Privacy Policy

Information regarding data protection and the processing of personal data in compliance with GDPR.



Introduction and Overview

We have written this privacy policy (version 21.08.2026-313234921) in order to explain to you, in accordance with the specifications of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as controllers – and the processors commissioned by us (e.g. providers) – process, will process in the future, and what lawful options you have. The terms used are to be understood as gender-neutral. In short: We inform you comprehensively about data that we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. As far as it is conducive to transparency, technical terms are explained in a user-friendly manner, links to further information are provided, and graphics are used. We thus inform in clear and simple language that, within the scope of our business activities, we only process personal data if an appropriate legal basis is given. This is certainly not possible if one provides explanations that are as concise, unclear, and legalistic-technical as possible, as is often the standard on the Internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one piece of information or another that you did not yet know. If questions nevertheless remain, we would like to ask you to turn to the responsible entity named below or in the legal notice, to follow the existing links, and to view further information on third-party sites. Our contact details can of course also be found in the legal notice.
Scope of Application

This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address, and postal address. The processing of personal data ensures that we can offer and bill for our services and products, whether online or offline. The scope of application of this privacy policy includes:

  • all online presences (websites, online shops) operated by us
  • social media presences and email communication
  • mobile apps for smartphones and other devices

In short: The privacy policy applies to all areas in which personal data is processed in a structured manner in the company via the specified channels. Should we enter into legal relations with you outside of these channels, we will inform you separately if necessary.
Legal Bases

In the following privacy policy, we provide you with transparent information about the legal principles and regulations, i.e., the legal bases of the General Data Protection Regulation, which enable us to process personal data. As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can of course read this General Data Protection Regulation of the EU online on EUR-Lex, the access to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:

  • Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of data entered into a contact form.
  • Contract (Article 6(1)(b) GDPR): In order to fulfill a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase agreement with you, we require personal information in advance.
  • Legal Obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally required to retain invoices for accounting purposes. These usually contain personal data.
  • Legitimate Interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website securely and economically efficiently. This processing is therefore a legitimate interest.

Further conditions such as the performance of tasks in the public interest and exercise of official authority as well as the protection of vital interests do not usually occur with us. Insofar as such a legal basis should nevertheless be relevant, it will be indicated at the appropriate place.
In addition to the EU regulation, national laws also apply:

  • In Austria, this is the Federal Act on the Protection of Natural Persons in the Processing of Personal Data (Data Protection Act), in short DSG.
  • In Germany, the Federal Data Protection Act, in short BDSG, applies.

If further regional or national laws apply, we will inform you about them in the following sections.


Contact Details of the Controller

Should you have any questions regarding data protection or the processing of personal data, you will find below the contact details of the controller in accordance with Article 4(7) EU General Data Protection Regulation (GDPR):

Nicole Reith

Finkenschlag 62 90766 Fürth, Germany
Email: field.and.food.blog@gmail.com

Phone: +49 1602302824

Legal Notice: https://www.fieldandfood.com/impressum/

Storage Duration

That we store personal data only for as long as is strictly necessary for the provision of our services and products applies as a general criterion for us. This means that we delete personal data as soon as the reason for data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose no longer applies, for example for accounting purposes.
Should you wish for the deletion of your data or revoke consent to data processing, the data will be deleted as quickly as possible and insofar as there is no duty to store it.
We will inform you further below about the concrete duration of the respective data processing, provided we have further information on it.
Rights According to the General Data Protection Regulation

In accordance with Articles 13, 14 GDPR, we inform you about the following rights to which you are entitled so that fair and transparent processing of data takes place:

  • According to Article 15 GDPR, you have a right of access to whether we process data from you. Should that be the case, you have the right to receive a copy of the data and to learn the following information:
    • for what purpose we carry out the processing;
    • the categories, i.e., the types of data that are processed;
    • who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
    • how long the data will be stored;
    • the existence of the right to rectification, deletion, or restriction of processing and the right to object to processing;
    • that you can lodge a complaint with a supervisory authority (links to these authorities can be found further below);
    • the origin of the data, if we did not collect it from you;
    • whether profiling is carried out, i.e., whether data is automatically evaluated in order to arrive at a personal profile of you.
  • According to Article 16 GDPR, you have a right to rectification of data, which means that we must correct data if you find errors.
  • According to Article 17 GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the deletion of your data.
  • According to Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but no longer use it.
  • According to Article 20 GDPR, you have the right to data portability, which means that we will provide you with your data in a common format upon request.
  • According to Article 21 GDPR, you have a right to object, which, once enforced, brings about a change in processing.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
    • If data is used to conduct direct advertising, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
    • If data is used to conduct profiling, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
  • According to Article 22 GDPR, you may under certain circumstances have the right not to be subject to a decision based solely on automated processing (for example profiling).
  • According to Article 77 GDPR, you have the right to lodge a complaint. This means you can complain to the data protection authority at any time if you are of the opinion that the processing of personal data violates the GDPR.

