://osmcal.org/event/4320/">:osmcalpic:</a></td>
					<td>2026-06-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/08/se.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Uppsala</td>
					<td>Datorföreningen Update</td>
					<td>Mapping meetup in Uppsala <a href="https://osmcal.org/event/4913/">:osmcalpic:</a></td>
					<td>2026-06-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hannover</td>
					<td>Kuriosum</td>
					<td>OSM-Stammtisch Hannover <a href="https://osmcal.org/event/4848/">:osmcalpic:</a></td>
					<td>2026-06-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Saint-Étienne</td>
					<td>Zoomacom</td>
					<td>Rencontre Saint-Étienne et sud Loire <a href="https://osmcal.org/event/4897/">:osmcalpic:</a></td>
					<td>2026-06-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Heidelberg</td>
					<td>DEZERNAT#16</td>
					<td>Rhein-Neckar OSM Treffen <a href="https://osmcal.org/event/4730/">:osmcalpic:</a></td>
					<td>2026-06-29</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Webinaire en ligne - Hydrants, armoires de rue, poteaux et bâtiments de service <a href="https://osmcal.org/event/4871/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum 0</td>
					<td>Braunschweiger Mappertreffen im Stratum 0 Hackerspace <a href="https://osmcal.org/event/4859/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>City of Westminster</td>
					<td>The Albert pub</td>
					<td>London pub meet-up <a href="https://osmcal.org/event/4874/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Derby</td>
					<td>The Brunswick, Railway Terrace, Derby</td>
					<td>East Midlands pub meet-up <a href="https://osmcal.org/event/4800/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>MapCup Asia Pacific 2026 <a href="https://osmcal.org/event/4911/">:osmcalpic:</a></td>
					<td>2026-07-01 - 2026-07-31</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>iD Community Chat <a href="https://osmcal.org/event/4868/">:osmcalpic:</a></td>
					<td>2026-07-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stuttgart</td>
					<td>Forum 3 Café,  Gymnasiumstr. 21,  70173 Stuttgart</td>
					<td>Stuttgarter OpenStreetMap-Treffen <a href="https://osmcal.org/event/4854/">:osmcalpic:</a></td>
					<td>2026-07-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/06/sk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Žilina</td>
					<td>Fakulta riadenia a informatiky UNIZA</td>
					<td>Missing Maps mapathon Žilina #23 <a href="https://osmcal.org/event/4870/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Angers</td>
					<td>L’Arrière Train, 3 rue de Frémur, Angers</td>
					<td>Angers : Rencontre mensuelle OpenStreetMap <a href="https://osmcal.org/event/4855/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Gent</td>
					<td>Nerdlab</td>
					<td>IntroLAB ✦ OpenStreetMap <a href="https://osmcal.org/event/4895/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bar Le Schmilblik</td>
					<td>Rencontre mensuelle des contributeurs Paris sud <a href="https://osmcal.org/event/4882/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/co.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bogotá</td>
					<td>Universidad Nacional de Colombia</td>
					<td>State of the Map Colombia (SotMCol) 2026 <a href="https://osmcal.org/event/4794/">:osmcalpic:</a></td>
					<td>2026-07-03 - 2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Mapas Web com uMap <a href="https://osmcal.org/event/4764/">:osmcalpic:</a></td>
					<td>2026-07-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum0 Hackspace</td>
					<td>Braunschweiger OSM-Treffen Mappingtour: Zusammen Braunschweig mappen <a href="https://osmcal.org/event/4860/">:osmcalpic:</a></td>
					<td>2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4886/">:osmcalpic:</a></td>
					<td>2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Salzburg</td>
					<td>Bewohnerservice Elisabeth-Vorstadt</td>
					<td>OSM-Treffpunkt <a href="https://osmcal.org/event/4469/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bern</td>
					<td>TBD</td>
					<td>OSM-Znacht in Bern <a href="https://osmcal.org/event/4820/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mapathon (with Training) Beginner Friendly  (Online) [eng] <a href="https://osmcal.org/event/4235/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2015/07/nl.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Groningen</td>
					<td>Groningen</td>
					<td>FOSS4GNL <a href="https://osmcal.org/event/4863/">:osmcalpic:</a></td>
					<td>2026-07-08 - 2026-07-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Trento</td>
					<td>Università di Trento - Facoltà di Sociologia</td>
					<td>FOSS4G IT &amp; OSMit 2026 <a href="https://osmcal.org/event/4827/">:osmcalpic:</a></td>
					<td>2026-07-09 - 2026-07-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>HTW Berlin</td>
					<td>Indoor OSM Workshop 2026 <a href="https://osmcal.org/event/4892/">:osmcalpic:</a></td>
					<td>2026-07-11 - 2026-07-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Chaayos, Paschim Vihar West, Delhi</td>
					<td>OSM Delhi Mapping Party No.30 (West Zone) <a href="https://osmcal.org/event/4351/">:osmcalpic:</a></td>
					<td>2026-07-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #90 <a href="https://osmcal.org/event/4326/">:osmcalpic:</a></td>
					<td>2026-07-13</td>
			</tr>
	</tbody>
</table>
<p><em>Над этим выпуском работали: <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, <a href="https://www.openstreetmap.org/user/derFred">derFred</a>, <a href="https://www.osm.org/user/izen57">izen57</a>, <a href="https://www.openstreetmap.org/user/richter_fn">richter_fn</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>Еженедельник OSM 827</title>
				<link>https://hugo.weeklyosm.eu/ru/archives/0827/</link>
				<pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/archives/0827/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/05/827.png" alt="Еженедельник OSM 827" /> 21.05.2026-27.05.2026
Сообщество Ари Альварес объясняет , как находить данные по ограничениям скорости на автодорогах США.
На 2-летний юбилей версии Еженедельника на бразильском варианте португальского языка Raquel Dezidério Souto подводит промежуточные итоги и делится наиболее важными собранными переводчиками новостями.
Лакс Шусс: «Есть много проблем с тегами walk=no».
Unique Mappers Network приняла участие в подготовке волонтёров к предстоящей Port Harcourt Tech Expo 2026. Во время выставки организация намерена внести свой вклад в работу по цифровой картографии OpenStreetMap.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/05/827.png" alt="Еженедельник OSM 827" /></p> <p>21.05.2026-27.05.2026</p>
<h2 id="сообщество">Сообщество</h2>
<ul>
<li>
<p><a id="wn827_34719"></a>
   Ари Альварес <a href="https://www.openstreetmap.org/user/AriAlvarez/diary/408725">объясняет</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, как находить данные по ограничениям скорости на автодорогах США.</p>
</li>
<li>
<p><a id="wn827_34735"></a>
   На 2-летний юбилей версии Еженедельника на бразильском варианте португальского языка Raquel Dezidério Souto <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408794">подводит</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 промежуточные итоги и делится наиболее важными собранными переводчиками новостями.</p>
</li>
<li>
<p><a id="wn827_34721"></a>
   Лакс Шусс: «<a href="https://www.openstreetmap.org/user/LuxSchuss/diary/408745">Есть</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 много проблем с тегами <code>walk=no</code>».</p>
</li>
<li>
<p><a id="wn827_34738"></a>
   Unique Mappers Network <a href="https://www.linkedin.com/posts/unique-mappers-network_phtechexpo2026-uniquemappers-gis-activity-7465513116894810112-A_ns?utm_source=social_share_video_v2&amp;utm_medium=android_app&amp;rcm=ACoAABLDs7sBdlyXV3s93fgVyG0F747qgerIZZg&amp;utm_campaign=share_via">приняла участие</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в подготовке волонтёров к предстоящей Port Harcourt Tech Expo 2026. Во время выставки организация намерена внести свой вклад в работу по цифровой картографии OpenStreetMap.</p>
</li>
<li>
<p><a id="wn827_34714"></a>
   Кристоф Хорманн для большей осведомлённости и прозрачности <a href="https://imagico.de/blog/en/update-2-on-fossgis-membership-fees/">поделился</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 полезной информацией, касающейся членских взносов в FOSSGIS.</p>
</li>
<li>
<p><a id="wn827_34720"></a>
   <a href="https://www.openstreetmap.org/user/b-unicycling"><em>b-unicycling</em></a> хотела бы написать туториал, как наносить на карту камни для лифтинга. <a href="https://www.openstreetmap.org/user/b-unicycling/diary/408781">Прочитайте</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 её пост, чтобы узнать больше о мыслях и идеях касательно этого спортивного развлечения.</p>
</li>
</ul>
<h2 id="фонд-openstreetmap">Фонд OpenStreetMap</h2>
<ul>
<li><a id="wn827_34730"></a>
   Команда модераторов OSMF, следящая за списками рассылки <code>talk@openstreetmap.org</code> и <code>osmf-talk@openstreetmap.org</code> и за категориями <code>general</code>, <code>general:tagging</code> и <code>foundation</code> на форуме, <a href="https://osmfoundation.org/wiki/File:20260523_OSM_talk_list_mods_annual_report.pdf">опубликовала</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 на сайте OSMF свой четвёртый годовой отчёт.</li>
</ul>
<h2 id="местные-отделения-osmf">Местные отделения OSMF</h2>
<ul>
<li>
<p><a id="wn827_34733"></a>
   Катя Хаферкорн и Оливер Рудзик <a href="https://www.fossgis.de/news/2026_05_26_fossgis-osm_communitytreffen_nr_25/">сообщают</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



, что 33 активных члена немецкоязычных сообществ OpenStreetMap и FOSSGIS собрались в городе Эссен на <a href="https://www.fossgis.de/wiki/FOSSGIS_OSM_Communitytreffen_2026_Nummer_25">общей встрече сообществ FOSSGIS и OSM</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



<figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 с 30 апреля по 3 мая 2026 года. Следующее собрание запланировано на период с 2 по 4 октября.</p>
</li>
<li>
<p><a id="wn827_34727"></a>
   Экземпляр Panoramax, организованный отделением OSM во Франции, отмечает свою <a href="https://forum.openstreetmap.fr/t/anniversaire-et-appel-aux-dons-pour-linstance-panoramax-dosm-france/43450">третью годовщину</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



. На нём хранится уже 50 миллионов фотографий, и, к сожалению, места для хранения данных становится всё меньше и меньше. Поэтому ассоциация <a href="https://openstreetmap.assoconnect.com/collect/donation/01KQZ3W4W1NYX8DCPA7SKHQD75/de-nouveaux-serveurs-de-stockage-pour-panoramax">просит о пожертвованиях</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



, чтобы увеличить ёмкость хранилища и приобрести графические процессоры для обеспечения работы сервиса размытия фотографий.</p>
</li>
<li>
<p><a id="wn827_34716"></a>
   Личное знакомство с OSM во время отпуска постепенно переросло в возрождение сообщества OpenStreetMap города Фульда (Германия). История человека, которую стоит <a href="https://www.openstreetmap.org/user/m_fuhrmann/diary/408757">прочитать</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



.</p>
</li>
</ul>
<h2 id="события">События</h2>
<ul>
<li><a id="wn827_34732"></a>
   <em>State of the Map Baltics 2026</em> <a href="https://balticgitconf.eu/">пройдёт</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 в рамках Балтийской конференции по геопространственным информационным технологиям 2026 в Латвийском университете 4 июня 2026 года.</li>
</ul>
<h2 id="карты">Карты</h2>
<ul>
<li>
<p><a id="wn827_34722"></a>
   [1] Кристоф Хорманн <a href="https://imagico.de/blog/en/putting-animals-on-the-map/">демонстрирует</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 картографические обозначения для животных в <a href="https://github.com/imagico/osm-carto-alternative-colors/commit/e608593bd577ef26b0eb6e66d6e2b9c9ad7e7889">альтернативных цветах OSM-Carto</a>.</p>
</li>
<li>
<p><a id="wn827_34711"></a>
   Польозователь Leni_v <a href="https://community.openstreetmap.org/t/i-built-urbanistmap-org-to-show-all-proposed-and-under-construction-ways/143993">запустил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 веб-платформу <a href="https://urbanistmap.org">urbanistmap.org</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



<figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



, где отображаются предлагаемые, планируемые или строящиеся объекты в OSM.</p>
</li>
<li>
<p><a id="wn827_34726"></a>
   Пользователь <em>leekyuhaiambox-ops</em> <a href="https://github.com/osmlab/awesome-openstreetmap/pull/193">сообщает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, что приложение <em><a href="https://geoinfomatic.pythonanywhere.com/">geoinformatic</a></em> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2020/08/ko-black.svg"
      
      
    />

  </picture>
</figure>



, размещённое на PythonAnywhere, использует данные OpenStreetMap для оценки районов на доступность ключевых объектов инфраструктуры, включая школы, больницы, торговые центры, парки, спортзалы, аптеки, библиотеки, кафе.</p>
</li>
</ul>
<h2 id="osm-в-деле">OSM в деле</h2>
<ul>
<li><a id="wn827_34731"></a>
   Пользователь <em>vic-tor-menta</em> <a href="https://neopaquita.es/@vic_101/116631084732514554">сообщает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



, что <a href="https://ru.wikipedia.org/wiki/%D0%91%D1%80%D0%BE%D0%BA%D0%BE%D0%B2%D0%B8%D1%87,_%D0%AD%D1%80%D0%B8%D0%BD">Э́рин Бро́кович</a> <a href="https://brockovichdatacenter.com/">создала</a> сайт, на котором люди могут сообщать о планирующихся центрах обработки данных в США, чтобы координировать протестные движения. На карте, основанной по OSM, показаны уже действующие и известные ЦОДы. Для Франции существует <a href="https://umap.openstreetmap.fr/fr/map/carte-des-data-centers-des-projets-et-des-contesta_1289485">аналогичная карта</a> на основе uMap и OSM с центрами обработки данных, созданная организацией <a href="https://lenuageetaitsousnospieds.org">«Le nuage était sous nos pieds»</a>.</li>
</ul>
<h2 id="открытые-данные">Открытые данные</h2>
<ul>
<li><a id="wn827_34710"></a>
   Тобиас <a href="https://en.osm.town/@tordans/116611748094950830">объявляет</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, что в рамках проекта Panoramax была разработана <a href="https://huggingface.co/Panoramax/classify_de_road_signs">нейросеть</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, способная распознавать дорожные знаки Германии по панорамам и снимкам улиц.</li>
</ul>
<h2 id="программы">Программы</h2>
<ul>
<li>
<p><a id="wn827_34728"></a>
   Команда проекта Bike Streets <a href="https://bikestreets.com/blog/bksengineering-advancing-osm-diff-processing">разработала</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 инструмент, который автоматически определяет, могут ли изменения данных OpenStreetMap потенциально повлиять на карты Bike Streets.</p>
</li>
<li>
<p><a id="wn827_34729"></a>
   <em>Altilunium</em> сделал сайт <em><a href="https://github.com/altilunium/terjangkau">Terjangkau: Neighborhood Explorer</a></em> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, который поможет пользователям измерять расстояние до объектов и достопримечательностей в радиусе одного километра от любого выбранного места. Платформа основана на данных OpenStreetMap.</p>
</li>
<li>
<p><a id="wn827_34736"></a>
   Организация <em>Open Energy Transition</em> и инициатива <em>MapYourGrid</em> <a href="https://open-energy-transition.github.io/grid2poster/">разработали</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 приложение <em>Grid2Poster</em>, где можно создать готовые к печати плакаты электрических сетей, используя данные из OpenStreetMap.</p>
</li>
<li>
<p><a id="wn827_34712"></a>
   HeiGIT <a href="https://heigit.org/heat-resilient-mobility-in-80-major-german-cities-and-an-invitation-to-shape-its-future/">выпустил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 приложение, которое строит пешеходные маршруты по данным о тенях в высоком разрешении, во избежание ходьбы под слишком сильным солнцем. Алгоритм построения работает на <em><a href="https://shaded.openrouteservice.org/">openrouteservice</a></em> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



<figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, движке маршрутизации HeiGIT с открытым исходным кодом, а в качестве сетки дорог используется OpenStreetMap.</p>
</li>
</ul>
<h2 id="программирование">Программирование</h2>
<ul>
<li><a id="wn827_34724"></a>
   Манбхав Сугла <a href="https://www.openstreetmap.org/user/Manbhav234/diary/408786">был выбран</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 для участия в проекте Google Summer of Code 2026, в рамках которого он будет разрабатывать поддержку бэкенда DuckDB в <a href="https://github.com/maplibre/martin/issues/2264">Martin TileServer</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



.</li>
</ul>
<h2 id="релизы">Релизы</h2>
<ul>
<li>
<p><a id="wn827_34715"></a>
   Bikerouter <a href="https://skylightaccess.de/@bikerouter/statuses/01KS9WTRSYKGCB1PDPMPKZ7XCR">выпускает</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 версию 2026.13, в которой появился «Инспектор маршрута», позволяющий пользователям просматривать информацию о всём маршруте и его частях прямо на карте.</p>
</li>
<li>
<p><a id="wn827_34717"></a>
   <a href="https://en.osm.town/@osrm/116625188568280499">Вышла</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 версия 0.5.0 OSRM-frontend, в которой появилось несколько новых возможностей и исправлены ошибки.</p>
</li>
<li>
<p><a id="wn827_34713"></a>
   Пользователь <em>rphyrin</em> <a href="https://www.openstreetmap.org/user/rphyrin/diary/408718">выпустил</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



 Altilunium LocationPad v26.5.22, в котором появилась поддержка более длинного текста описаний мест.</p>
</li>
</ul>
<h2 id="osm-в-прессе">OSM в прессе</h2>
<ul>
<li><a id="wn827_34718"></a>
   Газета <em>Seoul Economic Daily</em> <a href="https://www.sedaily.com/article/20044438">сообщила</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2020/08/ko-black.svg"
      
      
    />

  </picture>
</figure>



, что <a href="https://www.cacf.or.kr/site/index.php">Фонд культуры и туризма</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2020/08/ko-black.svg"
      
