Our official Privacy Policy explains how we handle your data, our use of cookies, and your rights under GDPR. Learn more about our commitment to your privacy.
How can you use Arabic for Nerds?
Before we get to everything else: There are two options to use Arabic for Nerds:
- Allowing ads (free)
- Arabic for Nerds+ (paid)
With the Arabic for Nerds+ option, we forgo advertising tracking altogether and also advertising as far as possible. Here, we analyze your usage solely for the purpose of tailoring our offer to your needs and do not pass on any usage data to third parties.
If, on the other hand, you wish to read us free of charge, we will finance our offer with your consent by means of further advertising and, above all, also by means of advertising tracking together with the forwarding of data to selected third parties for the playout and optimization of advertisements geared to your usage behavior and your presumed interests and needs.
For advertising tracking, we then store and use cookies, device identifiers and similar tracking technologies on your end devices. You will find a detailed overview of the services and cookies used for this purpose further down on this page.
The legal basis for advertising tracking is the German Telecommunications Digital Services Data Protection Act (TDDDG) (Section 25 TDDDG) regarding the storage of information on, or access to information in, your device, and the European General Data Protection Regulation (GDPR) (Article 6(1)(a) GDPR (consent)) regarding the subsequent processing of personal data. You can revoke your consent to advertising tracking at any time with effect for the future. If you do not consent to advertising tracking or revoke your consent, free access financed by personalized advertising may be limited; the paid “Arabic for Nerds+” option remains available as a tracking-free access option as far as possible.
Deleting cookies:
The legal basis for the few cookies and similar technologies also used in the Arabic for Nerds+ offer to provide security, account access, paid content, membership functions, and basic functionality is Section 25(2) TDDDG where the storage of, or access to, information is strictly necessary. Subsequent processing of personal data is based on Article 6(1)(b) GDPR (performance of contract) and Article 6(1)(f) GDPR (legitimate interests), unless a more specific legal basis is stated below.
If you want to comprehensively deactivate advertising tracking with data transfer to third parties with us, we recommend the “Arabic for Nerds+” option. To do this, it is not enough to activate a “Do-Not-Track Mode” in one of your browsers. Alternatively, however, you also have the option of setting an “Opt-Out” for each of the service providers listed in the PRIVACY SETTINGS. To do this, you would have to use the opt-out function on the websites of the respective service providers.
The services deactivated in this way will then not only be blocked for our offer, but also generally for the end device you are using. The settings are saved for your device or for your browser. If you use multiple browsers on multiple devices, you must select and deselect your settings on each browser separately, because we cannot or may not synchronize the opt-outs for you. In contrast, the Arabic for Nerds+ option with your log-in is of course usable on all your devices.
About comments – disclaimer:
For an open discussion, we reserve the right to delete any comment that is not directly related to the topic or has only the purpose of disparaging readers or authors. We want respectful communication with one another, as if the discussion were being conducted with real people present. We do this for the majority of our readers who want to talk about a topic factually and constructively – with humor, too.
Privacy Policy
Last updated: June 2026
1. An overview of data protection
General information
The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website. The term “personal data” comprises all data that can be used to personally identify you. For detailed information about the subject matter of data protection, please consult our Data Protection Declaration, which we have included beneath this copy.
Data recording on this website
Who is the responsible party for the recording of data on this website (i.e., the “controller”)?
The data on this website is processed by the operator of the website, whose contact information is available under section “Information about the responsible party (referred to as the “controller” in the GDPR)” in this Privacy Policy.
How do we record your data?
We collect your data as a result of your sharing of your data with us. This may, for instance be information you enter into our contact form.
Other data shall be recorded by our IT systems automatically or after you consent to its recording during your website visit. This data comprises primarily technical information (e.g., web browser, operating system, or time the site was accessed). This information is recorded automatically when you access this website.
What are the purposes we use your data for?
A portion of the information is generated to guarantee the error free provision of the website. Other data may be used to analyze your user patterns. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders or other order enquiries.
What rights do you have as far as your information is concerned?
You have the right to receive information about the source, recipients, and purposes of your archived personal data at any time without having to pay a fee for such disclosures. You also have the right to demand that your data are rectified or eradicated. If you have consented to data processing, you have the option to revoke this consent at any time, which shall affect all future data processing. Moreover, you have the right to demand that the processing of your data be restricted under certain circumstances. Furthermore, you have the right to log a complaint with the competent supervising agency.
Please do not hesitate to contact us at any time if you have questions about this or any other data protection related issues.
Analysis tools and tools provided by third parties
There is a possibility that your browsing patterns will be statistically analyzed when your visit this website. Such analyses are performed primarily with what we refer to as analysis programs.
For detailed information about these analysis programs please consult our Data Protection Declaration below.
2. Hosting and Content Delivery Networks (CDN)
We are hosting the content of our website at the following provider:
All-Inkl
The Provider is the ALL-INKL.COM – Neue Medien Münnich, owner: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany (hereinafter “All-Inkl”). For details, please visit the privacy policy of All-Inkl: https://all-inkl.com/datenschutzinformationen/.
The use of All-Inkl is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the most reliable representation of our website. If appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, insofar the consent includes the storage of cookies or the access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TDDDG. This consent can be revoked at any time.
Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
Cloudflare
We use the “Cloudflare” service provided by Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter referred to as “Cloudflare”).
Cloudflare provides a global content delivery network (CDN), DNS, security, firewall, caching, and performance services. The information transfer between your browser and our website is technically routed via Cloudflare’s network. This enables Cloudflare to analyze data traffic between your browser and our website, to deliver cached content from geographically distributed servers, and to act as a filter between our servers and potentially malicious traffic from the Internet.
We also use Cloudflare Automatic Platform Optimization (APO) for WordPress. APO may cache pages and static or dynamic website content at Cloudflare’s edge network to provide the website more quickly, reliably, and securely. In this context, Cloudflare may process IP addresses, request headers, URLs requested, timestamps, security events, and similar technical data required to deliver, cache, optimize, and protect the website.
Cloudflare may use cookies or similar technologies for security, load balancing, bot detection, abuse prevention, and technical functionality. These technologies are used for the purposes described here and not for our own advertising tracking.
The use of Cloudflare, including Cloudflare APO, is based on our legitimate interest in the secure, reliable, fast, and technically error-free provision of our website (Art. 6(1)(f) GDPR). Where Cloudflare stores information on your device or accesses information already stored on your device and this is strictly necessary to provide the website, protect the service, or maintain security, the legal basis under German law is Section 25(2) TDDDG. If consent is requested for non-essential functions, processing is carried out on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG; consent can be revoked at any time.