In short: You have rights – do not hesitate to contact the responsible entity listed above at our company!
If you believe that the processing of your data violates data protection law or your data protection claims have been violated in any other way, you can complain to the supervisory authority. For Austria, this is the Data Protection Authority, whose website you can find at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For further information, you can turn to the Federal Commissioner for Data Protection and Freedom of Information (BfDI). For our company, the following local data protection authority is responsible:
Security of Data Processing

In order to protect personal data, we have implemented both technical and organizational measures. Where possible for us, we encrypt or pseudonymize personal data. By doing so, we make it as difficult as possible within the scope of our possibilities for third parties to infer personal information from our data.
Art. 25 GDPR speaks here of "Data protection by design and by default" and means that one always thinks of security and sets appropriate measures both in software (e.g. forms) and hardware (e.g. access to the server room). In the following, we will go into concrete measures if necessary.
TLS Encryption with https

TLS, encryption, and https sound very technical and are. We use HTTPS (Hypertext Transfer Protocol Secure stands for "secure hypertext transfer protocol") to transmit data securely over the Internet against eavesdropping. This means that the complete transmission of all data from your browser to our web server is secured – no one can "eavesdrop".
We have thus introduced an additional layer of security and fulfill data protection through technology design (Article 25(1) GDPR). Through the use of TLS (Transport Layer Security), an encryption protocol for secure data transmission on the Internet, we can ensure the protection of confidential data. You can recognize the use of this securing of data transmission by the small lock symbol at the top left of the browser, to the left of the Internet address (e.g. examplepage.com) and the use of the schema https (instead of http) as part of our Internet address. If you would like to know more about encryption, we recommend searching Google for "Hypertext Transfer Protocol Secure wiki" to obtain good links to further information.
Communication

  • Communication Summary
    • 👥 Data Subjects: Everyone who communicates with us via telephone, email, or online form
    • 📓 Processed Data: e.g., phone number, name, email address, entered form data. More details on this can be found with the respective type of contact used
    • 🤝 Purpose: Handling communication with customers, business partners, etc.
    • 📅 Storage Duration: Duration of the business transaction and statutory regulations
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(b) GDPR (Contract), Art. 6(1)(f) GDPR (Legitimate Interests)

When you contact us and communicate via phone, email, or online form, personal data may be processed. The data is processed for handling and processing your question and the associated business transaction. The data is stored for precisely as long as that or as long as required by law.
Data Subjects

All those who seek contact with us via the communication channels provided by us are affected by the mentioned processes.
Telephone

When you call us, call data is stored in pseudonymized form on the respective device and with the telecommunications provider used. Furthermore, data such as name and phone number can subsequently be sent via email and stored to answer the inquiry. The data is deleted as soon as the business transaction has ended and legal requirements permit it.
Email

When you communicate with us via email, data may be stored on the respective end device (computer, laptop, smartphone, ...) and data is stored on the email server. The data is deleted as soon as the business transaction has ended and legal requirements permit it.
Online Forms

When you communicate with us using an online form, data is stored on our web server and, if applicable, forwarded to an email address of ours. The data is deleted as soon as the business transaction has ended and legal requirements permit it.
Legal Bases

The processing of data is based on the following legal bases:

  • Art. 6(1)(a) GDPR (Consent): You give us consent to store your data and use it further for purposes concerning the business case;
  • Art. 6(1)(b) GDPR (Contract): There is a necessity for the performance of a contract with you or a processor such as the telephone provider, or we must process the data for pre-contractual activities, such as preparing an offer;
  • Art. 6(1)(f) GDPR (Legitimate Interests): We want to conduct customer inquiries and business communication in a professional framework. For this purpose, certain technical facilities such as email programs, Exchange servers, and mobile network operators are necessary to conduct communication efficiently.

Cookies

  • Cookies Summary
    • 👥 Data Subjects: Visitors to the website
    • 🤝 Purpose: depending on the respective cookie. More details on this can be found further below or with the manufacturer of the software that sets the cookie.
    • 📓 Processed Data: Depending on the respective cookie used. More details on this can be found further below or with the manufacturer of the software that sets the cookie.
    • 📅 Storage Duration: depending on the respective cookie, can vary from hours up to years
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What are Cookies?

Our website uses HTTP cookies to store user-specific data. In the following, we explain what cookies are and why they are used so that you can better understand the following privacy policy.
Whenever you surf the Internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: Cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, as there are also other cookies for other areas of application. HTTP cookies are small files stored by our website on your computer. These cookie files are automatically placed in the cookie folder, quasi the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must additionally be specified.
Cookies store certain user data of yours, such as language or personal page settings. When you call up our site again, your browser transmits the "user-related" information back to our site. Thanks to cookies, our website knows who you are and offers you the setting you are used to. In some browsers, every cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser such as Chrome and the web server. Here, the web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site; third-party cookies are created by partner websites (e.g. Google Analytics). Every cookie is to be evaluated individually, as every cookie stores different data. The expiration time of a cookie also varies from a few minutes up to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other "malware". Cookies also cannot access information on your PC.
This is what cookie data can look like, for example:

  • Name: _ga
  • Value: GA1.2.1326744211.152313234921-9
  • Purpose: Differentiation of website visitors
  • Expiration Date: after 2 years

A browser should be able to support these minimum sizes:

  • At least 4096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3000 cookies in total

What Types of Cookies are There?

The question of which cookies we specifically use depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly address the different types of HTTP cookies.
Four types of cookies can be distinguished:

  1. Essential Cookies: These cookies are necessary to ensure basic functions of the website. For example, these cookies are needed when a user puts a product into the shopping cart, then continues surfing on other pages and only later goes to the checkout. Through these cookies, the shopping cart is not deleted, even if the user closes their browser window.
  2. Functional Cookies: These cookies collect information about user behavior and whether the user receives any error messages. In addition, these cookies are also used to measure loading time and the behavior of the website with different browsers.
  3. Target-oriented Cookies: These cookies ensure better user-friendliness. For example, entered locations, font sizes, or form data are stored.
  4. Advertising Cookies: These cookies are also called targeting cookies. They serve to deliver individually tailored advertising to the user. That can be very practical, but also very annoying.

Usually, when you visit a website for the first time, you are asked which of these cookie types you want to allow. And of course, this decision is also stored in a cookie.
If you would like to know more about cookies and do not shy away from technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) named "HTTP State Management Mechanism".
Purpose of Processing via Cookies

The purpose is ultimately dependent on the respective cookie. More details on this can be found further below or with the manufacturer of the software that sets the cookie.
Which Data is Processed?