      
    />

  </picture>
</figure>



 провинции Чхунчхо́н-Намдо́ провёл велосипедный тур с поездкой на поездах 16 и 17 мая 2026 года. Карта маршрута, распространённая фондом, использует OSM, но, к сожалению, без указания авторства.</li>
</ul>
<h2 id="разное-о-картах">Разное о картах</h2>
<ul>
<li>
<p><a id="wn827_34737"></a>
   Джонн Элледж <a href="https://jonn.substack.com/p/how-long-is-a-piece-of-string-on">объясняет</a> <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/en.svg"
      
      
    />

  </picture>
</figure>



, как на самом деле трудно корректно измерить длину рек.</p>
</li>
<li>
<p><a id="wn827_34723"></a>
   <a href="https://time.com/article/2026/05/19/iran-war-subsea-cables-internet-strait-hormuz-gulf-states-ai/">По сообщению</a> Time, Иран угрожает взимать ежегодную плату за пользование волоконно-оптических кабелей, проходящими по дну Ормузского пролива. Это ставит под угрозу несколько подводных кабельных систем, включая <a href="https://www.submarinecablemap.com/submarine-cable/asia-africa-europe-1-aae-1">AAE-1</a> и <a href="https://www.submarinecablemap.com/submarine-cable/seamewe-5">SEA-ME-WE 5</a>. Эксперты предупредили, что узлы в Юго-Восточной Азии могут столкнуться с серьёзными нагрузками при обмене данными с европейскими узлами.</p>
</li>
</ul>
<h2 id="предстоящие-события">Предстоящие события</h2>
<table>
	<thead>
			<tr>
					<th>Страна</th>
					<th>Где</th>
					<th>Адрес</th>
					<th>Что</th>
					<th>Когда</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4797/">:osmcalpic:</a></td>
					<td>2026-05-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/hu.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Balatonszéplak</td>
					<td>Mapping Party Széplakon <a href="https://osmcal.org/event/4831/">:osmcalpic:</a></td>
					<td>2026-05-29 - 2026-05-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Catania</td>
					<td>CreationDose Srl - Via Antonino di Sangiuliano 197</td>
					<td>LibreLocal Meetup Catania - Supported by Free Software Foundation &amp; Team1 <a href="https://osmcal.org/event/4826/">:osmcalpic:</a></td>
					<td>2026-05-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bad Harzburg</td>
					<td>Braunschweiger OSM-Treffen Mappingtour: Zusammen Bad Harzburg mappen <a href="https://osmcal.org/event/4775/">:osmcalpic:</a></td>
					<td>2026-05-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Thiruvananthapuram</td>
					<td>Gandhi Park, East Fort</td>
					<td>Mapping Party at East Fort <a href="https://osmcal.org/event/4838/">:osmcalpic:</a></td>
					<td>2026-05-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Coimbatore</td>
					<td>Sarvanampatti, Coimbatore</td>
					<td><del>Mapping Party @ Coimbatore</del> <a href="https://osmcal.org/event/4822/">:osmcalpic:</a></td>
					<td>2026-05-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bayonne Médiathèque centre-ville</td>
					<td>Cartopartie Bayonne <a href="https://osmcal.org/event/4789/">:osmcalpic:</a></td>
					<td>2026-06-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum 0</td>
					<td>Braunschweiger Mappertreffen im Stratum 0 Hackerspace <a href="https://osmcal.org/event/4634/">:osmcalpic:</a></td>
					<td>2026-06-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/es.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Madrid</td>
					<td>Online</td>
					<td>Mappy Hour OSM España <a href="https://osmcal.org/event/4806/">:osmcalpic:</a></td>
					<td>2026-06-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Salzburg</td>
					<td>Bewohnerservice Elisabeth-Vorstadt</td>
					<td>OSM-Treffpunkt <a href="https://osmcal.org/event/4468/">:osmcalpic:</a></td>
					<td>2026-06-02</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mapathon (with Training) Beginner Friendly  (Online) [eng] <a href="https://osmcal.org/event/4234/">:osmcalpic:</a></td>
					<td>2026-06-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Praha</td>
					<td></td>
					<td>Kvartální pivko Praha <a href="https://osmcal.org/event/4832/">:osmcalpic:</a></td>
					<td>2026-06-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Brno</td>
					<td></td>
					<td>Kvartální OSM pivo <a href="https://osmcal.org/event/4782/">:osmcalpic:</a></td>
					<td>2026-06-03</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSM Indoor Meetup <a href="https://osmcal.org/event/4781/">:osmcalpic:</a></td>
					<td>2026-06-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stuttgart</td>
					<td>Stuttgart</td>
					<td>Stuttgarter OpenStreetMap-Treffen <a href="https://osmcal.org/event/4814/">:osmcalpic:</a></td>
					<td>2026-06-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2019/09/lv.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Rīga</td>
					<td>House of Nature</td>
					<td>State of the Map Baltics 2026 <a href="https://osmcal.org/event/4690/">:osmcalpic:</a></td>
					<td>2026-06-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Angers</td>
					<td>L’Arrière Train, 3 rue de Frémur, Angers</td>
					<td>Angers : Rencontre mensuelle OpenStreetMap <a href="https://osmcal.org/event/4815/">:osmcalpic:</a></td>
					<td>2026-06-04</td>
			</tr>
			<tr>
					<td>sy</td>
					<td>بلدية دمشق القديمة</td>
					<td>Online</td>
					<td>OSM Syria Solidarity Mapathon #6 <a href="https://osmcal.org/event/4823/">:osmcalpic:</a></td>
					<td>2026-06-05</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Plugins QGIS para OSM <a href="https://osmcal.org/event/4761/">:osmcalpic:</a></td>
					<td>2026-06-05</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Piazzola sul Brenta</td>
					<td>Villa Contarini, Piazzola sul Brenta (PD)</td>
					<td>OpenStreetMap per i ciclisti al BAM! <a href="https://osmcal.org/event/4837/">:osmcalpic:</a></td>
					<td>2026-06-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4117/">:osmcalpic:</a></td>
					<td>2026-06-06</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4299/">:osmcalpic:</a></td>
					<td>2026-06-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #89 <a href="https://osmcal.org/event/4325/">:osmcalpic:</a></td>
					<td>2026-06-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/es.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Madrid</td>
					<td>Online</td>
					<td>Mappy Hour OSM España <a href="https://osmcal.org/event/4807/">:osmcalpic:</a></td>
					<td>2026-06-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hamburg</td>
					<td>Voraussichtlich: &ldquo;Variable&rdquo;, Karolinenstraße 23</td>
					<td>Hamburger Mappertreffen <a href="https://osmcal.org/event/4695/">:osmcalpic:</a></td>
					<td>2026-06-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>temporärhaus</td>
					<td>OSM-Stammtisch Ulm/Neu-Ulm <a href="https://osmcal.org/event/4722/">:osmcalpic:</a></td>
					<td>2026-06-09</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>iD Community Chat <a href="https://osmcal.org/event/4828/">:osmcalpic:</a></td>
					<td>2026-06-10</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/us.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Madison</td>
					<td>Madison, Wisconsin</td>
					<td>State of the Map US 2026 <a href="https://osmcal.org/event/4625/">:osmcalpic:</a></td>
					<td>2026-06-11 - 2026-06-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>München</td>
					<td>WikiMUC</td>
					<td>Münchner OSM-Treffen <a href="https://osmcal.org/event/4344/">:osmcalpic:</a></td>
					<td>2026-06-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bochum</td>
					<td>Das Labor, Alleestraße 50, Bochum</td>
					<td>OSM-Treffen Bochum <a href="https://osmcal.org/event/4821/">:osmcalpic:</a></td>
					<td>2026-06-11</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4843/">:osmcalpic:</a></td>
					<td>2026-06-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chennai Corporation</td>
					<td>Koyambedu Market</td>
					<td>Come map Koyambedu Market, Chennai with us on June 14th, 2026! <a href="https://osmcal.org/event/4835/">:osmcalpic:</a></td>
					<td>2026-06-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/07/dk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>København</td>
					<td>Cafe Bevar&rsquo;s</td>
					<td>OSMmapperCPH <a href="https://osmcal.org/event/4738/">:osmcalpic:</a></td>
					<td>2026-06-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Chaayos, Paschim Vihar West, Delhi</td>
					<td>OSM Delhi Mapping Party No.30 (West Zone) <a href="https://osmcal.org/event/4351/">:osmcalpic:</a></td>
					<td>2026-06-14</td>
			</tr>
	</tbody>
</table>
<p><em>Над этим выпуском работали: <a href="https://www.openstreetmap.org/user/MatthiasMatthias">MatthiasMatthias</a>, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, <a href="https://www.openstreetmap.org/user/TrickyFoxy">TrickyFoxy</a>, <a href="https://www.openstreetmap.org/user/derFred">derFred</a>, <a href="https://www.osm.org/user/izen57">izen57</a>, <a href="https://www.openstreetmap.org/user/richter_fn">richter_fn</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>Еженедельник OSM 825</title>
				<link>https://hugo.weeklyosm.eu/ru/archives/0825/</link>
				<pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/archives/0825/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/05/825.png" alt="Еженедельник OSM 825" /> 07.05.2026-13.05.2026
Картографирование Предложения, ждущие комментариев: Дополнительные теги датацентров: data_center:tier (уровень надёжности и отказоустойчивости), data_center:total_power (общая мощность),data_center:IT_power (максимальная мощность оборудования), data_center:IT_area (полезная площадь). На голосование вынесено предложение по разделению текущей довольно смешанной маркировки аэродромов. Предлагаются отдельные теги для типа аэропортов, их использованию, видов доступа к ним, наличию любительского или международного движения, а также специальные значения для взлётно-посадочных полос, площадок для вертолётов и т. д. Сообщество Анна-Каролина Дистель показывает в видео :EN-s:, какие объекты туристы могут добавлять в OpenStreetMap с помощью OsmAnd прямо на ходу. Среди примеров таких объектов: скамейки, указатели, площадки для наблюдения, места для отдыха или ночлега, броды и объекты, связанные с оказанием первой помощи.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/05/825.png" alt="Еженедельник OSM 825" /></p> <p>07.05.2026-13.05.2026</p>
<h2 id="картографирование">Картографирование</h2>
<ul>
<li><a id="wn825_34610"></a>
 Предложения, ждущие комментариев:</li>
</ul>
<ul>
<li><a href="https://wiki.openstreetmap.org/wiki/Proposal:Data_center_technical_attributes">Дополнительные теги</a> датацентров: <code>data_center:tier</code> (уровень надёжности и отказоустойчивости), <code>data_center:total_power</code> (общая мощность),<code>data_center:IT_power</code> (максимальная мощность оборудования), <code>data_center:IT_area</code> (полезная площадь).</li>
</ul>
<ul>
<li><a id="wn825_34612"></a>
 На <a href="https://wiki.openstreetmap.org/wiki/Proposal:Aerodrome_Descriptive_Tags">голосование</a> вынесено предложение по  разделению текущей довольно смешанной маркировки аэродромов. Предлагаются отдельные теги для типа аэропортов, их использованию, видов доступа к ним, наличию любительского или международного движения, а также специальные значения для взлётно-посадочных полос, площадок для вертолётов и т. д.</li>
</ul>
<h2 id="сообщество">Сообщество</h2>
<ul>
<li>
<p><a id="wn825_34628"></a>
 Анна-Каролина Дистель показывает в <a href="https://www.youtube.com/watch?v=94jWBT_6HU0">видео</a> :EN-s:, какие объекты туристы могут добавлять в OpenStreetMap с помощью OsmAnd прямо на ходу. Среди примеров таких объектов: скамейки, указатели, площадки для наблюдения, места для отдыха или ночлега, броды и объекты, связанные с оказанием первой помощи.</p>
</li>
<li>
<p><a id="wn825_34664"></a>
 Ракель Дезидерио Соуто <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408669">рассказывает</a> :EN-s::PT-s: о своём выступлении в качестве специального докладчика на мероприятии, организованном Педагогическим университетом Мапуту (Мозамбик), где обсуждались изменения в экологическом законодательстве страны. Во время мероприятия она подчеркнула важность открытых данных и использования совместных картографических платформ, уделив особое внимание OpenStreetMap. Текст выступления под названием «Развитие и охрана природы» можно изучить <a href="https://doi.org/10.5281/zenodo.20149423">здесь</a> :PT-s:.</p>
</li>
<li>
<p><a id="wn825_34634"></a>
 9tab написал о несоответствиях в использовании <code>addr:place</code> в <a href="https://wiki.openstreetmap.org/wiki/Talk:Wiki#addr:place_inconsistencies">вики-обсуждениях</a>. Использование <a href="https://wiki.openstreetmap.org/wiki/Key:addr:place">тега</a> на практике иногда отличается от местами противоречивых описаний на Вики, например, в отношении <a href="https://wiki.openstreetmap.org/wiki/Key:addr:street"><code>addr:street</code></a>.</p>
</li>
<li>
<p><a id="wn825_34651"></a>
 Новое <a href="https://community.openstreetmap.org/t/geografisk-crowdsourcing-via-openstreetmap-danmark-er-8-9-gange-mere-effektiv-viser-ny-stor-undersogelse/143708">сравнительное исследование</a> :DK-s:, проведённое в Дании, показывает, что датское сообщество OSM за два года создало качественных геоданных примерно в девять раз больше, чем правительственный проект GeoFA. Под наблюдениями были 38 различных категорий данных о природе и культуре, в которых на сообщество приходится более 145 000 зарегистрированных объектов.</p>
</li>
<li>
<p><a id="wn825_34639"></a>
 В последнем интервью компания OpenCage <a href="https://blog.opencagedata.com/post/openstreetmap-interview-transitous">беседует</a> :EN-s: с Фолкером Краузе о Transitous — сервисе для построения маршрутов на общественном транспорте, изменения в код которого может вносить каждый.</p>
</li>
<li>
<p><a id="wn825_34638"></a>
 Проект MapComplete <a href="https://en.osm.town/@MapComplete/116557376361008108">сообщает</a> :EN-s:, что на данный момент с помощью этого инструмента в 2026 году было создано более 20 000 наборов изменений. В то же время количество тегов <code>panoramax</code> в OpenStreetMap превысило 100 000, большинство из которых добавлены как раз через MapComplete.</p>
</li>
<li>
<p><a id="wn825_34493"></a>
 1 мая был опубликован двенадцатый выпуск <a href="https://community.openstreetmap.org/t/mensileosm-12-aprile-2026/143484">mensileOSM</a> :IT-s: — ежемесячных новостей итальянского сообщества OpenStreetMap на итальянском языке. Проект также отмечает первую годовщину.</p>
</li>
<li>
<p><a id="wn825_34657"></a>
 На форуме OSM <a href="https://community.openstreetmap.org/t/open-moon-map-collaboration/143808">началось</a> :EN-s: обсуждение возможного сотрудничества между сообществом OpenStreetMap и организацией Open Lunar по созданию карты Луны с открытым исходным кодом. Инициатива вызвана возобновлением лунной активности и существующими идеями о совместном картографировании Луны.</p>
</li>
<li>
<p><a id="wn825_34653"></a>
 Отделение OpenStreetMap в США <a href="https://openstreetmap.us/news/2026/05/openwetlandsmap-announcement/">сотрудничает</a> :EN-s: с Центром инноваций в области экологической политики (EPIC) в проекте OpenWetlandsMap — открытой базе данных о водно-болотных угодьях в США. Целью проекта является дополнение устаревших и фрагментарных данных по современным картам, создаваемыми сообществом, для поддержки охраны природы.</p>
</li>
<li>
<p><a id="wn825_34643"></a>
 Используя Altilunium Locationpad, rphyrin <a href="https://www.openstreetmap.org/user/rphyrin/diary/408657">проиллюстрировал</a> :EN-s: хадж индонезийских мусульман 2018 года от города Бадунг до самой Мекки.</p>
</li>
<li>
<p><a id="wn825_34629"></a>
 SomeoneElse <a href="https://www.openstreetmap.org/user/SomeoneElse/diary/408645">задаётся вопросом</a> :EN-s:, что на самом деле означает <code>disused=yes</code> в OSM.</p>
</li>
</ul>
<h2 id="местные-отделения-osmf">Местные отделения OSMF</h2>
<ul>
<li><a id="wn825_34669"></a>
 OpenStreetMap US <a href="https://openstreetmap.us/news/2026/05/yesterdays-charter-project/">приняла</a> :EN-s: проект <a href="https://yesterdays.maprva.org/">«Yesterdays»</a> в качестве нового <em>Charter Project</em>. Платформа позволяет всем желающим привязывать исторические фотографии к координатам и совместно составлять исторические карты городских пейзажей по OpenStreetMap и разным историческим источникам.</li>
</ul>
<h2 id="события">События</h2>
<ul>
<li><a id="wn825_34630"></a>
 Фонд OpenStreetMap <a href="https://blog.openstreetmap.org/2026/05/11/state-of-the-map-2027-call-for-venues-is-now-open/">объявил</a> конкурс на выбор места проведения конференции State of the Map 2027. Заявки принимаются до 19 июля 2026 года, а выбранное место проведения будет объявлено во время SotM 2026 в Париже.</li>
</ul>
<h2 id="oбразование">Oбразование</h2>
<ul>
<li><a id="wn825_34665"></a>
 Серия семинаров OpenStreetMap-2026, организованная IVIDES DATA для участников из португалоязычных стран (Бразилии, Мозамбика и Анголы) стартовала. Организаторы <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408653">выложили</a> :PT-s::EN-s: PDF и ссылку на презентационное видео, а также <a href="https://umap.openstreetmap.fr/pt-br/map/participantes-ciclo-de-oficinas-osm-2026_1404577#4/-14.944785/-14.414063">карту</a> городов участников.</li>
</ul>
<h2 id="карты">Карты</h2>
<ul>
<li>
<p><a id="wn825_34640"></a>
 Дэвид Смит <a href="https://www.david-smith.org/blog/2026/04/29/maps-on-watchos/">рассказывает</a> :EN-s: о разработке вместе с Энди Алланом карты на основе OSM в <a href="https://itunes.apple.com/us/app/pedometer&#43;&#43;/id712286167">Pedometer++</a> — трекере ходьбы для Apple watchOS — длиной в шесть лет.</p>
</li>
<li>
<p><a id="wn825_34632"></a>
 Сайт Transform Transport <a href="https://app.transformtransport.org/15minCS/europe-map.html">опубликовал</a> :EN-s: интерактивную карту «15 Minute City Score», отображающую уровень пешеходной доуступности к основным услугам в европейских городах. Используются данные OpenStreetMap.</p>
</li>
<li>
<p><a id="wn825_34649"></a>
 Используя веб-приложение для сравнения адресов <a href="https://addresses.tillb.de/">OSM-ALKIS</a> :DE-s:, Алекс Шпритце <a href="https://troet.cafe/@AlexSpritzeOSM/116560131710346931">проанализировал</a> :DE-s: распределение недостающих адресных данных в границах федеральной земли Саксония-Анхальт. Результаты свидетельствуют о значительных различиях между муниципалитетами: от районов с высокими показателями, таких как Ингерслебен, в котором «всего» девять отсутствующих адресов, до таких муниципалитетов, как Гюстен, где в настоящее время на карту нанесено всего 3,8 % адресов.</p>
</li>
</ul>
<h2 id="osm-в-деле">OSM в деле</h2>
<ul>
<li><a id="wn825_34617"></a>
 Министерство туризма Сирии <a href="https://alnashra.org/map11/gis_syria2/syria_tourism.php">разработало</a> веб-карту, основанную на OpenStreetMap, которая показывает расположение достопримечательностей, туристических объектов и инвестиционных возможностей в Сирии.</li>
</ul>
<h2 id="программы">Программы</h2>
<ul>
<li>
<p><a id="wn825_34673"></a>
 HeiGIT <a href="https://climate-action.heigit.org/dashboard/plugin/traffic_emissions">представил</a> свой новый инструмент внутри <a href="https://climate-action.heigit.org/dashboard">Climate Action Navigator</a> для отслеживания уровня автомобильных выхлопов на территории Германии с помощью машинного обучения на данных OpenStreetMap.</p>
</li>
<li>
<p><a id="wn825_34672"></a>
 Grid2Poster — новый инструмент с открытым исходным кодом, который <a href="https://github.com/open-energy-transition/grid2poster">отображает</a> :EN-s: сети электропередач по данным OpenStreetMap в виде готовых к печати плакатов. Проект на языке Python использует GeoPandas, OSMnx и Matplotlib, работает в масштабах страны или всего континента, поддерживает отображение линий электропередач, кабелей, административных границ.</p>
</li>
<li>
<p><a id="wn825_34652"></a>
 Тобиас Йорданс <a href="https://grenzabgleich.osm-verkehrswende.org/">выпустил</a> :DE-s: Grenzabgleich — веб-инструмент, сравнивающий административные границы Германии в OpenStreetMap с официальными источниками данных страны. Для выявления расхождений и исправления данных используются, среди прочего, как коэффициент Жаккара и метрика Хаусдорфа.</p>
</li>
<li>
<p><a id="wn825_34622"></a>
 Проект CoMaps <a href="https://www.comaps.app/news/comaps-technical-changes/">сообщает</a> :EN-s: о крупных технических обновлениях: постепенном переходе с Objective C на Swift, внедрении Android-дизайна Material 3 и автоматической генерации карт.</p>
</li>
<li>
<p><a id="wn825_34648"></a>
 CoMaps <a href="https://www.comaps.app/news/2026-05-12/celebrating-the-first-comaps-birthday/">отпраздновал</a> :EN-s: свой первый день рождения.</p>
</li>
<li>
<p><a id="wn825_34619"></a>
 HeiGIT <a href="https://heigit.org/new-user-statistics-in-ohsomenow/">представляет</a> возможность просматривать статистику по отдельным пользователям в <a href="https://ohsome-now.heigit.org/dashboard#hashtag=&amp;start=2025-05-08T00:00:00Z&amp;end=2026-05-08T11:11:15Z&amp;interval=P1M&amp;active_topic=contributor&amp;countries=&amp;topics=contributor,edit,building,road&amp;osm_user=115612">ohsomeNOW</a>.</p>
</li>
<li>
<p><a id="wn825_34645"></a>
 Команда OpenStreetMap Ops сильно <a href="https://en.osm.town/@osm_tech/116561251606643070">ограничила</a> :EN-s: доступ QGIS к <code>tile.openstreetmap.org</code> после того, как массовое использование тайлов привело к нарушению работы сервиса для других пользователей. Команды OSM и QGIS работают над разделением сценария использования тайлов, а OpenStreetMap принимает пожертвования в виде серверов для расширения возможностей рендеринга тайлов.</p>
</li>
<li>
<p><a id="wn825_34635"></a>
 Шон Карапелла запустил <a href="https://paddlemap.net/">PaddleMap</a>, инструмент для построения маршрутов для водных транспортных средств. Он работает на BRouter и brouter-web, поддерживает прокладку маршрутов по водным путям и порталам и выделяет POI, связанные с греблей, такие как точки доступа, плотины и пороги.</p>
</li>
<li>
<p><a id="wn825_34671"></a>
 Trailmaps.app — веб-проект, который <a href="https://trailmaps.app">превращает</a> данные OpenStreetMap в удобные для мобильных устройств офлайн-карты сетей горных велосипедных маршрутов. Эти карты разработаны таким образом, чтобы соответствовать местным указателям на маршрутах, а не общим цветам сложности, и соответствующий генератор карт был опубликован с открытым исходным кодом. По словам разработчика, весь проект был создан в основном с помощью Claude AI.</p>
</li>
<li>
<p><a id="wn825_34624"></a>
 Новый юзерскрипт <a href="https://community.openstreetmap.org/t/userscript-to-add-multiple-custom-maps-to-id-editor/143679">позволяет</a> :EN-s: добавлять несколько пользовательских фоновых слоёв в редактор iD. Вместо многократного изменения одного пользовательского URL, маперы теперь могут легко переключаться между несколькими источниками тайлов.</p>
</li>
<li>
<p><a id="wn825_34655"></a>
 Мэнни Фред <a href="https://community.openstreetmap.org/t/vorstellung-hydrantmap-org-openstreetmap-hydrantenkarte/143804">представил</a> :DE-s: HydrantMap — <a href="https://hydrantmap.org/">веб-карту</a>, созданную Фабианом Флодманом для визуализации данных о гидрантах из OpenStreetMap. Автор вдохновлялся OsmHydrant.</p>
</li>
</ul>
<h2 id="программирование">Программирование</h2>
<ul>
<li>
<p><a id="wn825_34644"></a>
 darkonus <a href="https://www.openstreetmap.org/user/darkonus/diary/408655">приглашает</a> пользователей JOSM протестировать его плагин <em>Fillet Tools</em>, который может скруглять углы, подобно инструменту fillet в CAD-программах. Автор просит оставлять отзывы, сообщения об ошибках, случаях необычного поведения и предложения. Плагин можно установить вручную с <a href="https://gitlab.com/darkonus/josm-fillet-tools/-/releases/v0.1.0/">GitLab</a>.</p>