Data transfer to the United States may take place within the scope of Cloudflare’s certification under the EU-US Data Privacy Framework (DPF). Where the DPF does not apply, data transfers are based on the Standard Contractual Clauses (SCC) of the European Commission and additional safeguards where required. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/ and https://www.cloudflare.com/cloudflare-customer-dpa/.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US for certified organizations. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5666.
Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that Cloudflare processes personal data of our website visitors only based on our instructions and in compliance with the GDPR, unless Cloudflare acts as an independent controller for specific security or abuse-prevention processing under its own terms.
WP Rocket
We use WP Rocket, a WordPress caching and performance plugin, on this website. The provider is WP Media, 6 rue d’Armaillé, 75017 Paris, France.
WP Rocket generates and optimizes cached versions of our website pages and may optimize files such as CSS, JavaScript, and images in order to improve loading times. The cache files are generally stored on our server. WP Rocket may also preload pages by technically simulating page visits so that cached versions can be generated before a real visitor accesses a page.
WP Rocket itself is used for the technical optimization and secure, efficient delivery of this website. The legal basis is Art. 6(1)(f) GDPR. We have a legitimate interest in a fast, stable, and resource-efficient website. If WP Rocket uses or respects cookies for cache differentiation, login status, consent status, or membership-related page variants, this is done only to provide the website correctly and to avoid serving personalized or protected content from the wrong cache. Where the storage of or access to information on your device is strictly necessary for these purposes, the legal basis is Section 25(2) TDDDG.
3. General information and mandatory information
Data protection
The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration.
Whenever you use this website, a variety of personal information will be collected. Personal data comprises data that can be used to personally identify you. This Data Protection Declaration explains which data we collect as well as the purposes we use this data for. It also explains how, and for which purpose the information is collected.
We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.
Information about the responsible party (referred to as the “controller” in the GDPR)
The data processing controller on this website is:
Gerald Drißner, journalist and author, Simon-Dach-Straße 9, 10245 Berlin
Phone: +493049960958
E-mail: [email protected]
The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g., names, e-mail addresses, etc.).
Storage duration
Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.
General information on the legal basis for the data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, if special categories of data are processed according to Art. 9(1) GDPR. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49 (1)(a) GDPR. If you have consented to the storage of cookies or to the access to information in your end device (e.g., via device fingerprinting), the data processing is additionally based on § 25 (1) TDDDG. The consent can be revoked at any time. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, if your data is required for the fulfillment of a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Furthermore, the data processing may be carried out on the basis of our legitimate interest according to Art. 6(1)(f) GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.
Information on data transfers to third countries
Some of the services used on this website are provided by companies or corporate groups that may process personal data outside the European Union or the European Economic Area. Where data is transferred to a third country, this is done only if there is an adequate level of protection under an adequacy decision pursuant to Art. 45 GDPR, if appropriate safeguards such as Standard Contractual Clauses pursuant to Art. 46 GDPR are in place, or if another legal basis under Chapter V GDPR applies.
For transfers to certified organizations in the United States, we may rely on the EU-US Data Privacy Framework (DPF) where the relevant recipient is listed as certified and the transfer falls within the scope of that certification. If a provider is not certified under the DPF, or if a specific transfer is not covered by the certification, we rely on Standard Contractual Clauses and, where necessary, additional safeguards or your explicit consent pursuant to Art. 49(1)(a) GDPR. Details on individual recipients and transfer mechanisms can be found in the respective sections of this Privacy Policy.
Recipients of personal data
In the scope of our business activities, we cooperate with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is required as part of the fulfillment of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Art. 6 (1)(f) GDPR, or if another legal basis permits the disclosure of this data. When using processors, we only disclose personal data of our customers on the basis of a valid contract on data processing. In the case of joint processing, a joint processing agreement is concluded.
Revocation of your consent to the processing of data
A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)
If data are processed on the basis of Art. 6(1)(e) or Art. 6(1)(f) GDPR, you have the right to object at any time to the processing of your personal data on grounds relating to your particular situation. This also applies to any profiling based on these provisions. To determine the legal basis on which any processing of data is based, please consult this Privacy Policy. If you lodge an objection, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims (objection pursuant to Art. 21(1) GDPR).
If your personal data are processed for direct advertising, you have the right to object at any time to the processing of your personal data for the purposes of such advertising. This also applies to profiling to the extent that it is related to such direct advertising. If you object, your personal data will subsequently no longer be used for direct advertising purposes (objection pursuant to Art. 21(2) GDPR).
Right to log a complaint with the competent supervisory agency
In the event of violations of the GDPR, data subjects are entitled to log a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred. The right to log a complaint is in effect regardless of any other administrative or court proceedings available as legal recourses.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you should demand the direct transfer of the data to another controller, this will be done only if it is technically feasible.
Information about, rectification and eradication of data
Within the scope of the applicable statutory provisions, you have the right to demand information about your archived personal data, their source and recipients as well as the purpose of the processing of your data at any time. You may also have a right to have your data rectified or eradicated. If you have questions about this subject matter or any other questions about personal data, please do not hesitate to contact us at any time.
Right to demand processing restrictions
You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. To do so, you may contact us at any time. The right to demand restriction of processing applies in the following cases:
- In the event that you should dispute the correctness of your data archived by us, we will usually need some time to verify this claim. During the time that this investigation is ongoing, you have the right to demand that we restrict the processing of your personal data.
- If the processing of your personal data was/is conducted in an unlawful manner, you have the option to demand the restriction of the processing of your data instead of demanding the eradication of this data.
- If we do not need your personal data any longer and you need it to exercise, defend or claim legal entitlements, you have the right to demand the restriction of the processing of your personal data instead of its eradication.
- If you have raised an objection pursuant to Art. 21(1) GDPR, your rights and our rights will have to be weighed against each other. As long as it has not been determined whose interests prevail, you have the right to demand a restriction of the processing of your personal data.
If you have restricted the processing of your personal data, these data – with the exception of their archiving – may be processed only subject to your consent or to claim, exercise or defend legal entitlements or to protect the rights of other natural persons or legal entities or for important public interest reasons cited by the European Union or a member state of the EU.
SSL and/or TLS encryption
For security reasons and to protect the transmission of confidential content, such as purchase orders or inquiries you submit to us as the website operator, this website uses either an SSL or a TLS encryption program. You can recognize an encrypted connection by checking whether the address line of the browser switches from “http://” to “https://” and also by the appearance of the lock icon in the browser line.