Cookies are small helpers for many different tasks. Which data is stored in cookies cannot unfortunately be generalized, but we will inform you within the framework of the following privacy policy about the processed or stored data.
Storage Duration of Cookies

The storage duration depends on the respective cookie and is specified further below. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.
You also have an influence on the storage duration yourself. You can manually delete all cookies at any time via your browser (see also "Right to Object" below). Furthermore, cookies that are based on consent will be deleted at the latest after revocation of your consent, whereby the lawfulness of the storage until then remains unaffected.
Right to Object – How Can I Delete Cookies?

How and whether you want to use cookies is up to you to decide. Regardless of which service or website the cookies come from, you always have the option to delete cookies, deactivate them, or only partially allow them. For example, you can block third-party cookies while allowing all other cookies.
If you want to determine which cookies have been stored in your browser, if you want to change cookie settings, or delete them, you can find this in your browser settings:

  • Chrome: Delete, enable, and manage cookies in Chrome
  • Safari: Manage cookies and website data with Safari
  • Firefox: Clear cookies and site data in Firefox
  • Internet Explorer: Delete and manage cookies
  • Microsoft Edge: Delete and manage cookies

If you fundamentally do not want any cookies, you can set up your browser so that it always informs you when a cookie is to be set. This way, you can decide for every single cookie whether you allow the cookie or not. The procedure differs depending on the browser. It is best to search for the instructions in Google with the search term "delete cookies Chrome" or "deactivate cookies Chrome" in the case of a Chrome browser.
Legal Basis

Since 2009, there have been the so-called "Cookie Directives". It is laid down therein that storing cookies requires consent (Article 6(1)(a) GDPR) from you. Within EU countries, however, there are still very different reactions to these directives. In Austria, however, the implementation of this directive took place in § 165(3) of the Telecommunications Act (2021). In Germany, the cookie directives were not implemented as national law. Instead, the implementation of this directive largely took place in § 15(3) of the Telemedia Act (TMG), which has been replaced by the Digital Services Act (DDG) since May 2024.
For strictly necessary cookies, even where no consent is present, legitimate interests exist (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We want to give visitors to the website a pleasant user experience, and for this, certain cookies are often strictly necessary.
Insofar as cookies that are not strictly necessary are used, this occurs only in the event of your consent. The legal basis in this respect is Art. 6(1)(a) GDPR.
In the following sections, you will be informed more precisely about the use of cookies if used software employs cookies.
Web Hosting Introduction

  • Web Hosting Summary
    • 👥 Data Subjects: Visitors to the website
    • 🤝 Purpose: professional hosting of the website and securing operation
    • 📓 Processed Data: IP address, time of website visit, browser used, and further data. More details on this can be found further below or with the respective web hosting provider used.
    • 📅 Storage Duration: depending on the respective provider, but usually 2 weeks
    • ⚖️ Legal Bases: Art. 6(1)(f) GDPR (Legitimate Interests)

What is Web Hosting?

When you visit websites nowadays, certain information – including personal data – is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By website, incidentally, we mean the entirety of all web pages on a domain, i.e., everything from the home page to the very last subpage (like this one). By domain, we mean for example example.com or sample-example.com.
When you want to view a website on a computer, tablet, or smartphone, you use a program for this called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We briefly call it browser or web browser.
In order to display the website, the browser must connect to another computer where the code of the website is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why this is usually handled by professional providers, the hosters. These offer web hosting and thus ensure reliable and error-free storage of website data. A whole lot of technical terms, but please stay tuned, it gets even better!
During the connection setup of the browser on your computer (desktop, laptop, tablet, or smartphone) and during data transmission to and from the web server, processing of personal data may occur. On the one hand, your computer stores data; on the other hand, the web server must also store data for a period of time to ensure proper operation.
A picture says more than a thousand words, so the following graphic shows the interaction between the browser, the Internet, and the hosting provider for illustration.
Why Do We Process Personal Data?

The purposes of data processing are:

  • Professional hosting of the website and securing operation
  • maintaining operational and IT security
  • Anonymous evaluation of access behavior to improve our offer and, if necessary, for prosecution or pursuit of claims

Which Data is Processed?

Even while you are visiting our website right now, our web server, which is the computer on which this web page is stored, usually automatically stores data such as:

  • the complete Internet address (URL) of the called web page
  • browser and browser version (e.g. Chrome 87)
  • the operating system used (e.g. Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g. https://www.examplesourcesite.com/camefromhere/)
  • the host name and the IP address of the device from which access is made (e.g. COMPUTERNAME and 194.23.43.121)
  • date and time in files, the so-called web server log files.

How Long is Data Stored?

As a rule, the above-mentioned data is stored for two weeks and then automatically deleted. We do not pass this data on, but cannot rule out that this data may be inspected by authorities in the event of unlawful behavior.
In short: Your visit is logged by our provider (company running our website on special computers (servers)), but we do not pass on your data without consent!
Legal Basis

The lawfulness of the processing of personal data within the framework of web hosting results from Art. 6(1)(f) GDPR (safeguarding legitimate interests), because the use of professional hosting with a provider is necessary to present the company securely and user-friendly on the Internet and to be able to pursue attacks and claims resulting therefrom if necessary.
Between us and the hosting provider, there is usually a contract for data processing pursuant to Art. 28 et seq. GDPR, which ensures compliance with data protection and guarantees data security.
Email Marketing Introduction

  • Email Marketing Summary
    • 👥 Data Subjects: Newsletter subscribers
    • 🤝 Purpose: Direct advertising via email, notification of system-relevant events
    • 📓 Processed Data: Data entered upon registration, but at least the email address. More details on this can be found with the respective email marketing tool used.
    • 📅 Storage Duration: Duration of the existence of the subscription
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Email Marketing?