</li>
<li>
<p><a id="wn825_34618"></a>
 Матия Налис <a href="https://www.openstreetmap.org/user/Matija%20Nalis/diary/408636">делится</a> :EN-s: своим опытом поднятия экземпляра Panoramax для хорватского отделения OSM, включая аппаратное обеспечение, настройку Docker и интеграцию OSM OAuth2.</p>
</li>
<li>
<p><a id="wn825_34616"></a>
 Кристиан Квест <a href="https://forum.geocommuns.fr/t/storage-needs-for-a-panoramax-instance/3205">поделился</a> конкретными цифрами о потребностях экземпляров Panoramax в памяти. Анализ показывает, что 360°-изображения, в частности, значительно увеличивают потребность, поэтому планируется оптимизация.</p>
</li>
<li>
<p><a id="wn825_34637"></a>
 Рабочая группа по управлению OpenStreetMap <a href="https://github.com/openstreetmap/owg-website/pull/170">обновила</a> :EN-s: политику использования Nominatim. Изменения ещё больше ограничивают использование API для ИИ-агентов и вайб-кодинга.</p>
</li>
</ul>
<h2 id="релизы">Релизы</h2>
<ul>
<li>
<p><a id="wn825_34621"></a>
 В марте и апреле сайт <a href="https://onroutemap.de/de/">onroutemap.de</a> Нико Изенбека подвергся некоторым <a href="https://onroutemap.de/de/about">улучшениям</a>.</p>
<ul>
<li>В март появилась поддержка на французском и испанском языков, а личные избранные маршруты теперь можно экспортировать в форматы KML и GPX</li>
<li>В апрель добавлен слой порывов ветра в реальном времени на карте Текущие данные о порывах ветра (Open-Meteo) со скоростью и направлением, с цветовой кодировкой по Бофорту. Самой важной новой функцией, однако, является переход с OverPass на PostGIS и, таким образом, гораздо более высокая производительность при создании карт</li>
</ul>
</li>
<li>
<p><a id="wn825_34625"></a>
 Маркус Яшен —  нескольких <a href="https://mastodon.social/@mjaschen/116545565991016798">новых функциях</a> :EN-s: в грядущей версии <a href="https://bikerouter.de">bikerouter</a> 2026.1.</p>
</li>
<li>
<p><a id="wn825_34620"></a>
 Мартин Райфер <a href="https://en.osm.town/@tyr/116539161555937761">сообщает</a> :EN-s: о выпуске <a href="https://github.com/openstreetmap/iD/releases/tag/v2.40.0">iD 2.40</a> :EN-s:. В нём: новый внешний вид для общих для велосипедистов и пешеходов дорожек, динамические уровни детализации для круговых элементов, изменена работа с пресетами (автоматически удаляются те теги, которые не действительны для вновь выбранного пресета).</p>
</li>
<li>
<p><a id="wn825_34667"></a>
 В <a href="https://osmand.net/blog/osmand-web-1.03-released">OsmAnd Web 1.03</a> появивлись: показ маршрутов общественного траспорта, интеграция с Garmin Connect для автоматической синхронизации активности, Smart Folders для треков, улучшенная информация о POI, а также обновленные инструменты для управления и отображения треков GPX и избранного.</p>
</li>
<li>
<p><a id="wn825_34626"></a>
 Проект OSRM <a href="https://github.com/Project-OSRM/osrm-backend/releases/tag/v26.5.0">выпустил</a> версию 26.5.0 <code>osrm-backend</code>. В релизе добавлены в основной репозиторий обёртка для Python, система сборки переведена на vcpkg, уменьшены зависимости Boost, добавлена поддержка <code>winter_road</code> и <code>ice_road</code> в профилях маршрутизации и много других улучшений.</p>
</li>
<li>
<p><a id="wn825_34627"></a>
 Проект OSRM <a href="https://en.osm.town/@osrm/116540225411349846">сообщает</a> в Mastodon, что он экспериментирует с API изохрон.</p>
</li>
<li>
<p><a id="wn825_34668"></a>
 Мартин ван Эксел <a href="https://community.openstreetmap.org/t/overpass-api-performance-issues/140598/121">обновил</a> свою Python-библиотеку для Overpass API Обновление теперь требует от приложений установки заголовка User-Agent.</p>
</li>
<li>
<p><a id="wn825_34633"></a>
 Начиная с <a href="https://www.comaps.app/news/2026-05-06/Release-2026.05.06-release-notes/">CoMaps 2026.05.06</a> версии карт больше не привязаны к версии приложения, что позволяет пользователям обновлять карты без обновления приложения. Это позволит увеличить частоту обновления карт, которая теперь будет еженедельной.</p>
</li>
<li>
<p><a id="wn825_34623"></a>
 Команда Organic Maps <a href="https://organicmaps.app/news/2026-05-08/public-transport-stop-selection-not-overlapping-bookmark-labels-vietnam-malaysia-china-region-splits/">выпустила</a> майское обновление, которое позволяет просматривать на карте маршруты общественного транспорта на остановках.</p>
</li>
</ul>
<h2 id="а-вы-знаете-">А вы знаете …</h2>
<ul>
<li><a id="wn825_34654"></a>
 &hellip; о расширении для браузера от Ильи Зверева, которое <a href="https://github.com/Zverik/osmtags-editor">добавляет</a> кнопку «Edit tags» к каждому объекту на сайте OSM?</li>
</ul>
<h2 id="osm-в-прессе">OSM в прессе</h2>
<ul>
<li><a id="wn825_34656"></a>
 CHIP опубликовал комментарий, в котором <a href="https://www.chip.de/news/software/warum-tut-man-sich-sowas-an-hier-ist-google-maps-richtig-nutzlos_8fc5f71e-74b0-4490-9e4b-b941a0becd94.html">говорится</a> :DE-s:, что OpenStreetMap гораздо полезнее Google Карт при поиске мест рядом в незнакомой местности.</li>
</ul>
<h2 id="разное-о-картах">Разное о картах</h2>
<ul>
<li>
<p><a id="wn825_34642"></a>
 Калеб Робинсон и Айзек Корли <a href="https://geospatialml.com/posts/sentinel2-superresolution">написали</a> :EN-s: об использовании <a href="https://en.wikipedia.org/wiki/Gaussian_splatting">3D гауссового разбрызгивания</a> для повышения резкости изображений со спутника Sentinel-2. Метод работает за счёт использования небольших различий в расположении пикселей между разными пролётами спутника для извлечения дополнительной информации из изображений.</p>
</li>
<li>
<p><a id="wn825_34670"></a>
 Компании Ordnance Survey и GeoPlace <a href="https://www.owenboswarva.com/blog/post-addr86.htm">потребовали</a> :EN-s: удалить миллионы опубликованных в открытом доступе записей об адресах муниципальных советов Великобритании, заявив о правах интеллектуальной собственности от имени Ordnance Survey, GeoPlace и Royal Mail. Затронутые датасеты ранее были опубликованы под открытыми лицензиями 57 муниципалитетами.</p>
</li>
<li>
<p><a id="wn825_34636"></a>
 Последнее обновление Garmin «TopoActive Europe 2026.10» (карт, основанных на данных OpenStreetMap) <a href="https://forums.garmin.com/sports-fitness/cycling/f/edge-840-series/435572/saving-diagnostics-boot-loop-after-map-update-2026-10">вызывает</a> :EN-s: серьёзные проблемы с маршрутами на нескольких устройствах, <a href="https://gpsradler.de/news/vorsicht-kartenupdate-garmin-2026_10/">включая</a> :DE-s: сбои и бесконечные перезагрузки. Затронуты несколько моделей Edge. В качестве временного решения Garmin <a href="https://support.garmin.com/de-DE/?faq=Zx9gEvcPOs09nQGpXO64U7">рекомендует</a> :DE-s: перейти на более раннюю версию карты.</p>
</li>
</ul>
<h2 id="предстоящие-события">Предстоящие события</h2>
<table>
	<thead>
			<tr>
					<th>Страна</th>
					<th>Где</th>
					<th>Адрес</th>
					<th>Что</th>
					<th>Когда</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Acireale</td>
					<td>Mappiamo le Aci <a href="https://osmcal.org/event/4757/">:osmcalpic:</a></td>
					<td>2026-05-16 - 2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/us.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>New York</td>
					<td>East River Park at Corlears Hook</td>
					<td>NYC Mapper Picnic <a href="https://osmcal.org/event/4770/">:osmcalpic:</a></td>
					<td>2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chennai Corporation</td>
					<td>Hotel Nithya Amirtham, Mylapore Market, Chennai</td>
					<td>Mapping at Mylapore Market, Chennai <a href="https://osmcal.org/event/4743/">:osmcalpic:</a></td>
					<td>2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bologna</td>
					<td>aula 0.6, DICAM, Unibo, Viale del Risorgimento 2</td>
					<td>Unibo Mapathon OpenStreetMap 2026-05 <a href="https://osmcal.org/event/4756/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Mannheim</td>
					<td>RaumZeitLabor, Mannheim</td>
					<td>Rhein-Neckar OpenstreetMap Treffen <a href="https://osmcal.org/event/4742/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Webinaire de sensibilisation à OpenStreetMap pour les collectivités <a href="https://osmcal.org/event/4736/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Greater London</td>
					<td>Médecins Sans Frontières (MSF UK) Office</td>
					<td>Missing Maps London In-Person Mapathon <a href="https://osmcal.org/event/4787/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mid-Month (Without Training) Advanced Mappers [eng] <a href="https://osmcal.org/event/4245/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Lyon</td>
					<td>Tubà</td>
					<td><del>Réunion du groupe local de Lyon</del> <a href="https://osmcal.org/event/4307/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chemnitz</td>
					<td>Kaffeesatz, Chemnitz</td>
					<td>OSM-Stammtisch Chemnitz <a href="https://osmcal.org/event/4658/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bonn</td>
					<td>Dotty&rsquo;s</td>
					<td>200. OSM-Stammtisch Bonn <a href="https://osmcal.org/event/4356/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Lüneburger Mappertreffen (online) <a href="https://osmcal.org/event/4371/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>MJC de Vienne</td>
					<td>Rencontre des contributeurs de Vienne (38) <a href="https://osmcal.org/event/4777/">:osmcalpic:</a></td>
					<td>2026-05-20</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Online Missing Maps Mapathon ÄRZTE OHNE GRENZEN (AT/DE) <a href="https://osmcal.org/event/4772/">:osmcalpic:</a></td>
					<td>2026-05-20</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Karlsruhe</td>
					<td>Chiang Mai</td>
					<td>Stammtisch Karlsruhe <a href="https://osmcal.org/event/4715/">:osmcalpic:</a></td>
					<td>2026-05-20</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Editor iD - Parte II <a href="https://osmcal.org/event/4760/">:osmcalpic:</a></td>
					<td>2026-05-22</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Metz</td>
					<td>l’Arob@se</td>
					<td>Atelier du groupe local de Metz - Cartographions les services publics ! <a href="https://osmcal.org/event/4783/">:osmcalpic:</a></td>
					<td>2026-05-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Ferrara</td>
					<td>Ferrara</td>
					<td>Raccolta dati aree verdi @ Giornata Mondiale della Biodiversità 2026 - Citizen Science Ferrara <a href="https://osmcal.org/event/4716/">:osmcalpic:</a></td>
					<td>2026-05-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Navi Mumbai</td>
					<td></td>
					<td>OSM Mumbai Mapping Party No.10 (Trans-Harbour Line - North) <a href="https://osmcal.org/event/4319/">:osmcalpic:</a></td>
					<td>2026-05-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bologna</td>
					<td>Velostazione ExDynamo</td>
					<td>Compleanno di Wikipedia a Bologna 2026, con wikigita e mapping party in Bolognina e pranzo alla velostazione <a href="https://osmcal.org/event/4773/">:osmcalpic:</a></td>
					<td>2026-05-24</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4298/">:osmcalpic:</a></td>
					<td>2026-05-25</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Lyon</td>
					<td>Tubà</td>
					<td>Réunion du groupe local de Lyon <a href="https://osmcal.org/event/4791/">:osmcalpic:</a></td>
					<td>2026-05-26</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>Online</td>
					<td>OSM-Verkehrswende #75 <a href="https://osmcal.org/event/4785/">:osmcalpic:</a></td>
					<td>2026-05-26</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Würzburg</td>
					<td>FabLab Würzburg</td>
					<td>Würzburger OSM-Treffen <a href="https://osmcal.org/event/4788/">:osmcalpic:</a></td>
					<td>2026-05-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Düsseldorf</td>
					<td>Online bei <a href="https://meet.jit.si/OSM-DUS-2026">https://meet.jit.si/OSM-DUS-2026</a></td>
					<td>Düsseldorfer OpenStreetMap-Treffen (online) <a href="https://osmcal.org/event/4385/">:osmcalpic:</a></td>
					<td>2026-05-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bad Harzburg</td>
					<td>Braunschweiger OSM-Treffen Mappingtour: Zusammen Bad Harzburg mappen <a href="https://osmcal.org/event/4775/">:osmcalpic:</a></td>
					<td>2026-05-30</td>
			</tr>
	</tbody>
</table>
<p><em>Над этим выпуском работали: <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, Andrew Davidson, <a href="https://www.openstreetmap.org/user/TrickyFoxy">TrickyFoxy</a>, <a href="https://www.openstreetmap.org/user/derFred">derFred</a>, <a href="https://www.osm.org/user/izen57">izen57</a>, <a href="https://www.osm.org/user/mcliquid">mcliquid</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>Еженедельник OSM 823</title>
				<link>https://hugo.weeklyosm.eu/ru/archives/0823/</link>
				<pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/archives/0823/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/05/822.png" alt="Еженедельник OSM 823" /> 23.04.2026-29.04.2026
Картографирование Предложение, ожидающее комментариев: terminal=yes для грузовых терминалов и лучшего описания связанных видов транспорта и обрабатываемых грузов. Идёт голосование: route=safari для обозначения маршрутов в сафари-парках. Сообщество Кристиан Квест в интервью OpenCage рассказывает :EN-s: о планах Фонда Panoramax по координации открытой, федерированной платформы для уличных снимков и панорам. Инициатива направлена на развитие международного сотрудничества и черпает вдохновение у Фонда OpenStreetMap.
Также Кристиан Квест напоминает :EN-s:, что экземпляр Panoramax сервер сообщества OSM France принимает изображения из-за пределов страны только в целях тестирования, при этом сейчас уже почти половина всех изображений загружаются из других стран. Правление OSM France вскоре примет решение об удалении этих изображений, поскольку дисковое пространство заполнено на 80 %. Согласно последним данным, федерация Panoramax увеличилась :EN-s: на 10 экземпляров, на которых теперь размещено более 100 миллионов открыто лицензированных изображений улиц от более чем 2000 пользователей. Это отметил :EN-s: и Бастиан Грешаке Тзоварас на Mastodon.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/05/822.png" alt="Еженедельник OSM 823" /></p> <p>23.04.2026-29.04.2026</p>
<h2 id="картографирование">Картографирование</h2>
<ul>
<li><a id="wn823_34500"></a>
 Предложение, ожидающее комментариев:</li>
</ul>
<ul>
<li><a href="https://wiki.openstreetmap.org/wiki/Proposal:Freight_Terminal"><code>terminal=yes</code></a> для грузовых терминалов и лучшего описания связанных видов транспорта и обрабатываемых грузов.</li>
</ul>
<ul>
<li><a id="wn823_34499"></a>
 Идёт голосование:</li>
</ul>
<ul>
<li><code>route=safari</code> <a href="https://wiki.openstreetmap.org/wiki/Proposal:Safari_Route_Relation_Type#Voting">для обозначения</a> маршрутов в сафари-парках.</li>
</ul>
<h2 id="сообщество">Сообщество</h2>
<ul>
<li>
<p><a id="wn823_34506"></a>
 Кристиан Квест в интервью OpenCage <a href="https://blog.opencagedata.com/post/openstreetmap-interview-panoramax">рассказывает</a> :EN-s: о планах Фонда Panoramax по координации открытой, федерированной платформы для уличных снимков и панорам. Инициатива направлена на развитие международного сотрудничества и черпает вдохновение у Фонда OpenStreetMap.</p>
</li>
<li>
<p><a id="wn823_34539"></a>
 Также Кристиан Квест <a href="https://community.openstreetmap.org/t/osm-fr-panoramax-server-only-for-testing-if-outside-of-france/143428">напоминает</a> :EN-s:, что экземпляр Panoramax сервер сообщества OSM France принимает изображения из-за пределов страны только в целях тестирования, при этом сейчас уже почти половина всех изображений загружаются из других стран. Правление OSM France вскоре примет решение об удалении этих изображений, поскольку дисковое пространство заполнено на 80 %. Согласно последним данным, федерация Panoramax <a href="https://en.osm.town/@PanoramaxContribs/116476556609091368">увеличилась</a> :EN-s: на 10 экземпляров, на которых теперь размещено <a href="https://panoramax.fr/stats">более 100 миллионов</a> открыто лицензированных изображений улиц от более чем 2000 пользователей. Это <a href="https://en.osm.town/@gedankenstuecke@scholar.social/116476561676964776">отметил</a> :EN-s: и Бастиан Грешаке Тзоварас на Mastodon.</p>
</li>
<li>
<p><a id="wn823_34529"></a>
 9_tab написал о <a href="https://www.openstreetmap.org/user/9_tab/diary/408586">«Кварталах Женевы»</a> :FR-s: — картографическом спринте в <a href="https://www.openstreetmap.org/#map=14/46.20506/6.14312">этом городе</a> для организации точек <code>place=*</code> и сравнения кварталов с местными данными.</p>
</li>
</ul>
<h2 id="фонд-openstreetmap">Фонд OpenStreetMap</h2>
<ul>
<li>
<p><a id="wn823_34552"></a>
 Фонд OpenStreetMap <a href="https://osmfoundation.org/wiki/Board/Minutes/2026-01/2026_OSMF_budget">опубликовал</a> :EN-s: свой бюджет на 2026 год, утверждённый в январе. На данный момент прогнозируется около 822 000 фунтов стерлингов доходов и около 933 000 фунтов расходов (показатели могут быть пересмотрены в течение года). Основными статьями расходов являются финансирование персонала и подрядчиков, выплаты грантов и траты на поддержку инфраструктуры.</p>
</li>
<li>
<p><a id="wn823_34553"></a>
 OSMF <a href="https://osmfoundation.org/wiki/Monthly_Board_Meetings/Presentations">задокументировал</a> :EN-s: короткие презентации, проводимые во время заседаний общественного совета, и рассматривает возможность возродить эти беседы с сообществами маперов в этом году. Десятиминутные выступления дают представление о проектах и инициативах сообщества OSM.</p>
</li>
</ul>
<h2 id="события">События</h2>
<ul>
<li>
<p><a id="wn823_34515"></a>
 Сильвина Меритано и Бастиан Грешаке Цоварас <a href="https://scholar.social/@gedankenstuecke/116470842976993935">выступили с докладом</a> :ES-s: об OSM на Латиноамериканском фестивале по установке свободного программного обеспечения в Кордове. Их <a href="https://talks.tzovar.as/2026-04-25-flisol/">слайды и материалы</a> :ES-s: доступны онлайн.</p>
</li>
<li>
<p><a id="wn823_34519"></a>
 <a href="https://community.openstreetmap.org/t/hackweekend-in-karlsruhe-am-26-27-september-2026/143357">Объявлено</a> :DE-s: о проведении OSM Hackweekend в Карлсруэ 26–27 сентября 2026 года. <a href="https://wiki.openstreetmap.org/wiki/Karlsruhe_Hack_Weekend_September_2026">Приглашаются</a>  :EN-s::DE-s: к сотрудничеству над проектами разработчики и картографы.</p>
</li>
<li>
<p><a id="wn823_34521"></a>
 <a href="https://community.openstreetmap.org/t/osm-science-2026/143356">Открыт</a> :EN-s: приём работ для конференции OSM Science 2026, которая пройдёт в рамках State of the Map 2026 в Париже.</p>
</li>
<li>
<p><a id="wn823_34555"></a>
 Викиданные и тайваньское сообщество OSM <a href="https://diff.wikimedia.org/2026/04/29/wikidata-community-summit-2026-coscup-call-for-proposals/">открыли</a> :EN-s: приём заявок на совместный трек «State of the Map Taiwan 2026 / Wikidata Community Summit&quot; на COSCUP до 9 мая 2026 года.</p>
</li>
</ul>
<h2 id="oбразование">Oбразование</h2>
<ul>
<li>
<p><a id="wn823_34524"></a>
 IVIDES DATA предлагает возможность двух оплачиваемых вакансий по обновлению и переводу содержания курса «IVIDES.org&rsquo;s OpenStreetMap» на английский (американский, либо же британский) и испанский языки. Пожалуйста, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408582">ознакомьтесь</a> :EN-s::ES-s: с условиями и отправьте сопроводительное письмо до 8 мая 2026 года.</p>
</li>
<li>
<p><a id="wn823_34538"></a>
 IVIDES DATA® начинает <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408597">приём заявок</a> :PT-s: на участие в серии семинаров по OpenStreetMap (на португальском языке). Они охватывают такие темы, как картография с OSM, плагины для QGIS, веб-формы с KoboToolbox и веб-карты с uMap. Основная цель в этом году — предоставить участникам инструменты, необходимые для разработки небольших практических проектов. Организаторы считают, что таким образом знания, полученные с помощью этих бесплатных программ, будут лучше участниками усвоены.</p>
</li>
</ul>
<h2 id="osm-в-науке">OSM в науке</h2>
<ul>
<li><a id="wn823_34535"></a>
 HeiGIT <a href="https://heigit.org/new-paper-automated-road-crack-localization-for-spatially-guided-highway-maintenance/">представляет</a> :EN-s: исследование об автоматизированной локализации дорожных трещин для обслуживания автомагистралей по данным из OpenStreetMap. Исследование было <a href="https://doi.org/10.1111/tgis.70258">опубликовано</a> :EN-s: в журнале «Transactions in GIS30» за авторством Knoblauch, Muthusamy, Ghamisi и Zipf.</li>
</ul>
<h2 id="карты">Карты</h2>
<ul>
<li>
<p><a id="wn823_34556"></a>
 Кристоф Хорманн <a href="https://github.com/openstreetmap-carto/openstreetmap-carto/issues/5216">предлагает</a> изменить алгоритм выбора названия для объектов в картостиле OpenStreetMap Carto.</p>
</li>
<li>
<p><a id="wn823_34532"></a>
 Немецкая цифровая библиотека <a href="https://openbiblio.social/@archivportal/116475825682678225">опубликовала</a> :DE-s:, основываясь на архивах проекта <a href="https://www.archivportal-d.de/content/ueber-uns">Archivportal-D</a>, <a href="https://www.archivportal-d.de/themenportale/rechte-gewalt?lang=en">карту</a> :DE-s: актов экстремизма правых в Германии с 1945 года. Сама карта основана на OpenStreetMap и OpenHistoricalMap (в зависимости от временного периода).</p>
</li>
</ul>
<h2 id="osm-в-деле">OSM в деле</h2>
<ul>
<li>
<p><a id="wn823_34534"></a>
 ^[1]^ Зои Скайфорест <a href="https://hackaday.com/2026/04/28/payphone-tag-is-australias-new-national-sport/">сообщила</a> :EN-s: о новой игре в Австралии. В <a href="https://payphonetag.com">Payphone Tag</a> :EN-s:, разработанной <a href="https://www.al3x.au/">Алексом Олчином</a> :EN-s:, игроки набирают номер на различных городских таксофонах, чтобы захватить определённую территорию вокруг себя. Карта территорий, удерживаемых игроками, в режиме реального времени отображается на OpenStreetMap. За последние семь дней в игре приняли участие 800 игроков, а общее количество «захватов территорий» на данный момент составило 36 640.</p>
</li>
<li>
<p><a id="wn823_34551"></a>
 Леонардо Тексидо Кинтана <a href="https://dev.to/leonardo_tq_13f83601e8513/20000-taxi-rides-in-cuba-what-i-learned-building-on-organic-maps-3k9b">разработал</a> :EN-s: <a href="https://www.youtube.com/watch?v=CLcUh1Hq_Fs">систему</a> :ES-s: для организации поездок на такси на Кубе, используя данные OpenStreetMap и форк Organic Maps. Через приложение было осуществлено более 20 000 реальных поездок (и это во время топливного кризиса), оно работает на смартфонах с 1 ГБ оперативной памяти и 2G-соединением.</p>
</li>
</ul>
<h2 id="открытые-данные">Открытые данные</h2>
<ul>
<li>
<p><a id="wn823_34558"></a>
 В новом и открытом датасете GOWIRES <a href="https://www.nature.com/articles/s41597-026-07290-4">объединены</a> :EN-s: более 400 000 ветрогенераторов по всему миру с данными по историческим и планирующимся ветряным источникам энергии. Географические данные в основном базируются на OpenStreetMap и проверены по государственным реестрам.</p>
</li>
<li>
<p><a id="wn823_34533"></a>
 Центр гуманитарных данных Управления ООН по координации гуманитарных дел <a href="https://data.humdata.org/m/dataset/cod-ab-global">опубликовал</a> глобальный набор данных о субнациональных административных границах для 110 стран.</p>
</li>
</ul>
<h2 id="программы">Программы</h2>
<ul>
<li>
<p><a id="wn823_34525"></a>
 Из-за недавних проблем с публичными серверами Overpass Кай Джонсон <a href="https://community.openstreetmap.org/t/announcing-a-new-overpass-container-image/143376">опубликовал</a> :EN-s: новый образ Docker для Overpass, <a href="https://www.openstreetmap.org/user/Kai%20Johnson/diary/408583">позволяющий</a> :EN-s: запускать собственные экземпляры сервиса.</p>