If the SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If you are under an obligation to share your payment information (e.g. account number if you give us the authority to debit your bank account) with us after you have entered into a fee-based contract with us, this information is required to process payments.
Payment transactions using common modes of paying (Visa/MasterCard, debit to your bank account) are processed exclusively via encrypted SSL or TLS connections. You can recognize an encrypted connection by checking whether the address line of the browser switches from “http://” to “https://” and also by the appearance of the lock icon in the browser line.
If the communication with us is encrypted, third parties will not be able to read the payment information you share with us.
Rejection of unsolicited e-mails
We herewith object to the use of contact information published in conjunction with the mandatory information to be provided in our Site Notice to send us promotional and information material that we have not expressly requested. The operators of this website and its pages reserve the express right to take legal action in the event of the unsolicited sending of promotional information, for instance via SPAM messages.
4. Recording of data on this website
Cookies
Our websites and pages use what the industry refers to as “cookies.” Cookies are small data packages that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or they are permanently archived on your device (permanent cookies). Session cookies are automatically deleted once you terminate your visit. Permanent cookies remain archived on your device until you actively delete them, or they are automatically erased by your web browser.
Cookies can be issued by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain third-party services into websites, for example for payment processing, advertising, analytics, spam protection, embedded media, or affiliate tracking.
Cookies and similar technologies have a variety of functions. Many are technically essential because certain website functions would not work without them, such as login sessions, membership access, payment checkout, consent storage, security functions, caching, or the display of content you requested. Other cookies and similar technologies may be used to analyze user behavior, measure reach, attribute affiliate commissions, or deliver and optimize advertising.
Cookies and similar technologies that are strictly necessary to provide a service expressly requested by you, to transmit a communication, or to maintain security and functionality are used on the basis of Section 25(2) TDDDG. The subsequent processing of personal data is based on Art. 6(1)(b) GDPR where it is necessary for a contract or pre-contractual measures, Art. 6(1)(c) GDPR where we must comply with a legal obligation, and Art. 6(1)(f) GDPR where we have a legitimate interest in the secure and technically error-free operation of our website.
All non-essential cookies and similar technologies, in particular for analytics, advertising tracking, personalized advertising, profiling, or affiliate tracking that requires storage of or access to information on your device, are used only if you have given consent. The legal basis is Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may revoke your consent at any time with effect for the future through the privacy settings or consent banner.
You have the option to set up your browser in such a manner that you will be notified any time cookies are placed and to permit the acceptance of cookies only in specific cases. You may also exclude the acceptance of cookies in certain cases or in general, or activate the delete function for the automatic erasure of cookies when the browser closes. If cookies are deactivated, the functions of this website may be limited.
Which cookies and services are used on this website can be found in this Privacy Policy and, where available, in the privacy settings of our consent banner.
Consent with Complianz
Our website uses Complianz’s consent technology to obtain your consent to store certain cookies on your device or for the use of certain technologies and to document this consent in a manner compliant with data protection regulations. The provider of this technology is Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, the Netherlands (hereinafter “Complianz”).
Complianz is hosted on our servers, so no connection to the servers of the provider of Complianz is established merely because the consent banner is displayed. Complianz stores a cookie in your browser in order to allocate the consents granted to you or their revocation. The data collected in this way is stored until you request us to delete it, delete the Complianz cookie yourself, or until the purpose for storing the data no longer applies. Mandatory legal storage obligations remain unaffected.
Complianz serves to obtain and document legally required consent for the use of cookies and similar technologies and to remember your privacy settings. Where technically required for advertising or analytics services, your consent choices may also be transmitted to the respective service providers as consent signals. The legal basis for this processing is Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. The storage of the consent cookie is necessary within the meaning of Section 25(2) TDDDG.
Server log files
The provider of this website and its pages automatically collects and stores information in so-called server log files, which your browser communicates to us automatically. The information comprises:
- The type and version of browser used
- The used operating system
- Referrer URL
- The hostname of the accessing computer
- The time of the server inquiry
- The IP address
This data is not merged with other data sources.
This data is recorded on the basis of Art. 6(1)(f) GDPR. The operator of the website has a legitimate interest in the technically error free depiction and the optimization of the operator’s website. In order to achieve this, server log files must be recorded.
Contact form
If you submit inquiries to us via our contact form, the information provided in the contact form as well as any contact information provided therein will be stored by us in order to handle your inquiry and in the event that we have further questions. We will not share this information without your consent.
The processing of these data is based on Art. 6(1)(b) GDPR, if your request is related to the execution of a contract or if it is necessary to carry out pre-contractual measures. In all other cases the processing is based on our legitimate interest in the effective processing of the requests addressed to us (Art. 6(1)(f) GDPR) or on your agreement (Art. 6(1)(a) GDPR) if this has been requested; the consent can be revoked at any time.
The information you have entered into the contact form shall remain with us until you ask us to eradicate the data, revoke your consent to the archiving of data or if the purpose for which the information is being archived no longer exists (e.g., after we have concluded our response to your inquiry). This shall be without prejudice to any mandatory legal provisions, in particular retention periods.
Request by e-mail, telephone, or fax
If you contact us by e-mail, telephone or fax, your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not pass these data on without your consent.
These data are processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or is required for the performance of pre-contractual measures. In all other cases, the data are processed on the basis of our legitimate interest in the effective handling of inquiries submitted to us (Art. 6(1)(f) GDPR) or on the basis of your consent (Art. 6(1)(a) GDPR) if it has been obtained; the consent can be revoked at any time.
The data sent by you to us via contact requests remain with us until you request us to delete, revoke your consent to the storage or the purpose for the data storage lapses (e.g. after completion of your request). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
Registration on this website
You have the option to register on this website to be able to use additional website functions. We shall use the data you enter only for the purpose of using the respective offer or service you have registered for. The required information we request at the time of registration must be entered in full. Otherwise, we shall reject the registration.
To notify you of any important changes to the scope of our portfolio or in the event of technical modifications, we shall use the e-mail address provided during the registration process.
The data entered during registration is processed for the purpose of implementing the user relationship established by the registration and, if necessary, for the initiation of further contracts (Art. 6 (1)(b) GDPR).
The data recorded during the registration process shall be stored by us as long as you are registered on this website. Subsequently, such data shall be deleted. This shall be without prejudice to mandatory statutory retention obligations.
Social Login (Registration via Facebook, Google, TikTok, etc.)