In order to keep you up to date, we also use the possibility of email marketing. In doing so, provided you have agreed to receive our emails or newsletters, data from you will also be processed and stored. Email marketing is a sub-area of online marketing. Here, news or general information about a company, products, or services are sent via email to a specific group of people who are interested in it.
If you want to participate in our email marketing (mostly via newsletter), you usually just have to register with your email address. To do this, you fill out an online form and send it off. However, it may also happen that we ask you, for example, for your salutation and your name so that we can also address you personally.
Basically, registering for newsletters works with the help of the so-called "double opt-in procedure". After you have registered for our newsletter on our website, you will receive an email via which you confirm the newsletter registration. This ensures that the email address belongs to you and nobody has registered with a third-party email address. We or a notification tool used by us logs every single registration. This is necessary so that we can also prove the legally correct registration process. Usually, the time of registration, the time of registration confirmation, and your IP address are stored. In addition, it is also logged when you make changes to your stored data.
Why Do We Use Email Marketing?

We naturally want to stay in contact with you and always present you with the most important news about our company. For this purpose, we use email marketing – often also simply referred to as "newsletter" – as an essential component of our online marketing. Provided you agree to it or it is legally permitted, we send you newsletters, system emails, or other notifications by email. When we use the term "newsletter" in the following text, we mainly mean regularly sent emails. Of course, we do not want to bother you in any way with our newsletter. Therefore, we really always endeavor to offer only relevant and interesting content. Thus, you learn more about our company, our services, or products, for example. Since we also continuously improve our offers, you also always learn via our newsletter when there is news or we are currently offering special, lucrative promotions. Insofar as we commission a service provider who offers a professional dispatch tool for our email marketing, we do so in order to be able to offer you fast and secure newsletters. The purpose of our email marketing is fundamentally to inform you about new offers and also to come closer to our entrepreneurial goals.
Which Data is Processed?

When you become a subscriber to our newsletter via our website, you confirm membership in an email list via email. In addition to IP address and email address, your salutation, name, address, and phone number may also be stored. However, only if you agree to these data storages. The data marked as such is necessary so that you can participate in the offered service. Providing it is voluntary, but failure to provide it means that you cannot use the service. In addition, information about your device or about your preferred content on our website may also be stored. You can find more about the storage of data when visiting a website in the section "Automatic Data Storage". We record your declaration of consent so that we can always prove that it complies with our laws.
Duration of Data Processing

If you unsubscribe your email address from our email/newsletter distribution list, we may store your address for up to three years based on our legitimate interests so that we can still prove your former consent. We may only process this data if we need to defend against any claims.
However, if you confirm that you gave us consent to register for the newsletter, you can submit an individual request for deletion at any time. If you permanently object to the consent, we reserve the right to store your email address in a blocklist. As long as you have voluntarily subscribed to our newsletter, we will of course also keep your email address.
Right to Object

You have the option to cancel your newsletter subscription at any time. For this, you only need to revoke your consent to the newsletter registration. That usually takes only a few seconds or one or two clicks. Mostly, you will find a link directly at the end of every email to cancel the newsletter subscription. If the link really cannot be found in the newsletter, please contact us by email and we will cancel your newsletter subscription immediately.
Legal Basis

The dispatch of our newsletter takes place on the basis of your consent (Article 6(1)(a) GDPR). This means that we may only send you a newsletter if you have actively registered for it beforehand. Where applicable, we may also send you advertising messages provided you have become our customer and have not objected to the use of your email address for direct advertising.
Information on specific email marketing services and how they process personal data can be found – if present – in the following sections.
Social Media Introduction

  • Social Media Privacy Policy Summary
    • 👥 Data Subjects: Visitors to the website
    • 🤝 Purpose: Presentation and optimization of our service, contact with visitors, interested parties, etc., advertising
    • 📓 Processed Data: Data such as phone numbers, email addresses, contact details, user behavior data, information about your device, and your IP address. More details on this can be found with the respective social media tool used.
    • 📅 Storage Duration: depending on the social media platforms used
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Social Media?

In addition to our website, we are also active on various social media platforms. In doing so, user data may be processed so that we can target users who are interested in us via social networks. In addition, elements of a social media platform may also be directly embedded in our website. This is the case, for example, when you click a so-called social button on our website and are forwarded directly to our social media presence. Websites and apps through which registered members can produce content, exchange content openly or in specific groups, and network with other members are referred to as social media.
Why Do We Use Social Media?

For years, social media platforms have been the place where people communicate and get in touch online. With our social media presences, we can bring our products and services closer to interested parties. The social media elements integrated into our website help you to switch to our social media content quickly and without complications.
The data stored and processed through your use of a social media channel primarily serves the purpose of being able to conduct web analyses. The goal of these analyses is to be able to develop more precise and personalized marketing and advertising strategies. Depending on your behavior on a social media platform, suitable conclusions about your interests can be made with the help of the evaluated data and so-called user profiles can be created. This also enables platforms to present you with tailored advertisements. Mostly, cookies are set in your browser for this purpose, which store data on your user behavior.
We generally assume that we remain responsible under data protection law, even if we use services of a social media platform. However, the European Court of Justice has decided that in certain cases the operator of the social media platform can be jointly responsible together with us within the meaning of Art. 26 GDPR. Insofar as this is the case, we point this out separately and work on the basis of a relevant agreement. The essence of the agreement is then reproduced further below with the affected platform.
Please note that when using social media platforms or our built-in elements, data from you may also be processed outside the European Union, as many social media channels, for example Facebook or Twitter, are American companies. As a result, you may no longer be able to claim or enforce your rights regarding your personal data as easily.
Which Data is Processed?