</li>
<li>
<p><a id="wn823_34536"></a>
 HeiGIT <a href="https://ask.openrouteservice.org/t/deprecating-api-openrouteservice-org-in-favour-of-api-heigit-org/7912">объявил</a>, что URL <code>api.openrouteservice.org</code> упраздняется в пользу <code>api.heigit.org</code>. Хотя все сервисы и остаются неизменными, пользователям необходимо обновить свои приложения до августа 2026 года.</p>
</li>
<li>
<p><a id="wn823_34527"></a>
 Geo Observer <a href="https://geoobserver.de/2026/04/28/drawonmaps-osm-picturemap/">демонстрирует</a> :DE-s: приложение DrawonMaps. Оно определяет края загруженного изображения, обводит и заливает его по уличной сетке на OpenStreetMap.</p>
</li>
<li>
<p><a id="wn823_34548"></a>
 GéoDataMine упрощает <a href="https://geodatamine.fr/">извлечение</a> :FR-s: данных из OpenStreetMap на территории Франции в форматах CSV, GeoJSON, XSLX и Shapefile.</p>
</li>
<li>
<p><a id="wn823_34516"></a>
 Илья Зверев <a href="https://en.osm.town/@zverik/116473171306638653">сообщает</a> :EN-s:, что <a href="https://josm.openstreetmap.de/ticket/2710">тикет</a> :EN-s:, открытый 15 лет назад, по поводу поддержки нескольких учётных записей в JOSM был закрыт, а поддержка добавлена не будет. На 2023 году некоторые пользователи <a href="https://www.openstreetmap.org/user/M!dgard/diary/401874">обходят</a> :EN-s: это ограничение с помощью собственных скриптов, но данное такое работает только на UNIX- подобных системах.</p>
</li>
<li>
<p><a id="wn823_34509"></a>
 Проект osm2pgsql <a href="https://osm2pgsql.org/news/2026/04/25/ngi0-grant-for-osm2pgsql.html">объявил</a> :EN-s:, что получил грант от фонда NGI0 Commons Fund на проект <a href="https://osm2pgsql.org/project-coda/">Compact OpenStreetMap Data Archive</a> :EN-s: (CODA, проектное название) для снижения потребления оперативной и постоянной памяти <a href="https://github.com/osm2pgsql-dev/osm2pgsql">osm2pgsql</a> более эффективными форматами хранения.</p>
</li>
<li>
<p><a id="wn823_34514"></a>
 Цель проекта <a href="https://opengridworks.com/power-plants?bubbleScale=0.65&amp;layers=tx%2Cdatacenters%2Chpoints%2CrowTx%2CrowSubs&amp;panel=closed">OpenGridWorks</a>, <a href="https://open.substack.com/pub/alpoma/p/opengridworks-un-alucinante-mapa">возглавляемом</a> :ES-s: Алехандро Поланко, — отображение энергоинфраструктуры с помощью CARTO и OpenStreetMap: электростанции, линии электропередач, подстанции, газопроводы, центры обработки данных, планируемые проекты по передаче электроэнергии, маршруты подводных кабелей, риски наводнений.</p>
</li>
</ul>
<h2 id="программирование">Программирование</h2>
<ul>
<li>
<p><a id="wn823_34541"></a>
 Candid Dauth <a href="https://www.openstreetmap.org/user/Candid%20Dauth/diary/408585">представляет</a> :EN-s: новый <a href="https://github.com/FacilMap/openstreetmap-tile-server">форк</a> <code>openstreetmap-tile-server</code>, который разделяет базу данных и рендеринг, поддерживая современные возможности <code>osm2pgsql</code>.</p>
</li>
<li>
<p><a id="wn823_34526"></a>
 Евгений Арбатов <a href="https://www.openstreetmap.org/user/Evgeny%20Arbatov/diary/408569">разработал</a> :EN-s: <code>vibe mapping</code> — инструмент для анализа общей атмосферы (<em>вайба</em>) мест на данных OpenStreetMap. Территория делится на шестиугольники H3, затем рассчитываются совокупные метрики по каждому шестиугольника. На основе этих показателей модель искусственного интеллекта генерирует короткое, в одно предложение, описание атмосферы места. Код <a href="https://github.com/evgeniyarbatov/vibe-mapping">доступен</a> на GitHub.</p>
</li>
<li>
<p><a id="wn823_34540"></a>
 NieWnen <a href="https://www.openstreetmap.org/user/NieWnen/diary/408589">публикует</a> :EN-s: скрипт, который фильтрует файлы репликации <code>.osc</code> по границам <code>.poly</code> для поддержания региональных баз данных в актуальном состоянии с помощью <code>osm2pgsql</code>. Этот подход предлагает альтернативу экземплярам Overpass и обеспечивает более гибкую самостоятельную обработку данных. Код <a href="https://github.com/praszuk/osm-replication-osc-poly-filter">доступен</a> на GitHub.</p>
</li>
<li>
<p><a id="wn823_34554"></a>
 Марк Литвинчик <a href="https://tech.marksblogg.com/reverse-geocoding-overture-maps.html">представляет</a> :EN-s: прототип обратного геокодирования на основе Overture Maps. Он извлекает коды стран и ближайшие адреса без использования внешнего API. Наборы данных также включают данные OpenStreetMap и обрабатываются локально.</p>
</li>
</ul>
<h2 id="релизы">Релизы</h2>
<ul>
<li>
<p><a id="wn823_34557"></a>
 Нильс Нольде <a href="https://github.com/valhalla/valhalla/releases/tag/3.7.0">выпустил</a> :EN-s: Valhalla 3.7.0 с мультимодальными маршрутами, поддержкой OSM XML и дополнительные метаданные. Релиз также содержит многочисленные исправления ошибок и изменения в компонентах обработки данных.</p>
</li>
<li>
<p><a id="wn823_34508"></a>
 В <a href="https://route.crafter.seen.one/">Route-Crafter</a> версии 0.2.4 <a href="https://github.com/seen-one/Route-Crafter/releases/tag/v0.2.4">улучшена</a> :EN-s: работа с очень длинными маршрутами, исправлены проблемы с мобильным интерфейсом и добавлены предупреждения об изменении настроек. Также обновлены функции настройки кнопки начала маршрута и улучшена визуализация уже пройденного пути.</p>
</li>
<li>
<p><a id="wn823_34517"></a>
 Маркус Яшен <a href="https://www.marcusjaschen.de/en/blog/2026/bikerouter-route-manager/">опубликовал</a> :EN-s: новый менеджер маршрутов для <a href="https://bikerouter.de/">Bikerouter</a>, позволяющий пользователям сохранять и организовывать маршруты как в браузере, так и на сервере.</p>
</li>
</ul>
<h2 id="а-вы-знаете-">А вы знаете …</h2>
<ul>
<li>
<p><a id="wn823_34560"></a>
 &hellip; что <a href="https://www.bikemap.net">Bikemap.net</a> позволяет пользователям планировать велосипедные маршруты по всему миру, используя данные OpenStreetMap?</p>
</li>
<li>
<p><a id="wn823_34550"></a>
 &hellip; что Skaringa <a href="https://www.openstreetmap.org/user/skaringa/diary/408596">разработал</a> :DE-s: карту речных бассейнов Центральной Европы по данным OpenStreetMap?</p>
</li>
</ul>
<h2 id="osm-в-прессе">OSM в прессе</h2>
<ul>
<li>
<p><a id="wn823_34559"></a>
 <a href="https://gpsradler.de/ratgeber/top-fahrrad-tourenplaner-web/">Недавнее</a> :DE-s: сравнение велосипедных онлайн-навигаторов подчеркнуло, что Bikerouter (основанный на BRouter) является мощным и полностью бесплатным инструментом с широкими возможностями построения маршрутов. <a href="https://bikerouter.de">Bikerouter.de</a>, созданный Маркусом Яшеном, <a href="https://gpsradler.de/praxistest/bikerouter-tourenplaner-test/">опирается</a> :DE-s: на данные OpenStreetMap для точной прокладки маршрута и предлагает расширенные возможности настройки и экспорта в форматы GPX или GeoJSON.</p>
</li>
<li>
<p><a id="wn823_34537"></a>
 Статья Анны Бизелли на netzpolitik.org <a href="https://netzpolitik.org/2026/wandern-radfahren-frei-und-dezentral-ins-gruene/">обозревает</a> :DE-s: некоторые нацеленные на конфиденциальность альтернативы коммерческим навигационным приложениям, включая несколько, основанных на OpenStreetMap. Среди главных преимуществ: децентрализованный подход и возможность использования в автономном режиме.</p>
</li>
<li>
<p><a id="wn823_34513"></a>
 The Rail Agenda <a href="https://open.substack.com/pub/therailagenda/p/oxford-and-cambridge-to-get-direct">отмечает</a> :EN-s:, что сегодня Оксфорд и Кембридж не имеют прямого железнодорожного сообщения. Восточно-западная железная дорога (East West Rail) восстановила бы его четырьмя поездами в час. Выводы показаны на карте OSM.</p>
</li>
<li>
<p><a id="wn823_34523"></a>
 Джо Федева <a href="https://www.howtogeek.com/android-app-gives-you-points-for-fixing-your-local-open-source-map/">рассказала</a> :EN-s: о приложении <a href="https://streetcomplete.app/">StreetComplete</a>, которое вознаграждает пользователей баллами за вклад в OpenStreetMap. Концепция призвана создать дополнительные стимулы для изменения и исправления картографических данных.</p>
</li>
</ul>
<h2 id="разное-о-картах">Разное о картах</h2>
<ul>
<li>
<p><a id="wn823_34512"></a>
 Издание Crust News <a href="https://open.substack.com/pub/crustiandaily/p/apple-maps-has-removed-place-names">заметило</a> :EN-s:, что на Apple Картах больше перестали отображаться названия многих городов и деревень Ливана. Удаления затрагивают не только территорию боевых действия с Израилем, но всю страну. Остались лишь несколько крупных городов такие как Бейрут, Сур (Тир), Сайда.</p>
</li>
<li>
<p><a id="wn823_34531"></a>
 В городе Порту состоится 17-я Иберийская конференцая по инфраструктуре пространственных данных <a href="https://www.dgterritorio.gov.pt/jiide2026/Default.aspx">JIIDE</a> :PT-s: с 11 по 13 ноября 2026 года. В рамках темы «Инфраструктура пространственных данных (SDI) в меняющемся мире» до 10 июня объявлен <a href="https://www.dgterritorio.gov.pt/apresentacao-de-resumos-prazo-10-de-junho">приём</a> :PT-s: заявок.</p>
</li>
<li>
<p><a id="wn823_34501"></a>
 <a href="https://www.ncei.noaa.gov/maps/bathymetry/?xmax=4.122&amp;xmin=-8.189&amp;ymax=55.123&amp;ymin=42.326">Bathymetric Data Viewer</a> :EN-s: — интерактивная карта, на которой можно найти данные батиметрической съёмки, а также цифровые <a href="https://www.ncei.noaa.gov/news/explore-sea-floor-ncei-modernized-portal">модели рельефа</a> :EN-s: из Национального центра экологической информации NOAA (он же NCEI). Также <a href="https://www.ncei.noaa.gov/maps/iho_dcdb/">доступен</a> :EN-s: геопросмотрщик со слоями из Центра данных цифровой батиметрии IHO.</p>
</li>
<li>
<p><a id="wn823_34530"></a>
 Согласно предложенному <a href="https://www.bundesgesundheitsministerium.de/service/gesetze-und-verordnungen/detail/notfallreform">Закону о реформе службы скорой помощи</a> :DE-s: &raquo;&gt;<a href="https://www-bundesgesundheitsministerium-de.translate.goog/service/gesetze-und-verordnungen/detail/notfallreform?_x_tr_sl=auto&amp;_x_tr_tl=RU">:RU-t:</a>, Федеральное министерство здравоохранения Германии планирует создать государственный реестр уличных дефибрилляторов.</p>
</li>
<li>
<p><a id="wn823_34507"></a>
 Йеспер Зедлиц (Jesper Zedlitz) <a href="https://open-north.de/blog/2026-04-24_hvd/">анализирует</a> :DE-s: принятые два года назад в Германии требования Европейского союза к высокоценными наборам данных. Он выявил значительные различия между федеральными землями, пробелы в формулировках, практику внедрения и вопросы категоризации.</p>
</li>
<li>
<p><a id="wn823_34522"></a>
 Габриэль Бруни <a href="https://placesjournal.org/article/the-disappearance-of-the-public-bench/">в статье</a> :EN-s: на сайте «Places Journal», исследуется роль общественных скамеек и их исчезновение в городах, а также подчёркивается их социальная и пространственная значимость. Статья последняя в серии «Описывая город» (Writing the City) — результат сотрудничества между «Places Journal» и Программой искусства и культуры Колумбийской школы журналистики. В OpenStreetMap скамейки обозначаются тегом <a href="https://wiki.openstreetmap.org/wiki/Tag:amenity%3Dbench"><code>amenity=bench</code></a>. С 2021 года реализуется <a href="https://wiki.openstreetmap.org/wiki/Proposal:Hostile_Architecture">предложение</a> по тегированию <a href="https://wiki.openstreetmap.org/wiki/Hostile_architecture#hostile_benches">«враждебной» архитектуры</a>. Пример применения этой концепции: специально максимально неудобные для сна на них скамейки или другие неровные поверхности.</p>
</li>
</ul>
<h2 id="предстоящие-события">Предстоящие события</h2>
<table>
	<thead>
			<tr>
					<th>Страна</th>
					<th>Где</th>
					<th>Адрес</th>
					<th>Что</th>
					<th>Когда</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Essen</td>
					<td>Linuxhotel Essen</td>
					<td>FOSSGIS-OSM-Communitytreffen im Linuxhotel <a href="https://osmcal.org/event/4121/">:osmcalpic:</a></td>
					<td>2026-04-30 - 2026-05-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://www.weeklyosm.eu/wp-content/uploads/2017/11/cn.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>大理市</td>
					<td>三月街集市</td>
					<td>大理三月民族节 <a href="https://osmcal.org/event/4751/">:osmcalpic:</a></td>
					<td>2026-05-01 - 2026-05-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Augsburg</td>
					<td>Augsburger Linux-Infotag 2026</td>
					<td>Workshop: JOSM - Java OpenStreetMap Editor - Eine Einführung <a href="https://osmcal.org/event/4700/">:osmcalpic:</a></td>
					<td>2026-05-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4116/">:osmcalpic:</a></td>
					<td>2026-05-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Sovigliana-Vinci</td>
					<td>Mappando si Vinci! - 2 Maggio 2026 <a href="https://osmcal.org/event/4678/">:osmcalpic:</a></td>
					<td>2026-05-02 - 2026-06-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Salzburg</td>
					<td>Bewohnerservice Elisabeth-Vorstadt</td>
					<td>OSM-Treffpunkt <a href="https://osmcal.org/event/4467/">:osmcalpic:</a></td>
					<td>2026-05-05</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum 0</td>
					<td>Braunschweiger Mappertreffen im Stratum 0 Hackerspace <a href="https://osmcal.org/event/4633/">:osmcalpic:</a></td>
					<td>2026-05-05</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mapathon (with Training) Beginner Friendly (Online) [eng] <a href="https://osmcal.org/event/4233/">:osmcalpic:</a></td>
					<td>2026-05-05</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>iD Community Chat <a href="https://osmcal.org/event/4733/">:osmcalpic:</a></td>
					<td>2026-05-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stuttgart</td>
					<td>Stuttgart</td>
					<td>Stuttgarter OpenStreetMap-Treffen <a href="https://osmcal.org/event/4679/">:osmcalpic:</a></td>
					<td>2026-05-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/us.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Richmond</td>
					<td>Shockoe Bottom</td>
					<td>Surveillance mapping with MapRVA <a href="https://osmcal.org/event/4682/">:osmcalpic:</a></td>
					<td>2026-05-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Editor iD - Parte I <a href="https://osmcal.org/event/4740/">:osmcalpic:</a></td>
					<td>2026-05-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>online</td>
					<td>SOSM Association Annual Meeting <a href="https://osmcal.org/event/4556/">:osmcalpic:</a></td>
					<td>2026-05-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Madurai</td>
					<td>Madurai Startups Spaces</td>
					<td>OSM Madurai Armchair mapping party <a href="https://osmcal.org/event/4767/">:osmcalpic:</a></td>
					<td>2026-05-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/07/dk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>København</td>
					<td>Cafe Bevar&rsquo;s</td>
					<td>OSMmapperCPH <a href="https://osmcal.org/event/4638/">:osmcalpic:</a></td>
					<td>2026-05-10</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Kori&rsquo;s, Humayunpur, Delhi</td>
					<td>OSM Delhi Mapping Party No.29 (South Zone) <a href="https://osmcal.org/event/4350/">:osmcalpic:</a></td>
					<td>2026-05-10</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4297/">:osmcalpic:</a></td>
					<td>2026-05-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zürich</td>
					<td>Bitwäscherei Zürich</td>
					<td>187. OSM-Stammtisch Zürich <a href="https://osmcal.org/event/4741/">:osmcalpic:</a></td>
					<td>2026-05-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #88 <a href="https://osmcal.org/event/4324/">:osmcalpic:</a></td>
					<td>2026-05-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Magdeburg</td>
					<td>Netz39 e.V. , Leibnizstraße 32,  39104 Magdeburg</td>
					<td>1. OSM Stammtisch Magdeburg <a href="https://osmcal.org/event/4734/">:osmcalpic:</a></td>
					<td>2026-05-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hamburg</td>
					<td>Voraussichtlich: &ldquo;Variable&rdquo;, Karolinenstraße 23</td>
					<td>Hamburger Mappertreffen <a href="https://osmcal.org/event/4694/">:osmcalpic:</a></td>
					<td>2026-05-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>temporärhaus</td>
					<td>OSM-Stammtisch Ulm/Neu-Ulm <a href="https://osmcal.org/event/4721/">:osmcalpic:</a></td>
					<td>2026-05-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Maison des associations de Bayonne - salle Valmont</td>
					<td>Rencontre Mapadour <a href="https://osmcal.org/event/4758/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Praha</td>
					<td>Seznam.cz</td>
					<td>Pražský mapathon s Lékaři bez hranic v Seznam.cz <a href="https://osmcal.org/event/4720/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2015/07/nl.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Amsterdam</td>
					<td>TomTom HQ</td>
					<td>2026 Spring End Maptime <a href="https://osmcal.org/event/4703/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>München</td>
					<td>Echardinger Einkehr</td>
					<td>Münchner OSM-Treffen <a href="https://osmcal.org/event/4342/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Mapaton - Marsh <a href="https://osmcal.org/event/4729/">:osmcalpic:</a></td>
					<td>2026-05-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/06/sk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Žilina</td>
					<td>Fakulta riadenia a informatiky UNIZA</td>
					<td>Missing Maps mapathon Žilina #22 <a href="https://osmcal.org/event/4762/">:osmcalpic:</a></td>
					<td>2026-05-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Acireale</td>
					<td>Mappiamo le Aci <a href="https://osmcal.org/event/4757/">:osmcalpic:</a></td>
					<td>2026-05-16 - 2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chennai Corporation</td>
					<td>Hotel Nithya Amirtham, Mylapore Market, Chennai</td>
					<td>Mapping at Mylapore Market, Chennai <a href="https://osmcal.org/event/4743/">:osmcalpic:</a></td>
					<td>2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bologna</td>
					<td>aula 0.6, DICAM, Unibo, Viale del Risorgimento 2</td>
					<td>Unibo Mapathon OpenStreetMap 2026-05 <a href="https://osmcal.org/event/4756/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Mannheim</td>
					<td>RaumZeitLabor, Mannheim</td>
					<td>Rhein-Neckar OpenstreetMap Treffen <a href="https://osmcal.org/event/4742/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
	</tbody>
</table>
<p><em>Над этим выпуском работали: <a href="https://www.openstreetmap.org/user/Nakaner">Nakaner</a>, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, Andrew Davidson, <a href="https://www.openstreetmap.org/user/TrickyFoxy">TrickyFoxy</a>, <a href="https://www.osm.org/user/izen57">izen57</a>, <a href="https://www.osm.org/user/mcliquid">mcliquid</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>Еженедельник OSM 815</title>
				<link>https://hugo.weeklyosm.eu/ru/archives/0815/</link>
				<pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/archives/0815/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/03/815.jpg" alt="Еженедельник OSM 815" /> 26.02.2026-04.03.2026
О нас StreetComplete теперь :EN-s: будет извещать о выходе нового выпуска weeklyOSM. Также в этом обновлении исправлены проблемы с расчётом статистики, появились уведомления об OSM-мероприятиях поблизости из OpenStreetMap Calendar и возможность настраивать эти уведомления. Картографирование Джеймс Уир начал обсуждение противоречащих друг другу определений тега wetland=tidalflat. Картографические акции [^1^] Daniele запустил :IT-s:&raquo;&gt;:RU-t: экземпляр утилиты Podoma на платформе облачных сервисов Викимедии :EN-s: для отслеживания проекта месяца :IT-s: — инициативы итальянского сообщества OpenStreetMap.
Завершилась февральская кампания :IT-s: по картографированию от итальянского сообщества OpenStreetMap. Благодаря участникам, на карту было добавлено 100 тыс. уличных фонарей, включая даже тип лампочек и их угол поворота.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/03/815.jpg" alt="Еженедельник OSM 815" /></p> <p>26.02.2026-04.03.2026</p>
<h2 id="о-нас">О нас</h2>
<ul>
<li>StreetComplete <a href="https://github.com/streetcomplete/StreetComplete/pull/6728">теперь</a> :EN-s: будет извещать о выходе нового выпуска weeklyOSM. Также в этом обновлении исправлены проблемы с расчётом статистики, появились уведомления об OSM-мероприятиях поблизости из <a href="https://osmcal.org">OpenStreetMap Calendar</a> и возможность настраивать эти уведомления.</li>
</ul>
<h2 id="картографирование">Картографирование</h2>
<ul>
<li>Джеймс Уир начал <a href="https://www.openstreetmap.org/user/jwheare/diary/408308">обсуждение</a> противоречащих друг другу определений тега <code>wetland=tidalflat</code>.</li>
</ul>
<h2 id="картографические-акции">Картографические акции</h2>
<ul>
<li>
<p>[^1^] Daniele <a href="https://community.openstreetmap.org/t/dashboard-podoma-per-il-progetto-del-mese/141779">запустил</a> :IT-s:&raquo;&gt;<a href="https://community-openstreetmap-org.translate.goog/t/dashboard-podoma-per-il-progetto-del-mese/141779?_x_tr_sl=auto&amp;_x_tr_tl=RU">:RU-t:</a> экземпляр утилиты <a href="https://wiki.openstreetmap.org/wiki/Podoma">Podoma</a> на платформе <a href="https://wikitech.wikimedia.org/wiki/Help:Cloud_Services_introduction">облачных сервисов Викимедии</a> :EN-s: для отслеживания <a href="https://wiki.openstreetmap.org/wiki/IT:Italia/Progetto_del_Mese">проекта месяца</a> :IT-s: — инициативы итальянского сообщества OpenStreetMap.</p>
</li>
<li>
<p>Завершилась февральская <a href="https://community.openstreetmap.org/t/progetto-del-mese-febbraio-2026-lampioni/141180/61">кампания</a> :IT-s: по картографированию от итальянского сообщества OpenStreetMap. Благодаря участникам, на карту было добавлено 100 тыс. уличных фонарей, включая даже тип лампочек и их угол поворота.</p>
</li>
</ul>
<h2 id="сообщество">Сообщество</h2>
<ul>
<li>
<p>В своём последнем интервью об OpenStreetMap команда OpenCage <a href="https://blog.opencagedata.com/post/openstreetmap-interview-dwinnovation">обсудила</a> :EN-s: с Deutsche Welle Innovation их разработку под названием SPOT, которая позволяет находить какое-либо место в городе по описанию объектов рядом с ним. Дискуссия развернулась вокруг того, как возник проект, технических деталей реализации и что по итогу смогли вынести для себя журналисты после года использования SPOT.</p>
</li>
<li>
<p>Межведомственное управление Франции по цифровым технологиям <a href="https://www.numerique.gouv.fr/sinformer/blog/la-fabrique-du-libre-panoramax-de-lutopie-a-linfrastructure-publique/">опубликовало</a> :FR-s: беседу с Кристианом Квестом о проекте Panoramax. В ней затрагиваются темы старта и разработки на ранних этапах, обсуждаются различные трудности по созданию активного пользовательского сообщества и его судьбе спустя годы.</p>
</li>
<li>
<p>Группа энтузиастов MapRVA <a href="https://en.osm.town/@yesterdays_bot">запустила</a> бота The Yesterdays в Мастодоне. Каждые два часа он выкладывает архивные исторические фотографии города Ричмонд (столицы штата Вирджиния) вместе с геопозицией на современных картах OSM.</p>
</li>
</ul>
<h2 id="фонд-openstreetmap">Фонд OpenStreetMap</h2>
<ul>
<li>Совет фонда OpenStreetMap официально <a href="https://en.osm.town/@openstreetmap/116165330892920654">представил</a> :EN-s: свои замечания по предложению Консорциума по открытым геоданным (Open Geospatial Consortium) о стандартизации глобальной системы географических координат (GERS) разработки Overture Maps. Фонд OSM не возражает против концепции глобальной системы географических идентификаторов, однако указывает, что географическая реальность не может быть сведена к одному авторитетному источнику. По мнению совета OSM, знания об окружающем мире создаются не только в центрах обработки данных корпораций, но и благодаря усилиям многих добровольцев по всему миру, которые картографируют улицы, районы и окружающую их среду. Поэтому фонд OSM считает, что любой стандарт, которому необходимо одобрение консорциума, должен быть достаточно гибким, чтобы учитывать как централизованные, так и децентрализованные, то есть управляемые сообществом источники геоданных.</li>