You can register and log in to our website using your existing accounts with various social networks (e.g., Facebook, Google, TikTok). To do this, you will be redirected to the page of the respective provider, where you can log in with your existing usage data. This links your profile with that provider to our website.
Through this link, we automatically receive personal data from the provider. We have strictly limited this data transfer to the absolute minimum required for authentication. Depending on the provider, we only receive and process the following data:
- Your Name (First and Last Name)
- Your Email Address
- Your Profile Picture (Avatar)
- The unique user ID assigned to you by the provider
We do not request or process your friends lists, contacts, likes, birthdays, or other profile details. The data is used to set up, provide, and customize your account.
Registration with Facebook Connect
The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook’s statement the collected data will be transferred to the USA and other third-party countries too.
If you decide to register via Facebook Connect, you will be automatically connected to the Facebook platform. This link gives us access to the strictly limited data mentioned above (Name, Email, Picture) stored with Facebook. We use this data exclusively to verify your identity for the login process and to display your name and avatar next to your comments.
The registration via Facebook Connect and the affiliated data processing transactions are implemented on the basis of your consent (Art. 6(1)(a) GDPR). You may revoke this consent at any time, which shall affect all future transactions thereafter.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The wording of the agreement can be found under: https://www.facebook.com/legal/controller_addendum.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). For more information: https://www.dataprivacyframework.gov/participant/4452.
Registration with Google
You can register with Google. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you sign in with Google, we use the specific information mentioned above (Name, Email, Picture) to create your profile. You can manage your connection settings here: https://myaccount.google.com/permissions.
The data processing associated with Google’s registration is based on your consent (Art. 6(1)(a) GDPR) and the fulfillment of the contract for account creation (Art. 6(1)(b) GDPR).
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). For more information: https://www.dataprivacyframework.gov/participant/5780.
Registration with TikTok
You can register using your TikTok account. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.
When you register via TikTok, a connection is established between our website and TikTok’s servers. TikTok provides us with your profile information (Name, Email, Avatar) to create your account. This data transfer serves the purpose of authentication and account management.
The use of this service is based on your consent (Art. 6(1)(a) GDPR) and the necessity for the performance of the contract (Art. 6(1)(b) GDPR). Data may be transferred to countries outside the EU/EEA (e.g., USA, China). TikTok relies on Standard Contractual Clauses (SCCs) to ensure data protection. For more information, please see TikTok’s privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en.
The comment function on this website
When you use the comment function on this website, information on the time the comment was generated and your e-mail-address and, if you are not posting anonymously, the username you have selected will be archived in addition to your comments.
Storage of the IP address
Our comment function stores the IP addresses of all users who enter comments. Given that we do not review the comments prior to publishing them, we need this information in order to take action against the author in the event of rights violations, such as defamation or propaganda.
Subscribing to comments
As a user of this website, you have the option to subscribe to comments after you have registered. You will receive a confirmation e-mail, the purpose of which is to verify whether you are the actual holder of the provided e-mail address. You can deactivate this function at any time by following a respective link in the information e-mails. The data entered in conjunction with subscriptions to comments will be deleted in this case. However, if you have communicated this information to us for other purposes and from a different location (e.g., when subscribing to the newsletter), the data shall remain in our possession.
Storage period for comments
Comments and any affiliated information shall be stored by us and remain on this website until the content the comment pertained to has been deleted in its entirety or if the comments had to be deleted for legal reasons (e.g., insulting comments).
Legal basis
Comments are stored on the basis of your consent (Art. 6(1)(a) GDPR). You have the right to revoke at any time any consent you have already given us. To do so, all you are required to do is sent us an informal notification via e-mail. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
Gravatar
We have integrated Gravatar on this website. The provider is Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA (hereinafter Gravatar).
Gravatar is a tool that lets you provide personal images (avatars) to users of our website. The avatars serve as visual representations of the users and are displayed wherever a user interacts with the platform (e.g., in forums or chats). When a user interacts with the platform, their avatar is displayed based on the choices associated with their email address. This adds a personal touch to the users’ online presence and simplifies the identification process, as the selected image is associated with the users when they are active online.
When commenting or interacting on our website with Gravatar enabled, the hash of the email address of the user using Gravatar (used as an ID) is processed by Gravatar.
The use of Gravatar is based on Art. 6 (1)(f) GDPR. The website operator has a legitimate interest in an appealing presentation of its forums. Insofar as a corresponding consent was requested, the processing is carried out exclusively on the basis of Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. This consent can be revoked at any time.
For further details, please refer to the provider’s privacy policy: https://automattic.com/privacy/.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4709.
Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
5. Social media
We have integrated elements of the social network Facebook on this website. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. According to Facebook’s statement the collected data will be transferred to the USA and other third-party countries too.
An overview of the Facebook social media elements is available under the following link: https://developers.facebook.com/docs/plugins/.
If the social media element has been activated, a direct connection between your device and the Facebook server will be established. As a result, Facebook will receive information confirming your visit to this website with your IP address. If you click on the Facebook Like button while you are logged into your Facebook account, you can link content of this website to your Facebook profile. Consequently, Facebook will be able to allocate your visit to this website to your user account. We have to emphasize that we as the provider of the website do not receive any information on the content of the transferred data and its use by Facebook. For more information, please consult the Data Privacy Policy of Facebook at: https://de-de.facebook.com/privacy/explanation.
The use of this service is based on your consent in accordance with Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing by Facebook that takes place after the onward transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The wording of the agreement can be found under: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information when using the Facebook tool and for the privacy-secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. You can assert data subject rights (e.g., requests for information) regarding data processed by Facebook directly with Facebook. If you assert the data subject rights with us, we are obliged to forward them to Facebook.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4452.
X (formerly Twitter)
We have integrated functions of the social media platform X (formerly Twitter) into this website. These functions are provided by the parent company X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. The branch Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, is responsible for the data processing of individuals living outside the United States.
If the social media element has been activated, a direct connection between your device and X’s server will be established. As a result, X (formerly Twitter) will receive information on your visit to this website. While you use X (formerly Twitter) and the “Re-Tweet” or “Repost” function, websites you visit are linked to your X (formerly Twitter) account and disclosed to other users. We must point out, that we, the providers of the website and its pages do not know anything about the content of the data transferred and the use of this information by X (formerly Twitter). For more details, please consult the X (formerly Twitter) Data Privacy Declaration at: https://x.com/en/privacy.
The use of this service is based on your consent in accordance with Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. Consent can be revoked at any time.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://gdpr.x.com/en/controller-to-controller-transfers.html.