Which data exactly is stored and processed depends on the respective provider of the social media platform. But usually it concerns data such as phone numbers, email addresses, data you enter into a contact form, user data such as which buttons you click, whom you like or follow, when you visited which pages, information about your device, and your IP address. Most of this data is stored in cookies. Especially if you have a profile yourself on the visited social media channel and are logged in, data can be linked to your profile.
All data collected via a social media platform is also stored on the providers' servers. Thus, only the providers have access to the data and can give you appropriate information or make changes.
If you want to know exactly which data is stored and processed by the social media providers and how you can object to the data processing, you should carefully read the respective privacy policy of the company. Also, if you have questions about data storage and data processing or want to assert corresponding rights, we recommend contacting the provider directly.
Duration of Data Processing

We will inform you further below about the duration of data processing, provided we have further information on it. For example, the social media platform Facebook stores data until it is no longer needed for its own purpose. However, customer data that is matched with own user data is deleted within two days. In general, we process personal data only for as long as is strictly necessary for the provision of our services and products. If required by law, as in the case of accounting for example, this storage duration can also be exceeded.
Right to Object

You also have the right and possibility at any time to revoke your consent to the use of cookies or third-party providers such as embedded social media elements. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating, or deleting cookies in your browser.
Since cookies can be used with social media tools, we also recommend our general privacy policy on cookies. To learn which data of yours is stored and processed exactly, you should read the privacy policies of the respective tools.
Legal Basis

If you have consented that data from you can be processed and stored by integrated social media elements, this consent applies as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, in the presence of consent, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in rapid and good communication with you or other customers and business partners. We nevertheless only use the tools insofar as you have given consent. Most social media platforms also set cookies in your browser to store data. Therefore, we recommend reading our data protection text on cookies carefully and viewing the privacy policy or cookie policies of the respective service provider.
Information on specific social media platforms can be found – if present – in the following sections.
Instagram Privacy Policy

  • Instagram Privacy Policy Summary
    • 👥 Data Subjects: Visitors to the website
    • 🤝 Purpose: Optimization of our service
    • 📓 Processed Data: Data such as user behavior data, information about your device, and your IP address. More details on this can be found further below in the privacy policy.
    • 📅 Storage Duration: until Instagram no longer needs the data for its purposes
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is Instagram?

We have integrated functions of Instagram on our website. Instagram is a social media platform of the company Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA. Instagram has been a subsidiary of Meta Platforms Inc. since 2012 and belongs to the Facebook products. The embedding of Instagram content on our website is called embedding. This allows us to show you content such as buttons, photos, or videos from Instagram directly on our website. When you call up web pages of our web presence that have an Instagram function integrated, data is transmitted to Instagram, stored, and processed. Instagram uses the same systems and technologies as Facebook. Your data is thus processed across all Facebook companies.
In the following, we want to give you a more detailed insight into why Instagram collects data, what data it involves, and how you can largely control data processing. Since Instagram belongs to Meta Platforms Inc., we obtain our information on the one hand from the Instagram guidelines, but on the other hand also from the Meta Privacy Policy itself.
Instagram is one of the most famous social media networks worldwide. Instagram combines the benefits of a blog with the benefits of audiovisual platforms like YouTube or Vimeo. You can upload photos and short videos to "Insta" (as many users casually call the platform), edit them with various filters, and also distribute them in other social networks. And if you don't want to be active yourself, you can also just follow other interesting users.
Why Do We Use Instagram on Our Website?

Instagram is that social media platform that has really gone through the roof in recent years. And of course, we have also reacted to this boom. We want you to feel as comfortable as possible on our website. That is why a varied presentation of our content is a matter of course for us. Through the embedded Instagram functions, we can enrich our content with helpful, funny, or exciting content from the Instagram world. Since Instagram is a subsidiary of Facebook, the collected data can also serve us for personalized advertising on Facebook. This way, our advertisements are only shown to people who are genuinely interested in our products or services.
Instagram also uses the collected data for measurement and analysis purposes. We receive aggregated statistics and thus more insight into your wishes and interests. It is important to mention that these reports do not identify you personally.
Which Data is Stored by Instagram?

When you encounter one of our pages that has built-in Instagram functions (such as Instagram images or plug-ins), your browser automatically connects to Instagram's servers. In doing so, data is sent to Instagram, stored, and processed. Namely, regardless of whether you have an Instagram account or not. This includes information about our website, about your computer, about purchases made, about advertisements you see, and how you use our offer. Furthermore, the date and time of your interaction with Instagram are also stored. If you have an Instagram account or are logged in, Instagram stores significantly more data about you.
Facebook distinguishes between customer data and event data. We assume that this is exactly the case with Instagram as well. Customer data includes, for example, name, address, phone number, and IP address. This customer data is only transmitted to Instagram after it has previously been "hashed". Hashing means converting a dataset into a character string. This makes it possible to encrypt contact data. In addition, the above-mentioned "event data" is also transmitted. By "event data", Facebook – and consequently also Instagram – means data about your user behavior. It can also happen that contact data is combined with event data. The collected contact data is matched with data that Instagram already has on you.
The collected data is transmitted to Facebook via small text files (cookies) that are mostly set in your browser. Depending on the Instagram functions used and whether you have an Instagram account yourself, varying amounts of data are stored.
We assume that data processing at Instagram works the same way as at Facebook. This means: if you have an Instagram account or have visited www.instagram.com, Instagram has set at least one cookie. If that is the case, your browser sends information to Instagram via the cookie as soon as you come into contact with an Instagram function. At the latest after 90 days (after matching), this data is deleted again or anonymized. Although we have dealt intensively with Instagram's data processing, we cannot say exactly which data Instagram precise collects and stores.
In the following, we show you cookies that are set in your browser as a minimum when you click on an Instagram function (such as a button or an Insta image). In our test, we assume that you do not have an Instagram account. If you are logged into Instagram, significantly more cookies will naturally be set in your browser.
These cookies were used in our test:

  • Name: csrftoken
  • Value: ""
  • Purpose: This cookie is set with high probability for security reasons to prevent request forgery. More precisely, however, we were not able to ascertain this.
  • Expiration Date: after one year
  • Name: mid
  • Value: ""
  • Purpose: Instagram sets this cookie to optimize its own services and offers on and off Instagram. The cookie establishes a unique user ID.
  • Expiration Date: after end of session
  • Name: fbsr_313234921124024
  • Value: no information
  • Purpose: This cookie stores the log-in request for users of the Instagram app.
  • Expiration Date: after end of session
  • Name: rur
  • Value: ATN
  • Purpose: This is an Instagram cookie that ensures functionality on Instagram.
  • Expiration Date: after end of session
  • Name: urlgen
  • Value: "{"194.96.75.33": 1901}:1iEtYv:Y833k2_UjKvXgYe313234921"
  • Purpose: This cookie serves Instagram's marketing purposes.
  • Expiration Date: after end of session

Note: We cannot claim completeness here. Which cookies are set in individual cases depends on the embedded functions and your use of Instagram.
How Long and Where is Data Stored?

Instagram shares the information received among the Facebook companies with external partners and with people you connect with worldwide. Data processing takes place in compliance with its own data policy. Your data is, among other things for security reasons, distributed across Facebook servers around the world. Most of these servers are located in the USA.
How Can I Delete My Data or Prevent Data Storage?

Thanks to the General Data Protection Regulation, you have the right to access, portability, rectification, and erasure of your data. You can manage your data in the Instagram settings. If you want to completely delete your data on Instagram, you must permanently delete your Instagram account.
And this is how deleting the Instagram account works: First open the Instagram app. On your profile page, go down and click on "Help Center". Now you come to the company's website. On the website, click on "Managing Your Account" and then on "Delete Your Account".
If you delete your account entirely, Instagram deletes posts such as your photos and status updates. Information that other people have shared about you does not belong to your account and is consequently not deleted.
As already mentioned above, Instagram stores your data primarily via cookies. You can manage, deactivate, or delete these cookies in your browser. Depending on your browser, management always works a little differently. Under the "Cookies" section, you will find the corresponding links to the respective instructions of the most well-known browsers.
You can also fundamentally set up your browser so that you are always informed when a cookie is to be set. Then you can always decide individually whether you want to allow the cookie or not.
Legal Basis

If you have consented that data from you can be processed and stored by integrated social media elements, this consent applies as the legal basis for data processing (Art. 6(1)(a) GDPR). In principle, your data is also stored and processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in rapid and good communication with you or other customers and business partners. We nevertheless only use integrated social media elements insofar as you have given consent. Most social media platforms also set cookies in your browser to store data. Therefore, we recommend reading our data protection text on cookies carefully and viewing the privacy policy or cookie policies of the respective service provider.
Instagram processes data from you, among other places, in the USA. Instagram or Meta Platforms is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure data transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Instagram uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are sample templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the Standard Contractual Clauses, Instagram commits to adhering to the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
We have tried to bring you closer to the most important information about data processing by Instagram. At https://privacycenter.instagram.com/policy/, you can deal in even greater detail with Instagram's data policies.
Blogs and Publication Media Introduction

  • Blogs and Publication Media Privacy Policy Summary
    • 👥 Data Subjects: Visitors to the website
    • 🤝 Purpose: Presentation and optimization of our service as well as communication between website visitors, security measures, and administration
    • 📓 Processed Data: Data such as contact details, IP address, and published content. More details on this can be found with the tools used.
    • 📅 Storage Duration: depending on the tools used
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests), Art. 6(1) sentence 1 lit. b. GDPR (Contract)

What are Blogs and Publication Media?

We use blogs or other means of communication on our website with which we on the one hand can communicate with you and on the other hand you can also communicate with us. In doing so, data from you may also be stored and processed by us. This may be necessary so that we can display content appropriately, communication works, and security is increased. In our data protection text, we address generally which data of yours can be processed. Exact specifications on data processing always depend also on the tools and functions used. In the privacy notices of individual providers, you will find detailed information about data processing.
Why Do We Use Blogs and Publication Media?

Our greatest concern with our website is to offer you interesting and exciting content, and at the same time your opinions and content are also important to us. That is why we want to create a good interactive exchange between us and you. With various blogs and publication possibilities, we can achieve exactly that. For example, you can write comments on our content, comment on other comments, or in some cases write posts yourself.
Which Data is Processed?

Which data is processed exactly always depends on the communication functions used by us. Very often, IP address, username, and published content are stored. This happens primarily to guarantee security protection, prevent spam, and be able to take action against unlawful content. Cookies can also be used for data storage. These are small text files that are stored with information in your browser. More on the collected and stored data can be found in our individual sections and in the privacy policy of the respective provider.
Duration of Data Processing

We will inform you further below about the duration of data processing, provided we have further information on it. For example, post and comment functions store data until you revoke data storage. Generally, personal data is stored only for as long as is strictly necessary for the provision of our services.
Right to Object

You also have the right and possibility at any time to revoke your consent to the use of cookies or third-party providers of communication tools. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, deactivating, or deleting cookies in your browser.
Since cookies can also be used with publication media, we also recommend our general privacy policy on cookies. To learn which data of yours is stored and processed exactly, you should read the privacy policies of the respective tools.
Legal Basis

We use communication media mainly on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in rapid and good communication with you or other customers, business partners, and visitors. Insofar as the use serves the execution of contractual relationships or their initiation, the legal basis is furthermore Art. 6(1) sentence 1 lit. b. GDPR.
Certain processings, in particular the use of cookies as well as the use of comment or message functions, require your consent. If and to the extent that you have consented that data from you can be processed and stored by integrated publication media, this consent applies as the legal basis for data processing (Art. 6(1)(a) GDPR). Most of the communication functions used by us set cookies in your browser to store data. Therefore, we recommend reading our data protection text on cookies carefully and viewing the privacy policy or cookie policies of the respective service provider.
Information on specific tools can be found – if present – in the following sections.
Blog Posts and Comment Functions Privacy Policy