</ul>
<h2 id="карты">Карты</h2>
<ul>
<li>Проект OpenStreetMap Americana <a href="https://community.openstreetmap.org/t/osm-americana-your-local-language-companion/141757">улучшает</a> :EN-s: поддержку диалектов и многоязычности. Веб-разработчики могут установить утилиту <a href="https://github.com/osm-americana/diplomat/">Diplomat</a> для экспорта языковых меток из OSM Americana на карты MapLibre.</li>
</ul>
<h2 id="программы">Программы</h2>
<ul>
<li>
<p>GanderPL <a href="https://www.openstreetmap.org/user/GanderPL/diary/408286">разработал</a> :EN-s: MCP-сервер для тегирования OSM объектов, основой для которого стал проект <a href="https://github.com/openstreetmap/id-tagging-schema">iD Tagging Schema</a> редактора iD.</p>
</li>
<li>
<p>Conveyal <a href="https://medium.com/conveyal-blog/introducing-osmix-365c4b4332ef">разработал</a> :EN-s: Osmix — <a href="https://github.com/conveyal/osmix">набор библиотек</a> для просмотра данных, поиска по ним, а также работы с форматом OpenStreetMap PBF прямо в браузере (все вычисления производятся локально, вне сторонних серверов).</p>
</li>
<li>
<p>Sarath Sabarish <a href="https://www.openstreetmap.org/user/sarath%20sabarish/diary/408305">демонстрирует</a> :EN-s: работу собственной утилиты SafeStreets на примере таиландского города Чиангмай: отсутствие пешеходных переходов (<code>highway=crossing</code>) приводит к низкой оценке даже в случае хорошо картографированных улиц. Для геокодирования используются Nominatim, для получения данных - Overpass API.</p>
</li>
</ul>
<h2 id="программирование">Программирование</h2>
<ul>
<li>
<p>pascal_n <a href="https://neis-one.org/2026/03/flappy-birds-coding-assistants">рассказал</a> :EN-s:, как ИИ-агенты справляются с задачами кодирования, будучи встроенными прямо в среду разработки, на примере создания аналога мобильной игры Flappy Birds и веб-страницы с картой OSM, слоями GeoJSON и WMS и так далее. В статье сравниваются Microsoft Copilot, OpenAI Codex и Anthropic Claude, а результаты подтолкнули автора к тому, чтобы попробовать такой вайб-кодинг со своими студентами.</p>
</li>
<li>
<p>HeiGIT <a href="https://heigit.org/how-street-level-imagery-and-deep-learning-are-helping-map-global-infrastructure">поделились рассуждениями</a> :EN-s:, как использование съёмки местности вместе с методами глубокого обучения помогает находить и картографировать критически важную инфраструктуру, данных о которой нет в существующих базах. Применяя описанные методы, можно эффективней классифицировать дорожное покрытие, детектировать мусор, замерять габариты тротуаров или строить маршруты с учётом актуальных погодных условий.</p>
</li>
</ul>
<h2 id="osm-в-прессе">OSM в прессе</h2>
<ul>
<li>Петя Кангалова, старший менеджер по технологическому сотрудничеству в HOT, <a href="https://lwn.net/Articles/1057691/">рассказала</a> :EN-s:, как общественная организация сумела создать сложный технический продукт вокруг OpenStreetMap, призванный упростить картографирование территорий именно местными жителями, облегчить глобальные гуманитарные работы, устранение последствий стихийных бедствий и техногенных катастроф.</li>
</ul>
<h2 id="разное-о-картах">Разное о картах</h2>
<ul>
<li>
<p>НАСА и компания <a href="https://dev.global/">DevGlobal</a> проведут онлайн-мероприятие, посвящённое <a href="https://nasalifelines.org/data-studios/">совместной работе</a> :EN-s: по устранению таких чрезвычайных происшествий, как пожары, наводнения и оползни. Встреча длительностью в один час пройдёт 11.03.2026 в 15:00 по UTC. <a href="https://nasalifelines.org/community-connect-sign-up/">Регистрация</a> бесплатна.</p>
</li>
<li>
<p>Chromy <a href="https://news.ycombinator.com/item?id=47205637">рассказал</a> :EN-s: про сайт <a href="https://atlas.flexport.com/">Flexport Atlas</a>. Это карта, частично использующая данные OpenStreetMap и на которой показываются грузовые суда (включая информацию о швартовке, стоянке или рейсе), а также порты и самолёты. Информация об объектах обновляется каждые 2 часа.</p>
</li>
</ul>
<h2 id="предстоящие-события">Предстоящие события</h2>
<ul>
<li>
<table>
	<thead>
			<tr>
					<th>Страна</th>
					<th>Где</th>
					<th>Адрес</th>
					<th>Что</th>
					<th>Когда</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Hogeschool Odissee Hospitaalstraat 23 Sint-Niklaas</td>
					<td>Vereniging Leraars Aardrijkskunde (VLA) conference 2026 <a href="https://osmcal.org/event/4522/">:osmcalpic:</a></td>
					<td>2026-03-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2017/06/au.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Perth</td>
					<td>Espresso Perk U Later</td>
					<td>Social Mapping Sunday: Moort-ak Waadiny / Wellington Square Perth <a href="https://osmcal.org/event/4539/">:osmcalpic:</a></td>
					<td>2026-03-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2017/06/au.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Perth</td>
					<td>Espresso Perk U Later</td>
					<td>Social Mapping Sunday: Moort-ak Waadiny / Wellington Square Perth <a href="https://osmcal.org/event/4540/">:osmcalpic:</a></td>
					<td>2026-03-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/07/dk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>København</td>
					<td>Cafe Bevar&rsquo;s</td>
					<td><del>OSMmapperCPH</del> <a href="https://osmcal.org/event/4479/">:osmcalpic:</a></td>
					<td>2026-03-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Books and Beans Café, Mayur Vihar Phase 1</td>
					<td>OSM Delhi Mapping Party No.27 (East Zone) <a href="https://osmcal.org/event/4348/">:osmcalpic:</a></td>
					<td>2026-03-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/ca.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>London</td>
					<td>Social Sciences Centre - Western University</td>
					<td>Friends of MSF UWO Mapathon <a href="https://osmcal.org/event/4517/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Brno</td>
					<td>Geografický ústav, PřF MUNI, Brno</td>
					<td>Březnový brněnský Missing Maps Mapathon na Geografickém ústavu <a href="https://osmcal.org/event/4512/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4293/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Grenoble</td>
					<td>La Turbine Coop</td>
					<td>Découverte d&rsquo;OpenStreetMap <a href="https://osmcal.org/event/4563/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #86 <a href="https://osmcal.org/event/4322/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/es.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zaragoza</td>
					<td>Online</td>
					<td>Mappy Hour OSM España <a href="https://osmcal.org/event/4602/">:osmcalpic:</a></td>
					<td>2026-03-10</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hamburg</td>
					<td>Voraussichtlich: &ldquo;Variable&rdquo;, Karolinenstraße 23</td>
					<td>Hamburger Mappertreffen <a href="https://osmcal.org/event/4399/">:osmcalpic:</a></td>
					<td>2026-03-10</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://www.weeklyosm.eu/wp-content/uploads/2018/11/ie.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Cork</td>
					<td>Logitech, Cork, Ireland</td>
					<td><del>Logitech Missing Maps - Office Mapathon</del> <a href="https://osmcal.org/event/4510/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/us.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Reston</td>
					<td>George Mason University, HUB VIP 3</td>
					<td>The GAIN Mapathon <a href="https://osmcal.org/event/4531/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zürich</td>
					<td>Bitwäscherei Zürich</td>
					<td>185. OSM-Stammtisch Zürich <a href="https://osmcal.org/event/4450/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zürich</td>
					<td>Schweizerisches Rotes Kreuz</td>
					<td>Missing Maps Zürich Mapathon <a href="https://osmcal.org/event/4558/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Milano</td>
					<td>Building 3A Ground Floor - Politecnico di Milano</td>
					<td>PoliMappers Maptedì <a href="https://osmcal.org/event/4599/">:osmcalpic:</a></td>
					<td>2026-03-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>Dieselhaus, Forum a. d. Museumsinsel 10</td>
					<td>213. OSM-Stammtisch Berlin-Brandenburg <a href="https://osmcal.org/event/4600/">:osmcalpic:</a></td>
					<td>2026-03-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>München</td>
					<td>WikiMUC</td>
					<td>Münchner OSM-Treffen <a href="https://osmcal.org/event/4343/">:osmcalpic:</a></td>
					<td>2026-03-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Magrathea Laboratories Chaos Computer Club Fulda</td>
					<td>OSM-Tools: Wenn die Welt zur Spielwiese wird <a href="https://osmcal.org/event/4598/">:osmcalpic:</a></td>
					<td>2026-03-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Leuven</td>
					<td>Romaanse Poort</td>
					<td>Camera&rsquo;s in kaart brengen <a href="https://osmcal.org/event/4549/">:osmcalpic:</a></td>
					<td>2026-03-14</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London: (Online) Mid-Month Mapathon [eng] <a href="https://osmcal.org/event/4243/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Lyon</td>
					<td>Tubà</td>
					<td>Réunion du groupe local de Lyon <a href="https://osmcal.org/event/4305/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bonn</td>
					<td>Dotty&rsquo;s</td>
					<td>198. OSM-Stammtisch Bonn <a href="https://osmcal.org/event/4354/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Lüneburger Mappertreffen (online) <a href="https://osmcal.org/event/4369/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>MJC de Vienne</td>
					<td>Réunion des contributeurs de Vienne (38) <a href="https://osmcal.org/event/4562/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stainach-Pürgg</td>
					<td>Online</td>
					<td>20. Österreichischer OSM-Stammtisch (online) <a href="https://osmcal.org/event/4438/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Online Mapathon - Ärzte ohne Grenzen <a href="https://osmcal.org/event/4513/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Heidelberg</td>
					<td>DEZERNAT#16</td>
					<td>Rhein-Neckar OSM Treffen // Intro iD-Editor <a href="https://osmcal.org/event/4509/">:osmcalpic:</a></td>
					<td>2026-03-19</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4601/">:osmcalpic:</a></td>
					<td>2026-03-20</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Olomouc</td>
					<td>Přírodovědecká fakulta Univerzity Palackého</td>
					<td>Missing Maps Day Olomouc 2026 <a href="https://osmcal.org/event/4545/">:osmcalpic:</a></td>
					<td>2026-03-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td></td>
					<td>Frühlingsmapping 2026 <a href="https://osmcal.org/event/4542/">:osmcalpic:</a></td>
					<td>2026-03-22</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4294/">:osmcalpic:</a></td>
					<td>2026-03-23</td>
			</tr>
	</tbody>
</table>
</li>
</ul>
]]></content:encoded>
			</item>
			<item>
				<title>Еженедельник OSM 816</title>
				<link>https://hugo.weeklyosm.eu/ru/archives/0816/</link>
				<pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/archives/0816/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/03/816.png" alt="Еженедельник OSM 816" /> 05.03.2026-11.03.2026
Картографирование Идёт голосование: AndreaDp27 предложил :EN-s: расширение схемы тегов для мест, официально предназначенных для организации гражданской обороны населения :EN-s:. Голосование открылось 9 марта 2026 года и закроется 23 марта 2026 года. Сообщество На конференции State of the Map 2025 Бен Гур Пинтор выступил :EN-s: с докладом «Удивительные (OSM) игры», в котором освещает ряд игр, использующих данные OpenStreetMap, хотя и необязательно предназначенных для картографирования OSM.
Derlamaer предлагает :EN-s: новый тег для светофоров с детекторами движения пешеходов (detector_operated=*).
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/03/816.png" alt="Еженедельник OSM 816" /></p> <p>05.03.2026-11.03.2026</p>
<h2 id="картографирование">Картографирование</h2>
<ul>
<li>Идёт голосование:</li>
</ul>
<ul>
<li>AndreaDp27 <a href="https://www.openstreetmap.org/user/AndreaDp271/diary/408338">предложил</a> :EN-s: расширение схемы тегов для мест, официально предназначенных для организации <a href="https://wiki.openstreetmap.org/wiki/Proposal:Civil_Protection_Areas">гражданской обороны населения</a> :EN-s:. Голосование открылось 9 марта 2026 года и закроется 23 марта 2026 года.</li>
</ul>
<h2 id="сообщество">Сообщество</h2>
<ul>
<li>
<p>На конференции State of the Map 2025 Бен Гур Пинтор <a href="https://media.ccc.de/v/sotm2025-71684-awesome-osm-games">выступил</a> :EN-s: с докладом «Удивительные (OSM) игры», в котором освещает ряд игр, использующих данные OpenStreetMap, хотя и необязательно предназначенных для картографирования OSM.</p>
</li>
<li>
<p>Derlamaer <a href="https://www.openstreetmap.org/user/Derlamaer/diary/408326">предлагает</a> :EN-s: новый тег для светофоров с детекторами движения пешеходов (<code>detector_operated=*</code>).</p>
</li>
<li>
<p>Микель Марон <a href="https://www.openstreetmap.org/user/mikelmaron/diary/408323">разработал</a> :EN-s: инструмент для сопоставления и импорта данных Overture Maps в OpenStreetMap.</p>
</li>
<li>
<p>Natfoot <a href="https://www.openstreetmap.org/user/Natfoot/diary/408333">предложил</a> ставить <code>railway=trail</code> для обозначения велосипедных дорожек вдоль железнодорожных путей.</p>
</li>
<li>
<p>Rene78 <a href="https://www.openstreetmap.org/user/rene78/diary/408318">заметил</a> :EN-s:, что можно попросить ChatGPT сгенерировать по фото вывески корректный тег <a href="https://wiki.openstreetmap.org/wiki/Key:opening_hours">opening_hours</a>.</p>
</li>
<li>
<p>Саймон Пул <a href="https://www.openstreetmap.org/user/SimonPoole/diary/408313">рассказал</a> :EN-s: о нескольких проблемах, с которыми столкнулось швейцарское сообщество OpenStreetMap при попытке импортировать данные о муниципальных границах от Федерального бюро топографии. Ситуация, по его словам, похожа на небезызвестный импорт базы данных TIGER в 2009 году.</p>
</li>
<li>
<p>В связи с недавней попыткой <a href="https://wiki.openstreetmap.org/wiki/Overture_Maps">Overture Maps</a> утвердить свою систему глобальных идентификаторов (GERS) стандартом Консорциума по открытым геоданным, Саймон Пул <a href="https://www.openstreetmap.org/user/SimonPoole/diary/408332">подчёркивает</a> :EN-s:, что идентификаторы объектов OSM также подходят в качестве альтернативы GERS. rphyrin <a href="https://www.openstreetmap.org/user/rphyrin/diary/408331">разделяет</a> :EN-s: его мнение.</p>
</li>
<li>
<p>Также Саймон Пул <a href="https://www.openstreetmap.org/user/SimonPoole/diary/408343">пишет</a> :EN-s:, что редактор Vespucci может столкнуться с проблемами на старых устройствах Android из-за устаревших корневых сертификатов, поскольку в старых версиях Android (до Android 7) они обновляются при полном обновлении системы. Он предложил пользователям вручную устанавливать сертификаты в качестве временного решения проблемы, поскольку сейчас в редактор <a href="https://en.osm.town/@simon/116198817230773538">не встроен</a> :EN-s: актуальный набор корневых сертификатов.</p>
</li>
<li>
<p>Паскаль Нейс <a href="https://neis-one.org/2026/03/who-and-where-osm-profiles/">проанализировал</a> :EN-s: недавно введённые поля «компания» (company) и «местоположение» (location) в профилях пользователей OpenStreetMap и подытожил, что его <a href="https://hdyc.neis-one.org/">профили HDYC</a> более надёжны, так как формируются автоматически из собранных данных о вкладах, а не из той информации, которую люди пишут о себе сами и которую зачастую трудно проверить.</p>
</li>
</ul>
<h2 id="местные-отделения-osmf">Местные отделения OSMF</h2>
<ul>
<li>Йохен Топф <a href="https://www.fossgis.de/news/2026_03_05_fossgis-bekommt-f%C3%B6rderung-von-dsee/">сообщил</a> :DE-s:, что FOSSGIS e.V. получило финансирование от Немецкого фонда вовлечения и волонтёрства на проведение обучающей программы по OpenStreetMap.</li>
</ul>
<h2 id="карты">Карты</h2>
<ul>
<li>[^1^] k-yle <a href="https://github.com/k-yle/OpenSeaMap-vector">разработал</a> OpenSeaMap-vector, <a href="https://kyle.kiwi/OpenSeaMap-vector/#map=12.28/37.80087/-122.40002">переработанную версию</a> OpenSeaMap с векторными тайлами вместо растровых.</li>
</ul>
<h2 id="открытые-данные">Открытые данные</h2>
<ul>
<li>Flacombe <a href="https://teamopendata.org/t/louverture-des-donnees-observee-par-les-autorites-administratives-independantes/4876">сравнивает</a> :FR-s: несколько фреймворков, используемых для анализа практики обмена данными во Франции.</li>
</ul>
<h2 id="программы">Программы</h2>
<ul>
<li>
<p>HeiGIT <a href="https://heigit.org/a-map-is-better-than-a-thousand-words-global-data-reveals-gaps-in-access-to-education-and-healthcare">сообщает</a> :EN-s: о разработке платформы открытых данных под названием <a href="https://giscience.github.io/open-access-lens">OpenAccessLens</a>, которая показывает, например, время в пути и расстояние, на котором люди находятся от ближайших школ и больниц.</p>
</li>
<li>
<p>Команда сайта OSM <a href="https://community.openstreetmap.org/t/what-s-new-on-the-openstreetmap-website/130080/23">поделилась информацией</a> о своём прогрессе в переходе на MapLibre и ряде исправлений в работе с пользователями.</p>
</li>
</ul>
<h2 id="программирование">Программирование</h2>
<ul>
<li>Владислав Алцыбеев <a href="https://habr.com/ru/articles/1006398/">рассказал</a> на Хабре, как команда <a href="https://mapmagic.app/">MapMagic</a> создала собственные топографические карты, объединив данные OSM и цифровую модель рельефа <a href="https://mapterhorn.com/">Mapterhorn</a>.</li>
</ul>
<h2 id="релизы">Релизы</h2>
<ul>
<li>
<p>Среди нововведений <a href="https://codeberg.org/comaps/comaps/releases/tag/v2026.03.09-18">CoMaps 2026.03.09</a> :EN-s:: отображение стандарта зарядки SAE J1772 для электромобилей, стоимости услуг в заведении и населения городов. Также добавлена и улучшена поддержка таких типов POI, как аттракционы и магазины по продаже питьевой воды.</p>
</li>
<li>
<p>Бастиан Грешаке Тзоварас <a href="https://pypi.org/project/comaps-map-distributor/0.4.0/">опубликовал</a> версию 0.4.0 утилиты для дистрибуции карт CoMaps, в которой улучшили управление загрузками.</p>
</li>
<li>
<p>Кристоф Хорманн <a href="https://www.openstreetmap.org/user/imagico/diary/408344">сообщает</a> :EN-s: о релизе картостиля OpenStreetMap Carto 6.0.0. В ближайшее время обновление будет развёрнуто для тайлов на сайте OpenStreetMap.</p>
</li>
</ul>
<h2 id="а-вы-знаете-">А вы знаете …</h2>
<ul>
<li>&hellip; что в последнее время QGIS использует сервер тайлов OpenStreetMap <a href="https://gist.github.com/pnorman/c25d913a6825c2a64eb364531b5bbbf6">больше</a> :EN-s:, чем сам OpenStreetMap.org? Некоторые плагины QGIS способны загружать огромное количество тайлов OSM, но недавно <a href="https://github.com/nextgis/qgis_qtiles/issues/125#issuecomment-4031102171">была добавлена</a> :EN-s: защита, предотвращающая подобную нагрузку на сервера.</li>
</ul>
<h2 id="osm-в-прессе">OSM в прессе</h2>
<ul>
<li>
<p>Фальк Штайнер из Heise <a href="https://www.heise.de/hintergrund/Missing-Link-Auf-der-Spree-schwimmt-eine-Infrastrukturschutz-Ente-11202843.html">заявил</a> :DE-s:, что OpenStreetMap несёт частичную ответственность за недавний пожар на вантовом мосту, который привёл к отключению электричества в некоторых районах юго-западного Берлина. Штайнер ссылается на то, что открытые данные OSM о местоположении критической инфраструктуры могли быть использованы в целях саботажа.</p>
</li>
<li>
<p>Emhraim из команды GNU-Linux CH <a href="https://gnulinux.ch/openstreetmap-am-handy">демонстрирует</a> :DE-s: несколько мобильных приложений для редактирования OpenStreetMap; главные из них в статье — это CoMaps и StreetComplete.</p>
</li>
<li>
<p>В недавнем интервью французскому независимому новостному интернет-ресурсу «Basta!» Жером Эрге, сотрудник Национального центра научных исследований и специалист по социальным сетям, <a href="https://basta.media/la-societe-civile-en-reseau-peut-faire-mieux-que-tous-les-gafam-reunis">заявил</a> :FR-s:, что проект OpenStreetMap стагнирует. По его словам, Google Карты препятствуют популяризации OSM.</p>
</li>
</ul>
<h2 id="разное-о-картах">Разное о картах</h2>
<ul>
<li>
<p>Исследователи из Института исторических исследований Лондонского университета <a href="https://www.layersoflondon.org/">создали</a> «Слои Лондона». На карте столицы Соединённого королевства могут поделиться своими историями, воспоминаниями и рассказами, дабы написать историю жителей этого города.</p>
</li>
<li>
<p>Историк Иван Малара случайно <a href="https://www.science.org/content/article/galileo-s-handwritten-notes-found-ancient-astronomy-text">обнаружил</a> :EN-s: рукописные примечания Галилео Галилея к «Альмагесту» Птолемея в Национальной центральной библиотеке Италии во Флоренции.</p>
</li>
<li>
<p>Айзек Корли и Калеб Робинсон <a href="https://geospatialml.com/">начали вести</a> :EN-s: блог GeoSpatial ML, в котором публикуют статьи по машинному обучению, дистанционному зондированию и другим областям. Вы можете следить за ним через <a href="https://geospatialml.com/index.xml">RSS</a> или на <a href="https://substack.com/@geospatialml">Substack</a>.</p>
</li>
<li>
<p>Пьер Сош <a href="https://www.linkedin.com/posts/pierresuchet_celles-et-ceux-qui-ont-assist%C3%A9-jeudi-dernier-share-7437396339694440448-STMl">прокомментировал</a> :FR-s: проект «Ризе. Воспоминания, культура, обмен» (Le Rize: mémoires, cultures, échanges), в рамках которого <a href="https://macarte.ign.fr/carte/zcJwwF/Le-Ruisseau-de-la-Rize-a-Lyon-et-Villeurbanne">была создана</a> интерактивная веб-карта c историческими фотографиями местности вдоль реки Ризе близ французского Лиона. Проект осуществляется при поддержке <a href="https://www.ign.fr/">Национального географического института Франции</a>.</p>
</li>
<li>
<p>Университет Сарагосы возглавил разработку <a href="https://visor.firepaths.org">онлайн-карт</a> :ES-s: для оценки риска лесных пожаров в рамках проекта <a href="https://geoinnova.org/blog-territorio/proyecto-firepaths-visor-incendios-forestales/">FirePaths</a> :ES-s:. Используется свободное и открытое программное обеспечение, стандарты OGC, а в качестве базовой карты — OpenStreetMap.</p>
</li>
<li>
<p>Катарина Сигер и Филипп Миндерхуд <a href="https://www.nature.com/articles/s41586-026-10196-1">предупреждают</a>, что уровень моря гораздо выше, чем предполагался в большинстве оценок опасности для прибрежных районов. В статье, опубликованной в журнале Nature, они объясняют, что в почти 99 % оценок была использована неправильная методология замеров на основе эквипотенциальной модели геоида. Более точные методы, как например, с использованием воздушного лидара, учитывают высоту побережий. В результате новая оценка может быть больше старой на 1 метр.</p>
</li>
</ul>
<h2 id="предстоящие-события">Предстоящие события</h2>
<ul>
<li>
<table>
	<thead>
			<tr>
					<th>Страна</th>
					<th>Где</th>
					<th>Адрес</th>
					<th>Что</th>
					<th>Когда</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td><del>March Missing Maps Mapathon</del> <a href="https://osmcal.org/event/4617/">:osmcalpic:</a></td>
					<td>2026-03-12 - 2026-03-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Magrathea Laboratories Chaos Computer Club Fulda</td>
					<td>OSM-Tools: Wenn die Welt zur Spielwiese wird <a href="https://osmcal.org/event/4598/">:osmcalpic:</a></td>