You have the option to reset your data protection settings on X (formerly Twitter) under the account settings at https://x.com/settings/account.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/2710.
We have integrated functions of the public media platform Instagram into this website. These functions are being offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
If the social media element has been activated, a direct connection between your device and Instagram’s server will be established. As a result, Instagram will receive information on your visit to this website.
If you are logged into your Instagram account, you may click the Instagram button to link contents from this website to your Instagram profile. This enables Instagram to allocate your visit to this website to your user account. We have to point out that we as the provider of the website and its pages do not have any knowledge of the content of the data transferred and its use by Instagram.
The use of this service is based on your consent in accordance with Art. 6 (1)(a) GDPR and § 25 (1) TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook or Instagram. The processing by Facebook or Instagram that takes place after the onward transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The wording of the agreement can be found under: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information when using the Facebook or Instagram tool and for the privacy-secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook or Instagram products. You can assert data subject rights (e.g., requests for information) regarding data processed by Facebook or Instagram directly with Facebook. If you assert the data subject rights with us, we are obliged to forward them to Facebook.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381.
For more information on this subject, please consult Instagram’s Data Privacy Declaration at: https://privacycenter.instagram.com/policy/.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4452.
6. Analysis tools and advertising
Cloudflare Zaraz
We use Cloudflare Zaraz. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).
Cloudflare Zaraz is a tag-management and third-party-tool management service. It allows us to manage and load selected tools, such as analytics or advertising technologies, via Cloudflare’s infrastructure instead of integrating every tool directly into the website source code. This can improve performance, reduce the number of direct browser connections to third-party providers, and help us apply consent choices before optional tools are loaded.
When Zaraz is used, technical data may be processed, including your IP address, request and event data, browser and device information, page URL, referrer information, timestamps, consent status, and technical identifiers required to execute configured tools and transmit consent signals. The exact data processed depends on the individual tool configured in Zaraz. Optional analytics or advertising tools are loaded only where the required legal basis exists, in particular where you have given consent through the consent management mechanism.
Cloudflare Zaraz also supports consent management, the IAB Europe Transparency & Consent Framework and Google Consent Mode, where configured. This is relevant in particular for Google AdSense and other advertising or analytics tools that require granular consent signals in the EEA, the United Kingdom and Switzerland.
The legal basis for the technical operation of Zaraz as part of our website infrastructure is Art. 6(1)(f) GDPR. We have a legitimate interest in secure, privacy-conscious and efficient management of website tools. Where Zaraz or tools loaded through Zaraz store information on your device or access information already stored on your device, and this is not strictly necessary to provide the website or a requested function, this takes place only on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be revoked at any time. Where storage or access is strictly necessary for security, consent management or a function expressly requested by you, Section 25(2) TDDDG applies.
Further information can be found in Cloudflare’s privacy policy and Cloudflare’s Zaraz documentation: https://www.cloudflare.com/privacypolicy/ and https://developers.cloudflare.com/zaraz/.
Cloudflare analytics, logs and anonymized Cloudflare data
We use Cloudflare-provided analytics, security logs and technical request information in order to understand the performance, availability and security of our website. This may include aggregated or anonymized information about requests, page views, country or region, browser type, device type, referrers, cache status, firewall events, bot-management signals, error rates and similar technical metrics.
Where we use Cloudflare data for statistical or editorial purposes, we use it in aggregated or anonymized form as far as possible and do not use it to identify individual visitors. Cloudflare may nevertheless process personal data such as IP addresses, request headers, user-agent data, timestamps, URLs and security-event data in order to provide the CDN, security, caching and analytics services described in this Privacy Policy.
The legal basis is Art. 6(1)(f) GDPR. We have a legitimate interest in measuring the technical performance of our website, detecting errors, preventing abuse, improving security and understanding the approximate use of our content without creating individual advertising profiles from this Cloudflare data. Where a Cloudflare feature stores information on your device or accesses information already stored on your device, the applicable legal basis under German law is Section 25 TDDDG as described in the Cloudflare section above.
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior patterns of website visitors. To that end, the website operator receives a variety of user data, such as pages accessed, time spent on the page, the utilized operating system and the user’s origin. This data is summarized in a user-ID and assigned to the respective end device of the website visitor.
Furthermore, Google Analytics allows us to record your mouse and scroll movements and clicks, among other things. Google Analytics uses various modeling approaches to augment the collected data sets and uses machine learning technologies in data analysis.
Google Analytics uses technologies that make the recognition of the user for the purpose of analyzing the user behavior patterns (e.g., cookies or device fingerprinting). The website use information recorded by Google is, as a rule transferred to a Google server in the United States, where it is stored.
The use of these services occurs on the basis of your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revoke your consent at any time.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5780.
IP anonymization
Google Analytics IP anonymization is active. As a result, your IP address will be abbreviated by Google within the member states of the European Union or in other states that have ratified the Convention on the European Economic Area prior to its transmission to the United States. The full IP address will be transmitted to one of Google’s servers in the United States and abbreviated there only in exceptional cases. On behalf of the operator of this website, Google shall use this information to analyze your use of this website to generate reports on website activities and to render other services to the operator of this website that are related to the use of the website and the Internet. The IP address transmitted in conjunction with Google Analytics from your browser shall not be merged with other data in Google’s possession.
Browser plug-in
You can prevent the recording and processing of your data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
For more information about the handling of user data by Google Analytics, please consult Google’s Data Privacy Declaration at: https://support.google.com/analytics/answer/6004245?hl=en.
Google Signals
We use Google Signals. Whenever you visit our website, Google Analytics records, among other things, your location, the progression of your search and YouTube progression as well as demographic data (site visitor data). This data may be used for customized advertising with the assistance of Google Signal. If you have a Google account, your site visitor information will be linked to your Google account by Google Signal and used to send you customized promotional messages. The data is also used to compile anonymized statistics of our users’ online patterns.
Contract data processing
We have executed a contract data processing agreement with Google and are implementing the stringent provisions of the German data protection agencies to the fullest when using Google Analytics.
Google Analytics E-Commerce-Tracking
This website uses the “E-Commerce Tracking” function of Google Analytics. With the assistance of E-Commerce Tracking, the website operator is in a position to analyze the purchasing patterns of website visitors with the aim of improving the operator’s online marketing campaigns. In this context, information, such as the orders placed, the average order values, shipping costs and the time from viewing the product to making the purchasing decision are tracked. These data may be consolidated by Google under a transaction ID, which is allocated to the respective user or the user’s device.