There are various online communication media that we can use on our website. For example, we use blog posts and comment functions. This gives you the opportunity to also comment on content or write posts. When you use this function, your IP address, for example, may be stored for security reasons. In this way, we protect ourselves against unlawful content such as insults, unauthorized advertising, or forbidden political propaganda. In order to detect whether comments are spam, we can also store and process user details on the basis of our legitimate interest. If we launch a survey, we also store your IP address for the duration of the survey so that we can ensure that all participants really only vote once. Cookies may also be used for the purpose of storage. All data that we store from you (such as content or information about your person) remains stored until your objection.
Blogger.com Privacy Policy

We also use the hosting and blogger platform Blogger.com on our website. The service provider is the American company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services.
Google processes data from you, among other places, in the USA. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure data transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are sample templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the Standard Contractual Clauses, Google commits to adhering to the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can learn more about the data processed through the use of Google in the Privacy Policy at https://policies.google.com/privacy?hl=en.
Affiliate Programs Introduction

  • Affiliate Programs Privacy Policy Summary
    • 👥 Data Subjects: Visitors to the website
    • 🤝 Purpose: economic success and the optimization of our service
    • 📓 Processed Data: Access statistics containing data such as locations of access, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed.
    • 📅 Storage Duration: personal data is mostly stored by affiliate programs until it is no longer needed
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What are Affiliate Programs?

We use affiliate programs of different providers on our website. Through the use of an affiliate program, data from you can be transferred to the respective affiliate program provider, stored, and processed. In this data protection text, we give you a general overview of data processing by affiliate programs and show you how you can also prevent or revoke data transmission. Every affiliate program is based on the principle of referral commission. A link or an advertisement including a link is placed on our website, and if you are interested in it and click on it and purchase a product or service in this way, we receive a commission (advertising cost reimbursement) for it.
Why Do We Use Affiliate Programs on Our Website?

Our goal is to provide you with a pleasant time with lots of helpful content. For this, we put a lot of work and time into the development of our website. With the help of affiliate programs, we have the opportunity to be compensated a little for our work. Every partner link is of course always related to our topic and shows offers that might interest you.
Which Data is Processed?

So that it can be traced whether you clicked on a link placed by us, the affiliate program provider must learn that it was you who followed the link via our website. Correct assignment of the affiliate program links used to subsequent actions (deal completion, purchase, conversion, impression, etc.) must therefore occur. Only then can the billing of commissions work.
For this assignment to work, a value can be attached to a link (in the URL) or information stored in cookies. Stored therein, for example, is which page you come from (referrer), when you clicked on the link, an identifier of our website, which offer it is, and a user identifier.
This means that as soon as you interact with products and services of an affiliate program, this provider also collects data from you. Which data is stored exactly depends on the individual providers. For example, the Amazon Associate program distinguishes between active and automatic information. Active information includes name, email address, phone number, age, payment information, or location information. Automatically stored information in this case includes user behavior, IP address, device information, and the URL.
Duration of Data Processing

We will inform you further below about the duration of data processing, provided we have further information on it. Generally, personal data is processed only for as long as is necessary for the provision of services and products. Data stored in cookies is stored for varying lengths of time. Some cookies are deleted again right after leaving the website; others, unless actively deleted, can be stored in your browser over several years. The exact duration of data processing depends on the provider used; mostly you should prepare for a storage duration of several years. In the respective privacy policies of individual providers, you will usually receive detailed information about the duration of data processing.
Right to Object

You always have the right to access, rectification, and erasure of your personal data. If you have questions, you can also contact responsible persons of the used affiliate program provider at any time. Contact details can be found either in our specific privacy policy or on the website of the corresponding provider.
Cookies that providers use for their functions can be deleted, deactivated, or managed in your browser. Depending on which browser you use, this works in different ways.
Legal Basis

If you have consented that affiliate programs may be used, the legal basis of the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent), this consent represents the legal basis for the processing of personal data as can occur during collection by an affiliate program.
On our part, there is also a legitimate interest in using an affiliate program to optimize our online service and our marketing measures. The corresponding legal basis for this is Art. 6(1)(f) GDPR (Legitimate Interests). We nevertheless use the affiliate program only insofar as you have given consent.
Information on specific affiliate programs can be found – if present – in the following sections.
Amazon Associate Program Privacy Policy

  • Amazon Associate Program Privacy Policy Summary
    • 👥 Data Subjects: Visitors to the website
    • 🤝 Purpose: economic success and the optimization of our service
    • 📓 Processed Data: Access statistics containing data such as locations of access, device data, duration and time of access, navigation behavior, click behavior, and IP addresses. Personal data such as name or email address may also be processed.
    • 📅 Storage Duration: personal data is stored by Amazon until it is no longer needed
    • ⚖️ Legal Bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is the Amazon Associate Program?

We use the Amazon Associate Program of the company Amazon.com, Inc. on our website. The responsible entities within the meaning of the privacy policy are Amazon Europe Core S.à.r.l., Amazon EU S.à.r.l, Amazon Services Europe S.à.r.l., and Amazon Media EU S.à.r.l., all four located at 5, Rue Plaetis, L-2338 Luxembourg, as well as Amazon Instant Video Germany GmbH, Domagkstr. 28, 80807 Munich. Acting as data processor is Amazon Deutschland Services GmbH, Marcel-Breuer-Str. 12, 80807 Munich. Through the use of this Amazon Associate Program, data from you can be transferred to Amazon, stored, and processed.
In this privacy policy, we inform you about what data it involves, why we use the program, and how you can manage or prevent data transmission.
The Amazon Associate Program is an affiliate marketing program of the online mail-order company Amazon.de. Like any affiliate program, the Amazon Associate Program is based on the principle of referral commission. Amazon or we place advertising or partner links on our website, and if you click on them and purchase a product via Amazon, we receive advertising cost reimbursement (commission).
Why Do We Use the Amazon Associate Program on Our Website?