					<td>2026-03-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Leuven</td>
					<td>Romaanse Poort</td>
					<td>Camera&rsquo;s in kaart brengen <a href="https://osmcal.org/event/4549/">:osmcalpic:</a></td>
					<td>2026-03-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>A Mapathon to enrich participatory mapping of short supply chains around the Tokikoa label in the Basque Country <a href="https://osmcal.org/event/4604/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/es.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zaragoza</td>
					<td>Online</td>
					<td>Mappy Hour OSM España <a href="https://osmcal.org/event/4615/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London: (Online) Mid-Month Mapathon [eng] <a href="https://osmcal.org/event/4243/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Lyon</td>
					<td>Tubà</td>
					<td>Réunion du groupe local de Lyon <a href="https://osmcal.org/event/4305/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bonn</td>
					<td>Dotty&rsquo;s</td>
					<td>198. OSM-Stammtisch Bonn <a href="https://osmcal.org/event/4354/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Lüneburger Mappertreffen (online) <a href="https://osmcal.org/event/4369/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>MJC de Vienne</td>
					<td>Rencontre des contributeurs de Vienne (38) <a href="https://osmcal.org/event/4562/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Online Mapathon - Ärzte ohne Grenzen <a href="https://osmcal.org/event/4513/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stainach-Pürgg</td>
					<td>Online</td>
					<td>20. Österreichischer OSM-Stammtisch (online) <a href="https://osmcal.org/event/4438/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Gent</td>
					<td>Tramzwart, KASK</td>
					<td>Camera&rsquo;s in kaart brengen <a href="https://osmcal.org/event/4612/">:osmcalpic:</a></td>
					<td>2026-03-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Heidelberg</td>
					<td>DEZERNAT#16</td>
					<td>Rhein-Neckar OSM Treffen // Intro iD-Editor <a href="https://osmcal.org/event/4509/">:osmcalpic:</a></td>
					<td>2026-03-19</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4601/">:osmcalpic:</a></td>
					<td>2026-03-20</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Olomouc</td>
					<td>Přírodovědecká fakulta Univerzity Palackého</td>
					<td>Missing Maps Day Olomouc 2026 <a href="https://osmcal.org/event/4545/">:osmcalpic:</a></td>
					<td>2026-03-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Domplatz Fulda</td>
					<td>Frühlingsmapping 2026 <a href="https://osmcal.org/event/4542/">:osmcalpic:</a></td>
					<td>2026-03-22</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4294/">:osmcalpic:</a></td>
					<td>2026-03-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stadtgebiet Bremen</td>
					<td>Online und im Hackerspace Bremen</td>
					<td>Bremer Mappertreffen <a href="https://osmcal.org/event/4608/">:osmcalpic:</a></td>
					<td>2026-03-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Pôle Numérique Brest Iroise</td>
					<td>Rencontre OpenStreetMap et Territoires <a href="https://osmcal.org/event/4077/">:osmcalpic:</a></td>
					<td>2026-03-24</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Göttingen</td>
					<td>Uni Göttingen</td>
					<td>FOSSGIS-Konferenz 2026 <a href="https://osmcal.org/event/4400/">:osmcalpic:</a></td>
					<td>2026-03-24 - 2026-03-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Derby</td>
					<td>The Brunswick, Railway Terrace, Derby</td>
					<td>East Midlands pub meet-up <a href="https://osmcal.org/event/4432/">:osmcalpic:</a></td>
					<td>2026-03-24</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Düsseldorf</td>
					<td>Online bei <a href="https://meet.jit.si/OSM-DUS-2026">https://meet.jit.si/OSM-DUS-2026</a></td>
					<td>Düsseldorfer OpenStreetMap-Treffen (online) <a href="https://osmcal.org/event/4383/">:osmcalpic:</a></td>
					<td>2026-03-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chemnitz</td>
					<td>Neues Hörsaalgebäude, TU Chemnitz</td>
					<td>Chemnitzer Linux-Tage 2026 <a href="https://osmcal.org/event/4211/">:osmcalpic:</a></td>
					<td>2026-03-28 - 2026-03-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Göttingen</td>
					<td>Uni Göttingen, Fakultät für Geowissenschaften</td>
					<td>FOSSGIS 2026 - OSM-Samstag <a href="https://osmcal.org/event/4416/">:osmcalpic:</a></td>
					<td>2026-03-28</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Local Chapters &amp; Communities Congress 2026 <a href="https://osmcal.org/event/4490/">:osmcalpic:</a></td>
					<td>2026-03-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Vélo Utile</td>
					<td>rencontre OSM <a href="https://osmcal.org/event/4605/">:osmcalpic:</a></td>
					<td>2026-03-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Mira-Bhayander</td>
					<td>DBT Café, Mira Road</td>
					<td>OSM Mumbai Mapping Party No.8 (Western Line - North) <a href="https://osmcal.org/event/4317/">:osmcalpic:</a></td>
					<td>2026-03-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hannover</td>
					<td>Kuriosum</td>
					<td>OSM-Stammtisch Hannover <a href="https://osmcal.org/event/4555/">:osmcalpic:</a></td>
					<td>2026-03-30</td>
			</tr>
	</tbody>
</table>
</li>
</ul>
]]></content:encoded>
			</item>
			<item>
				<title>Вносить вклад</title>
				<link>https://hugo.weeklyosm.eu/ru/this-news-should-be-in-weeklyosm/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/this-news-should-be-in-weeklyosm/</guid>
				<description><![CDATA[ Thank you for considering contributing to weeklyOSM! We welcome all link proposals from across the OpenStreetMap universe.
Propose a Link We collect your contributions with our OSM Blog Collector. Thank you for proposing your link via this form.
Step-by-Step Guide Log In: Before you can submit a link proposal, you need to log in with your OpenStreetMap account.
Search: Once authenticated, enter your link proposal into the search form provided.
Check for Duplicates: Upon submission, the Blog Collector will display a table of similar links that have already been submitted. Please review the latest entries to avoid duplicates. If your link isn&rsquo;t listed, or if you see the message No Articles found for search, you are the first to propose it!
]]></description>
				<content:encoded><![CDATA[<p></p> <p>Thank you for considering contributing to weeklyOSM! We welcome all link proposals from across the OpenStreetMap universe.</p>
<h2 id="propose-a-link">Propose a Link</h2>
<p>We collect your contributions with our <em>OSM Blog Collector</em>. Thank you for proposing your link <a href="https://osmbc.openstreetmap.de/article/create">via this form</a>.</p>
<hr>
<h2 id="step-by-step-guide">Step-by-Step Guide</h2>
<ol>
<li>
<p><strong>Log In:</strong> Before you can submit a link proposal, you need to log in with your OpenStreetMap account.</p>
</li>
<li>
<p><strong>Search:</strong> Once authenticated, enter your link proposal into the search form provided.</p>
</li>
<li>
<p><strong>Check for Duplicates:</strong> Upon submission, the Blog Collector will display a table of similar links that have already been submitted. Please review the latest entries to avoid duplicates. If your link isn&rsquo;t listed, or if you see the message <code>No Articles found for search</code>, you are the first to propose it!</p>
</li>
<li>
<p><strong>Add Details:</strong> Enter a short title and a brief description in the <em>Collection</em> field. You can also include additional relevant links here. Choosing a matching category is optional but helpful.</p>
</li>
<li>
<p><strong>Submit:</strong> Once you have filled in all the relevant details, click <em>OK</em> to submit your link. It will then be forwarded to the Blog Collector for our editors and translators to review.</p>
</li>
</ol>
]]></content:encoded>
			</item>
			<item>
				<title>О нас</title>
				<link>https://hugo.weeklyosm.eu/ru/about-us/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/about-us/</guid>
				<description><![CDATA[ В чём идея? weeklyOSM еженедельно рассказывает сообществу о том, что происходит во мире OSM. Выпуски еженедельника создаются энтузиастами как для новичков, так и для опытных картографов. OSM. Из-за огромной нагрузки (52 выпуска в год, без отпусков) для работы над переводами нужно минимум три картографа.
Идея weeklyOSM — собирать со всего мира интересные новости об OSM и переводить их на как можно больше языков. Это должно помочь преодолеть языковые барьеры и максимально полно информировать сообщество.
]]></description>
				<content:encoded><![CDATA[<p></p> <h2 id="в-чём-идея">В чём идея?</h2>
<p>weeklyOSM еженедельно рассказывает сообществу о том, что происходит во мире OSM. Выпуски еженедельника создаются энтузиастами как для новичков, так и для опытных картографов. OSM. Из-за огромной нагрузки (52 выпуска в год, без отпусков) для работы над переводами нужно минимум три картографа.</p>
<p>Идея weeklyOSM — собирать со всего мира интересные новости об OSM и переводить их на как можно больше языков. Это должно помочь преодолеть языковые барьеры и максимально полно информировать сообщество.</p>
<p>Редакция weeklyOSM независима от организаций и компаний так как OSMF, HOT, FOSSGIS и других. Тем не менее, мы были бы рады, если бы наши выпуски (на любом языке) появлялись бы на главной странице Wiki.</p>
<h2 id="кто-мы-и-где">Кто мы и где?</h2>
<ul>
<li>
<p>Email: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
</li>
<li>
<p><a href="https://wiki.openstreetmap.org/wiki/WeeklyOSM">Викистраница weeklyOSM</a></p>
</li>
<li>
<p><a href="https://umap.openstreetmap.fr/en/map/weeklyosm-is-currently-produced-in_56718#2/8.8/108.3">Откуда наши редакторы?</a></p>
</li>
<li>
<p><a href="https://wiki.openstreetmap.org/wiki/Former_weeklyOSM_authors">Редакторы с более 100 правками</a></p>
</li>
</ul>
]]></content:encoded>
			</item>
			<item>
				<title>Политика конфиденциальности</title>
				<link>https://hugo.weeklyosm.eu/ru/privacy-policy/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ru/privacy-policy/</guid>
				<description><![CDATA[ We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).
]]></description>
				<content:encoded><![CDATA[<p></p> <p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<h2 id="1-definitions"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM<br>
c/o FOSSGIS e.V.<br>
Bundesallee 23<br>
10717 Berlin</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a><br>
Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Angaben gemäß § 5 DDG</p>
<h1 id="privacy-policy"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-1"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-1"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-1"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-1"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-1"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-1"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-1"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-1"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-1"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-1"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-1"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-1"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-1"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-1"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-1"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-1"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-1"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-1"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-1"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-1"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-1"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-1"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-1"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-2"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-2"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-2"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-2"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-2"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-2"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-2"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-2"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-2"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-2"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-2"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-2"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-2"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-2"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-2"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-2"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-2"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-2"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-2"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-2"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-2"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-2"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.weeklyOSM</p>
<h1 id="privacy-policy-2"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-3"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-3"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-3"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-3"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-3"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-3"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-3"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-3"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-3"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-3"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-3"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-3"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-3"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-3"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-3"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-3"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-3"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-3"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-3"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-3"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-3"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-3"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.z. H. FOSSGIS e.V.</p>
<h1 id="privacy-policy-3"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-4"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-4"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-4"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-4"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-4"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-4"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-4"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-4"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-4"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-4"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-4"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-4"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-4"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-4"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-4"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-4"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-4"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-4"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-4"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-4"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-4"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-4"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Bundesallee 23</p>
<h1 id="privacy-policy-4"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-5"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-5"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-5"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-5"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-5"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-5"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-5"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-5"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-5"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-5"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-5"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-5"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-5"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-5"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-5"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-5"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-5"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-5"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-5"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-5"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-5"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-5"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.10717 Berlin</p>
<h1 id="privacy-policy-5"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-6"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-6"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-6"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-6"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-6"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-6"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-6"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-6"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-6"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-6"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-6"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-6"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-6"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-6"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-6"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-6"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-6"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-6"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-6"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-6"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-6"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-6"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-6"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-7"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-7"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-7"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-7"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-7"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-7"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-7"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-7"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-7"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-7"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-7"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-7"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-7"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-7"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-7"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-7"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-7"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-7"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-7"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-7"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-7"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-7"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Vertreten durch</p>
<h1 id="privacy-policy-7"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-8"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-8"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-8"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-8"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-8"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-8"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-8"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-8"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-8"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-8"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-8"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-8"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-8"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-8"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-8"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-8"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-8"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-8"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-8"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-8"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-8"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-8"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-8"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-9"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-9"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-9"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-9"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-9"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-9"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-9"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-9"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-9"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-9"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-9"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-9"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-9"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-9"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-9"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-9"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-9"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-9"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-9"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-9"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-9"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-9"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Marc Gehling</p>
<h1 id="privacy-policy-9"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-10"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-10"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-10"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-10"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-10"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-10"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-10"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-10"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-10"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-10"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-10"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-10"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-10"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-10"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-10"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-10"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-10"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-10"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-10"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-10"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-10"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-10"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-10"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-11"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-11"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-11"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-11"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-11"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-11"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-11"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-11"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-11"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-11"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-11"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-11"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-11"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-11"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-11"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-11"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-11"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-11"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-11"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-11"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-11"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-11"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Kontakt</p>