Google AdSense
This website uses Google AdSense, a service for the integration of advertisements. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google AdSense enables us to display advertisements on our website and to finance free access to our content. Depending on your consent choices, Google may display personalized or non-personalized ads. Personalized ads may be selected based on information such as your previous visits to this or other websites, your interests, your approximate location, the content of the page, or other information available to Google. Non-personalized ads are not based on a user profile but may still use contextual information, such as the content of the page, and general information such as your approximate location.
Google AdSense may use cookies, web beacons, device identifiers, local storage, and comparable technologies to deliver ads, prevent fraud and abuse, measure performance, limit ad frequency, and, where consent has been given, personalize advertising. Information generated in this context, including IP address, browser and device information, pages visited, interactions with ads, and identifiers, may be transmitted to Google servers and processed by Google and its partners.
For users in the European Economic Area, the United Kingdom, and Switzerland, we use Google AdSense only in conjunction with the consent and privacy settings required for Google advertising services. If consent is required for personalized advertising, ad measurement, or the storage of or access to information on your device, processing takes place only on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may revoke your consent at any time with effect for the future. Processing that is strictly necessary for security, fraud prevention, billing, and technically necessary ad delivery may be based on Art. 6(1)(f) GDPR and Section 25(2) TDDDG, unless a more specific legal basis applies.
Data transfer to the United States may take place within the scope of Google’s certification under the EU-US Data Privacy Framework (DPF). Where the DPF does not apply, Google relies on Standard Contractual Clauses (SCC) of the European Commission and additional safeguards where required. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/, https://policies.google.com/privacy, and https://support.google.com/adsense/answer/13554116.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5780.
VG Wort counting pixel
We have implemented texts on our website, in which a so-called tracking pixel (METIS tracking pixel) is embedded. The provider is the Verwertungsgesellschaft WORT – VG WORT (association with legal capacity by virtue of conferral), Untere Weidenstraße 5, 81543 Munich (hereinafter “VG Wort”).
The pixel counts the views of texts, forwards them anonymously to the VG Wort, in order to determine the distributions for the authors. The use of the VG Wort pixel is based on our legitimate interest in receiving remuneration for the texts published on our website for our authors or for ourselves (Art. 6(1)(f) GDPR). Conflicting interests of website visitors are not apparent, as the data is transmitted to VG Wort in anonymized form.
7. Newsletter
Newsletter data
If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data is not collected or only on a voluntary basis. For the handling of the newsletter and related e-mail dispatch, we may use Brevo, MailPoet and/or our hosting provider All-Inkl as described below. Some providers may be used as backup or fallback sending options.
E-mail dispatch through All-Inkl and backup sending providers
In addition to the newsletter providers named below, we may send transactional, administrative and system-related e-mails through our hosting provider All-Inkl or through the e-mail infrastructure connected to our WordPress installation. This includes, for example, registration e-mails, password reset e-mails, membership and subscription notices, payment or renewal notices, comment notifications, contact-form replies, security notifications and other service-related communications.
For this purpose, the data required for dispatch and delivery may be processed, including your e-mail address, name or username where applicable, message content, subject line, metadata, timestamps, delivery status, error messages, IP addresses or server log data required for troubleshooting, and information necessary to allocate the message to your account, order, membership or request.
We may use Brevo, MailPoet and/or All-Inkl as primary or backup sending options, depending on the type of e-mail, technical availability and deliverability requirements. Newsletter e-mails are sent only on the basis of your consent unless another legal basis expressly applies. Transactional and account-related e-mails are processed on the basis of Art. 6(1)(b) GDPR where they are required for account, membership, payment or contract performance, Art. 6(1)(c) GDPR where we are legally obliged to send or retain the communication, and Art. 6(1)(f) GDPR for reliable, secure and traceable communication with users and customers.
Brevo
This website uses Brevo for the sending of newsletters. The provider is the Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
Brevo services can, among other things, be used to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter are archived on servers of Sendinblue GmbH in Germany.
Data analysis by Brevo
Brevo enables us to analyze our newsletter campaigns. For instance, it allows us to see whether a newsletter message has been opened and, if so, which links may have been clicked. This enables us to determine, which links drew an extraordinary number of clicks.
Moreover, we are also able to see whether once the e-mail was opened or a link was clicked, any previously defined actions were taken (conversion rate). This allows us to determine whether you have made a purchase after clicking on the newsletter.
Brevo also enables us to divide the subscribers to our newsletter into various categories (i.e., to “cluster” recipients). For instance, newsletter recipients can be categorized based on age, gender, or place of residence. This enables us to tailor our newsletter more effectively to the needs of the respective target groups.
If you do not want to permit an analysis by Brevo, you must unsubscribe from the newsletter. We provide a link for you to do this in every newsletter message. Moreover, you can also unsubscribe from the newsletter right on the website.
For detailed information on the functions of Brevo please follow this link: https://www.brevo.com/de/newsletter-software/.
Legal basis
The data is processed based on your consent (Art. 6(1)(a) GDPR). You may revoke any consent you have given at any time by unsubscribing from the newsletter. This shall be without prejudice to the lawfulness of any data processing transactions that have taken place prior to your revocation.
Storage period
The data deposited with us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter or the newsletter service provider and deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data stored for other purposes with us remain unaffected.
After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist, if such action is necessary to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). The storage in the blacklist is indefinite. You may object to the storage if your interests outweigh our legitimate interest.
For more details, please consult the Data Protection Regulations of Brevo at: https://www.brevo.com/de/datenschutz-uebersicht/ and https://www.brevo.com/de/legal/privacypolicy/.
Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
MailPoet
This website uses MailPoet to send newsletters. Aut O’Mattic A8C Ireland Ltd., Business Centre, No.1 Lower Mayor Street, International Financial Services Centre, Dublin 1, Ireland, whose parent company is based in the US (hereinafter MailPoet).
MailPoet is a service with which, in particular, the sending of newsletters can be organized and analyzed. The data you enter to subscribe to the newsletter is stored on our servers but sent through MailPoet’s servers so that MailPoet can process your newsletter-related data (MailPoet Sending Service). You can find details here: https://account.mailpoet.com/.
Data analysis by MailPoet
MailPoet helps us to analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened, and which links were clicked on, if any. In this way, we can determine, in particular, which links were clicked on particularly often.
We can also see if certain previously defined actions were performed after opening/clicking (conversion rate). For example, we can see whether you have made a purchase after clicking on the newsletter.