Our goal is to provide you with a pleasant time with lots of helpful content. For this, we put a lot of work and energy into the development of our website. With the help of the Amazon Associate Program, we have the opportunity to be compensated a little for our work. Every partner link to Amazon is of course always related to our topic and shows offers that might interest you.
Which Data is Stored by the Amazon Associate Program?

As soon as you interact with the products and services of Amazon, Amazon collects data from you. Amazon distinguishes between information that you actively give to the company and information that is automatically collected and stored. "Active information" includes, for example, name, email address, phone number, age, payment information, or location information. So-called "automatic information" is primarily stored via cookies. This includes information on user behavior, IP address, device information (browser type, location, operating systems), or the URL. Amazon furthermore also stores the clickstream. This means the path (sequence of pages) that you as a user cover to get to a product. Also to be able to trace the origin of an order, Amazon stores cookies in your browser. In this way, the company recognizes that you clicked an Amazon advertisement or a partner link via our website.
If you have an Amazon account and are logged in while surfing on our website, the collected data can be assigned to your account. You prevent this by logging out of Amazon before surfing on our website.
Here we show you exemplary cookies that are set in your browser when you click on an Amazon link on our website:

  • Name: uid
  • Value: 3230928052675285215313234921-9
  • Purpose: This cookie stores a unique user ID and collects information about your website activity.
  • Expiration Date: after 2 months
  • Name: ad-id
  • Value: AyDaInRV1k-Lk59xSnp7h5o
  • Purpose: This cookie is provided by amazon-adsystem.com and serves the company for various advertising purposes.
  • Expiration Date: after 8 months
  • Name: uuid2
  • Value: 8965834524520213028313234921-2
  • Purpose: This cookie enables targeted and interest-based advertising via the AppNexus platform. The cookie collects and stores anonymous data via the IP address, for example, about which advertising you clicked and which pages you called up.
  • Expiration Date: after 3 months
  • Name: session-id
  • Value: 262-0272718-2582202313234921-1
  • Purpose: This cookie stores a unique user ID assigned to you by the server for the duration of a website visit (session). If you visit the same page again, the information stored therein is retrieved again.
  • Expiration Date: after 15 years
  • Name: APID
  • Value: UP9801199c-4bee-11ea-931d-02e8e13f0574
  • Purpose: This cookie stores information about how you use a website and which advertising you viewed before visiting the website.
  • Expiration Date: after one year
  • Name: session-id-time
  • Value: tb:s-STNY7ZS65H5335FZEVPE|1581329862486&t:1581329864300&adb:adblk_no
  • Purpose: This cookie records the time you spend on a web page with a unique cookie ID.
  • Expiration Date: after 2 years
  • Name: csm-hit
  • Value: 2082754801l
  • Purpose: We could not ascertain exact information about this cookie.
  • Expiration Date: after 15 years

Note: Please note that this list merely shows cookie examples and cannot claim completeness.
Amazon uses this received information to match advertisements more precisely to the interests of users.
How Long and Where is Data Stored?

Personal data is stored by Amazon for as long as necessary for Amazon's business services or required for legal reasons. Since the company Amazon has its headquarters in the USA, the collected data is also stored on American servers.
How Can I Delete My Data or Prevent Data Storage?

You have the right to access your personal data and also to delete it at any time. If you own an Amazon account, you can manage or delete much of the collected data in your account.
Another option to manage data processing and storage by Amazon according to your preferences is offered by your browser. There you can manage, deactivate, or delete cookies. This works a little differently with every browser. Under the "Cookies" section, you will find the corresponding links to the respective instructions of the most well-known browsers.
Legal Basis

If you have consented that the Amazon Associate Program may be used, the legal basis of the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent), this consent represents the legal basis for the processing of personal data as can occur during collection by the Amazon Associate Program.
On our part, there is also a legitimate interest in using the Amazon Associate Program to optimize our online service and our marketing measures. The corresponding legal basis for this is Art. 6(1)(f) GDPR (Legitimate Interests). We nevertheless use the Amazon Associate Program only insofar as you have given consent.
Amazon processes data from you, among other places, in the USA. Amazon is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure data transfer of personal data of EU citizens to the USA. More information on this can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Amazon uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCC) are sample templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even when transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and through the Standard Contractual Clauses, Amazon commits to adhering to the European level of data protection when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Amazon Data Processing Terms (AWS GDPR DATA PROCESSING), which correspond to the Standard Contractual Clauses, can be found at https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf.
We hope we have brought you closer to the most important information about data transmission through the use of the Amazon Associate Program. More information can be found at https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010.
Closing Remarks

Congratulations! If you are reading these lines, you have really "fought" your way through our entire privacy policy or at least scrolled down to here. As you can see from the scope of our privacy policy, we take the protection of your personal data anything but lightly.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, however, we do not only want to inform you which data is processed, but also bring you closer to the motives for using various software programs. Usually, privacy policies sound very technical and legalistic. Since most of you are not web developers or lawyers, however, we also wanted to take a different path linguistically and explain the facts in simple and clear language. This is of course not always possible due to the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
For questions regarding data protection on our website, please do not hesitate to contact us or the responsible entity. We wish you a wonderful time and hope to welcome you to our website again soon.
All texts are protected by copyright.
Source: Privacy Policy created with the Privacy Policy Generator for Germany by AdSimple