<h1 id="privacy-policy-11"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-12"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-12"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-12"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-12"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-12"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-12"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-12"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-12"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-12"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-12"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-12"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-12"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-12"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-12"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-12"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-12"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-12"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-12"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-12"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-12"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-12"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-12"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-12"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-13"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-13"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-13"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-13"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-13"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-13"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-13"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-13"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-13"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-13"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-13"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-13"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-13"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-13"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-13"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-13"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-13"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-13"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-13"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-13"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-13"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-13"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure <a href="mailto:wording.info@weeklyosm.eu">wording.info@weeklyosm.eu</a></p>
<h1 id="privacy-policy-13"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-14"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-14"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-14"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-14"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-14"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-14"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-14"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-14"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-14"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-14"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-14"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-14"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-14"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-14"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-14"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-14"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-14"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-14"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-14"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-14"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-14"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-14"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-14"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-15"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-15"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-15"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-15"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-15"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-15"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-15"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-15"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-15"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-15"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-15"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-15"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-15"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-15"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-15"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-15"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-15"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-15"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-15"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-15"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-15"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-15"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Redaktionell verantwortlich</p>
<h1 id="privacy-policy-15"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-16"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-16"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-16"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-16"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-16"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-16"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-16"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-16"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-16"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-16"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-16"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-16"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-16"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-16"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-16"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-16"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-16"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-16"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-16"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-16"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-16"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-16"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-16"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-17"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-17"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-17"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-17"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-17"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-17"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-17"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-17"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-17"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-17"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-17"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-17"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-17"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-17"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-17"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-17"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-17"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-17"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-17"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-17"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-17"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-17"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Marc Gehling</p>
<h1 id="privacy-policy-17"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-18"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-18"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-18"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-18"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-18"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-18"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-18"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-18"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-18"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-18"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-18"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-18"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-18"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-18"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-18"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-18"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-18"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-18"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-18"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-18"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-18"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-18"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-18"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-19"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-19"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-19"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-19"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-19"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-19"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-19"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-19"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-19"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-19"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-19"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-19"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-19"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-19"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-19"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-19"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-19"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-19"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-19"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-19"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-19"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-19"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Haftung für Inhalte</p>
<h1 id="privacy-policy-19"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-20"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-20"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-20"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-20"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-20"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-20"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-20"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-20"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-20"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-20"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-20"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-20"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-20"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-20"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-20"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-20"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-20"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-20"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-20"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-20"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-20"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-20"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-20"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-21"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-21"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-21"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-21"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-21"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-21"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-21"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-21"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-21"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-21"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-21"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-21"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-21"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-21"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-21"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-21"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-21"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-21"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-21"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-21"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-21"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-21"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Als Diensteanbieter sind wir gemäß § 7 Abs.1 Digitale-Dienste-Gesetz (DDG) für eigene Inhalte auf diesen Seiten nach den allgemeinen Gesetzen verantwortlich. Nach den Art. 4 bis 8 des Digital Services Act, sind wir als Diensteanbieter jedoch nicht verpflichtet, übermittelte oder gespeicherte fremde Informationen zu überwachen oder nach Umständen zu forschen, die auf eine rechtswidrige Tätigkeit hinweisen.</p>
<h1 id="privacy-policy-21"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-22"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-22"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-22"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-22"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-22"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-22"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-22"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-22"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-22"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-22"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-22"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-22"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-22"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-22"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-22"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-22"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-22"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-22"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-22"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-22"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-22"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-22"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-22"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-23"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-23"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-23"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-23"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-23"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-23"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-23"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-23"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-23"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-23"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-23"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-23"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-23"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-23"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-23"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-23"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-23"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-23"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-23"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-23"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-23"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-23"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Verpflichtungen zur Entfernung oder Sperrung der Nutzung von Informationen nach den allgemeinen Gesetzen bleiben hiervon unberührt. Eine diesbezügliche Haftung ist jedoch erst ab dem Zeitpunkt der Kenntnis einer konkreten Rechtsverletzung möglich. Bei Bekanntwerden von entsprechenden Rechtsverletzungen werden wir diese Inhalte umgehend entfernen.</p>
<h1 id="privacy-policy-23"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-24"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-24"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-24"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-24"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-24"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-24"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-24"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-24"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-24"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-24"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-24"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-24"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-24"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-24"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-24"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-24"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-24"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-24"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-24"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-24"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-24"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-24"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-24"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-25"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-25"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-25"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-25"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-25"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-25"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-25"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-25"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-25"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-25"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-25"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-25"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-25"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-25"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-25"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-25"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-25"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-25"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-25"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-25"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-25"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-25"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Haftung für Links</p>
<h1 id="privacy-policy-25"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-26"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-26"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-26"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-26"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-26"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-26"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-26"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-26"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-26"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-26"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-26"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-26"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-26"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-26"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-26"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-26"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-26"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-26"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-26"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-26"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-26"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-26"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-26"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-27"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-27"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-27"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-27"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-27"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-27"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-27"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-27"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-27"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-27"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-27"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-27"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-27"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-27"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-27"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-27"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-27"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-27"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-27"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-27"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-27"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-27"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Unser Angebot enthält Links zu externen Websites Dritter, auf deren Inhalte wir keinen Einfluss haben. Deshalb können wir für diese fremden Inhalte auch keine Gewähr übernehmen. Für die Inhalte der verlinkten Seiten ist stets der jeweilige Anbieter oder Betreiber der Seiten verantwortlich. Die verlinkten Seiten wurden zum Zeitpunkt der Verlinkung auf mögliche Rechtsverstöße überprüft. Rechtswidrige Inhalte waren zum Zeitpunkt der Verlinkung nicht erkennbar.</p>