MailPoet also allows us to divide newsletter recipients into different categories (“clustering”). This allows us to classify newsletter recipients according to age, gender, or place of residence, for example. In this way, the newsletter can be better adapted to the respective target groups. If you do not wish to receive an evaluation by MailPoet, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message.
Detailed information about the functions of MailPoet can be found at the following link: https://account.mailpoet.com/ and https://www.mailpoet.com/mailpoet-features/.
You can find the MailPoet privacy policy at https://www.mailpoet.com/privacy-notice/.
Legal basis
The data processing is based on your consent (Art. 6(1)(a) GDPR). You can revoke this consent at any time with effect for the future.
Data transfer to the US is based on standard contractual clauses of the EU Commission. Details can be found here: https://automattic.com/de/privacy/.
Duration of storage
The data that you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list or deleted after the purpose has been fulfilled. We reserve the right to delete email addresses within the scope of our legitimate interest under Art. 6(1)(f) GDPR. Data stored by us for other purposes remain unaffected.
After you have been removed from the newsletter distribution list, it is possible that your email address will be saved by us in a blacklist, if such action is necessary to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in compliance with the legal requirements when sending newsletters (legitimate interest in the sense of Art. 6(1)(f) GDPR). The storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4709.
Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
8. Plug-ins and Tools
YouTube with expanded data protection integration
This website integrates videos from the YouTube website. The operator of the website is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of these websites on which YouTube is integrated, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube in extended data protection mode. According to YouTube, videos that are played in extended data protection mode are not used to personalize browsing on YouTube. Ads that are played in extended data protection mode are also not personalized. No cookies are set in extended data protection mode. Instead, so-called local storage elements are stored in the user’s browser, which contain personal data similar to cookies and can be used for recognition. Details on the extended data protection mode can be found here: https://support.google.com/youtube/answer/171780.
After activating a YouTube video, further data processing operations may be triggered over which we have no influence.
The use of YouTube is based on our interest in presenting our online content in an appealing manner. Pursuant to Art. 6(1)(f) GDPR, this is a legitimate interest. If appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, insofar the consent includes the storage of cookies or the access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TDDDG. This consent can be revoked at any time.
For more information on how YouTube handles user data, please consult the YouTube Data Privacy Policy under: https://policies.google.com/privacy?hl=en.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5780.
Vimeo Without Tracking (Do-Not-Track)
This website uses plugins of the Vimeo video portal. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.
Whenever you visit one of our pages featuring Vimeo videos, a connection with the servers of Vimeo is established. In conjunction with this, the Vimeo server receives information about which of our sites you have visited. Vimeo also receives your IP address. However, we have set up Vimeo in such a way that Vimeo cannot track your user activities and does not place any cookies.
We use Vimeo to make our online presentation attractive for you. This is a legitimate interest on our part pursuant to Art. 6(1)(f) GDPR. If a respective declaration of consent was requested (e.g. concerning the storage of cookies), processing shall occur exclusively on the basis of Art. 6(1)(a) GDPR; the given consent may be revoked at any time.
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission and, according to Vimeo, on “legitimate business interests”. Details can be found here: https://vimeo.com/privacy.
For more information on the handling of user data, please consult Vimeo’s data privacy policy at: https://vimeo.com/privacy
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5711.
Google Fonts (local embedding)
This website uses so-called Google Fonts provided by Google to ensure the uniform use of fonts on this site. These Google fonts are locally installed so that a connection to Google’s servers will not be established in conjunction with this application.
For more information on Google Fonts, please follow this link: https://developers.google.com/fonts/faq and consult Google’s Data Privacy Declaration under: https://policies.google.com/privacy?hl=en.
Font Awesome (local embedding)
This website uses Font Awesome to ensure the uniform use of fonts on this site. Font Awesome is locally installed so that a connection to Fonticons, Inc.’s servers will not be established in conjunction with this application.
For more information on Font Awesome, please and consult the Data Privacy Declaration for Font Awesome under: https://fontawesome.com/privacy.
OpenStreetMap
We use map material from OpenStreetMap (OSM) to display maps and location information on our website. OpenStreetMap is a project of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom.
If map tiles are loaded directly from OpenStreetMap Foundation servers, or from another OSM-based tile provider used by the map plugin, your browser establishes a connection to that provider’s servers. In this context, technical data such as your IP address, browser and device information, the requested map tile, the page on which the map is embedded, referrer information and the time of the request may be transmitted to the respective provider. This is technically necessary to display the map in your browser.
We use OpenStreetMap to present location information in an understandable way and to make locations mentioned on our website easier to find. The legal basis is Art. 6(1)(f) GDPR. We have a legitimate interest in an accessible and user-friendly presentation of location information. If consent is requested for map loading, for example because the map plugin stores or accesses information on your device or because the map is initially blocked until activation, processing takes place on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG; consent may be revoked at any time.
Further information can be found in the OpenStreetMap Foundation privacy policy and tile usage policy: https://osmfoundation.org/wiki/Privacy_Policy and https://operations.osmfoundation.org/policies/tiles/.
Cloudflare Turnstile
We use “Cloudflare Turnstile” on this website. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Turnstile”).
Turnstile is used to check whether data input on this website, for example in contact forms, login forms, registration forms, comment forms, or other interactive functions, is made by a human user and not by an automated program or abusive bot.
For this purpose, Turnstile processes technical and security-related information such as your IP address, browser and device information, the page on which Turnstile is used, timestamps, interaction and challenge data, and a verification token. Depending on the technical configuration, Cloudflare may also use cookies or comparable technologies, for example security or clearance cookies. The token is verified server-side in order to decide whether the requested action can be accepted.
Turnstile is used for bot protection, spam prevention, fraud prevention, account security, and the protection of our forms and services. According to Cloudflare, Turnstile is not used for advertising retargeting by us. We do not use the Turnstile data to create advertising profiles.
The legal basis for the use of Turnstile is Art. 6(1)(f) GDPR. We have a legitimate interest in protecting our website from spam, abusive automated access, credential stuffing, fake registrations, attacks, and other misuse. Where Turnstile stores information on your device or accesses information already stored on your device and this is strictly necessary for the security function expressly requested in connection with the form or action, the legal basis under German law is Section 25(2) TDDDG. If consent is requested for non-essential storage or access, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG; consent may be revoked at any time.