<h1 id="privacy-policy-27"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-28"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-28"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-28"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-28"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-28"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-28"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-28"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-28"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-28"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-28"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-28"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-28"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-28"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-28"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-28"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-28"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-28"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-28"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-28"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-28"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-28"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-28"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-28"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-29"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-29"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-29"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-29"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-29"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-29"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-29"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-29"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-29"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-29"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-29"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-29"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-29"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-29"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-29"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-29"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-29"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-29"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-29"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-29"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-29"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-29"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Eine permanente inhaltliche Kontrolle der verlinkten Seiten ist jedoch ohne konkrete Anhaltspunkte einer Rechtsverletzung nicht zumutbar. Bei Bekanntwerden von Rechtsverletzungen werden wir derartige Links umgehend entfernen.</p>
<h1 id="privacy-policy-29"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-30"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-30"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-30"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-30"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-30"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-30"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-30"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-30"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-30"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-30"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-30"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-30"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-30"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-30"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-30"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-30"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-30"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-30"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-30"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-30"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-30"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-30"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-30"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-31"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-31"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-31"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-31"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-31"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-31"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-31"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-31"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-31"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-31"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-31"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-31"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-31"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-31"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-31"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-31"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-31"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-31"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-31"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-31"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-31"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-31"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Urheberrecht</p>
<h1 id="privacy-policy-31"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-32"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-32"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-32"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-32"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-32"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-32"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-32"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-32"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-32"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-32"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-32"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-32"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-32"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-32"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-32"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-32"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-32"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-32"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-32"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-32"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-32"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-32"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-32"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-33"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-33"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-33"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-33"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-33"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-33"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-33"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-33"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-33"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-33"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-33"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-33"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-33"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-33"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-33"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-33"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-33"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-33"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-33"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-33"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-33"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-33"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Die durch die Seitenbetreiber erstellten Inhalte und Werke auf diesen Seiten unterliegen dem deutschen Urheberrecht. Die Vervielfältigung, Bearbeitung, Verbreitung und jede Art der Verwertung außerhalb der Grenzen des Urheberrechtes bedürfen der schriftlichen Zustimmung des jeweiligen Autors bzw. Erstellers. Downloads und Kopien dieser Seite sind nur für den privaten, nicht kommerziellen Gebrauch gestattet.</p>
<h1 id="privacy-policy-33"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-34"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-34"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-34"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-34"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-34"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-34"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-34"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-34"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-34"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-34"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-34"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-34"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-34"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-34"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-34"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-34"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-34"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-34"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-34"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-34"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-34"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-34"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-34"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-35"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-35"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-35"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-35"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-35"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-35"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-35"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-35"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-35"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-35"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-35"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-35"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-35"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-35"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-35"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-35"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-35"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-35"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-35"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-35"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-35"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-35"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Soweit die Inhalte auf dieser Seite nicht vom Betreiber erstellt wurden, werden die Urheberrechte Dritter beachtet. Insbesondere werden Inhalte Dritter als solche gekennzeichnet. Sollten Sie trotzdem auf eine Urheberrechtsverletzung aufmerksam werden, bitten wir um einen entsprechenden Hinweis. Bei Bekanntwerden von Rechtsverletzungen werden wir derartige Inhalte umgehend entfernen.</p>
<h1 id="privacy-policy-35"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-36"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-36"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-36"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-36"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-36"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-36"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-36"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-36"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-36"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-36"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-36"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-36"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-36"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-36"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-36"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-36"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-36"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-36"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-36"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-36"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-36"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-36"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-36"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-37"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-37"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-37"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-37"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-37"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-37"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-37"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-37"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-37"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-37"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-37"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-37"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-37"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-37"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-37"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-37"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-37"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-37"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-37"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-37"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-37"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-37"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Verbraucher­streit­beilegung/Universal­schlichtungs­stelle</p>
<h1 id="privacy-policy-37"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-38"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-38"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-38"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-38"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-38"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-38"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-38"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-38"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-38"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-38"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-38"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-38"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-38"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-38"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-38"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-38"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-38"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-38"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-38"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-38"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-38"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-38"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-38"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-39"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-39"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-39"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-39"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-39"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-39"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-39"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-39"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-39"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-39"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-39"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-39"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-39"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-39"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-39"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-39"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-39"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-39"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-39"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-39"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-39"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-39"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Wir sind nicht bereit oder verpflichtet, an Streitbeilegungsverfahren vor einer Verbraucherschlichtungsstelle teilzunehmen.</p>
<h1 id="privacy-policy-39"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-40"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-40"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-40"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-40"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-40"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-40"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-40"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-40"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-40"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-40"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-40"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-40"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-40"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-40"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-40"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-40"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-40"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-40"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-40"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-40"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-40"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-40"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-40"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-41"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-41"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-41"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-41"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-41"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-41"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-41"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-41"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-41"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-41"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-41"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-41"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-41"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-41"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-41"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-41"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-41"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-41"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-41"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-41"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-41"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-41"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Quelle</p>
<h1 id="privacy-policy-41"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-42"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-42"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-42"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-42"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-42"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-42"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-42"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-42"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-42"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-42"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-42"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-42"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-42"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-42"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-42"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-42"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-42"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-42"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-42"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-42"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-42"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-42"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-42"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-43"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-43"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-43"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-43"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-43"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-43"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-43"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-43"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-43"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-43"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-43"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-43"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-43"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-43"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-43"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-43"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-43"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-43"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-43"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-43"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-43"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-43"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.<a href="https://www.e-recht24.de">eRecht24</a></p>
<h1 id="privacy-policy-43"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-44"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-44"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-44"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-44"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-44"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-44"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-44"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-44"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-44"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-44"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-44"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-44"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-44"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-44"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-44"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-44"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-44"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-44"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-44"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-44"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-44"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-44"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
]]></content:encoded>
			</item>
	</channel>
</rss>