Data transfer to the United States may take place within the scope of Cloudflare’s certification under the EU-US Data Privacy Framework (DPF). Where the DPF does not apply, data transfers are based on the Standard Contractual Clauses (SCC) of the European Commission and additional safeguards where required. Details can be found here: https://www.cloudflare.com/turnstile-privacy-policy/, https://www.cloudflare.com/cloudflare-customer-scc/, and https://www.cloudflare.com/cloudflare-customer-dpa/.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5666.
Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that Cloudflare processes personal data of our website visitors only based on our instructions and in compliance with the GDPR, unless Cloudflare acts as an independent controller for specific security or abuse-prevention processing under its own terms.
Akismet
We have implemented Akismet on this website. The provider is Aut O’Mattic A8C Ireland Ltd, Business Centre, No.1 Lower Mayor Street, International Financial Services Centre, Dublin 1, Ireland (hereinafter Aut O’Mattic), whose parent company is based in the US.
Akismet enables us to analyze posted comments for being SPAM. For this purpose, we process the provided visitor name, mail address, IP address, comment text, browser type and access time.
The website operator has a legitimate interest in undisturbed, spam-free communication with website visitors. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 (1)(a) GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information in the user’s terminal device (e.g., for device fingerprinting) as defined by the TDDDG. Such consent may be revoked at any time.
Further details can be found here: https://akismet.com/gdpr/.
Data transfer to the US is based on the standard contractual clauses of the EU Commission. Details can be found here: https://wordpress.com/support/data-processing-agreements/.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4709.
Data processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
Spotify
We have integrated features of the Spotify music platform into this website. The provider is Spotify AB, Birger Jarlsgatan 61, 113 56 Stockholm, Sweden. You will be able to recognize Spotify plug-ins when you see the green logo on this website. An overview of Spotify’s plug-ins can be found at: https://developer.spotify.com.
The plug-in makes it possible to establish a direct connection between your browser and Spotify’s server when you visit this website. As a result, Spotify receives the information that you visited this website with your IP address. If you click the Spotify button while you are logged into your Spotify account, you have the option to link content from this website with your Spotify profile. Consequently, Spotify will be in a position to allocate your visit to this website to your user account.
We would like to point out that when using Spotify, cookies are used by Google Analytics so that your usage data can also be passed on to Google when using Spotify. Google Analytics is a tool of the Google Group for the analysis of user behavior with headquarters in the USA. Spotify alone is responsible for this integration. We as website operators have no influence on this processing.
Data are stored and analyzed on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the attractive acoustic presentation of the website. If appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, insofar the consent includes the storage of cookies or the access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TDDDG. This consent can be revoked at any time.
For more information, please consult Spotify’s Data Protection Declaration under: https://www.spotify.com/us/legal/privacy-policy/.
If you do not want Spotify to be able to allocate the visit of this website to your Spotify user account, please log out of your Spotify user account while visiting our sites.
9. Online marketing and partner programs
Affiliate Programs on this website
We participate in affiliate partner programs. Affiliate links enable us to finance parts of our editorial offer. If you click on an affiliate link and subsequently make a purchase or carry out another qualifying action, we may receive a commission. The price for you does not change because of this.
Depending on the affiliate program and the technical implementation, affiliate tracking may be carried out by means of ordinary link parameters, cookies, server-side tracking, or comparable recognition technologies. These technologies may be used to attribute a transaction to us, to calculate commissions, to prevent fraud, and to generate reporting for the parties involved.
Where affiliate tracking requires the storage of or access to information on your device, this takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may revoke your consent at any time with effect for the future. Where only ordinary affiliate links without third-party scripts, pixels, or cookies on our website are used, processing may be based on our legitimate interest in monetizing our editorial content and correctly attributing commissions (Art. 6(1)(f) GDPR).
We participate in the following affiliate programs:
Amazon partner program
We participate in the Amazon partner program. The provider is Amazon Europe Core S.à.r.l. If you click on an Amazon affiliate link, Amazon may process information about your visit, the clicked link, and any subsequent purchase in order to attribute commissions and to operate the Amazon partner program. For details, please consult Amazon’s privacy notice and cookie information: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010.
Amazon.com Services LLC is certified in accordance with the “EU-US Data Privacy Framework” (DPF) for relevant transfers where applicable. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5776.
AWIN
We participate in the AWIN affiliate program. The AWIN affiliate network is operated by AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany (referred to below as “AWIN”). AWIN, the advertiser, and we may act as joint controllers for the processing of personal data in connection with the AWIN partner program, in particular where tracking and attribution are used to identify a commissionable transaction. The obligations that fall to the parties have been set out in AWIN’s data protection terms and joint processing arrangements. You may direct data protection enquiries to us or to AWIN. AWIN’s privacy policy is available here: https://www.awin.com/gb/privacy.
Lingualism Affiliate Program (BixGrow)
We participate in the affiliate program of Lingualism, which may use the BixGrow affiliate platform. If you click on an affiliate link to Lingualism, a cookie, link parameter, or similar tracking technology may be used to attribute the sale to us. This allows us to receive a commission.
For more information, please visit the privacy policy of the platform BixGrow: https://bixgrow.com/privacy-policy.
Affiliate Links
We may use plain affiliate links for selected partners such as N26, All-Inkl, and Wise. If only plain links are used, no third-party scripts or tracking pixels from these providers are placed on our website. The respective provider may process data once you click the link and leave our website.
10. eCommerce and payment service providers
Processing of Customer and Contract Data
We collect, process, and use personal customer and contract data for the establishment, content arrangement and modification of our contractual relationships. Data with personal references to the use of this website (usage data) will be collected, processed, and used only if this is necessary to enable the user to use our services or required for billing purposes. The legal basis for these processes is Art. 6(1)(b) GDPR.
The collected customer data shall be deleted upon completion of the order or termination of the business relationship and upon expiration of any existing statutory archiving periods. This shall be without prejudice to any statutory archiving periods.
Data transfer upon closing of contracts for online stores, retailers, and the shipment of merchandise
Whenever you order merchandise from us, we will share your personal data with the transportation company entrusted with the delivery as well as the payment service commissioned to handle the payment transactions. Only the data these respective service providers require to meet their obligations will be shared. The legal basis for this sharing is Art. 6 (1)(b) GDPR, which permits the processing of data for the fulfillment of contractual or pre-contractual obligations. If you give us your respective consent pursuant to Art. 6 (1)(a) GDPR, we will share your email address with the transportation company entrusted with the delivery so that this company can notify you on the shipping status for your order via email. You have the option to revoke your consent at any time.
Data transfer upon closing of contracts for services and digital content
We share personal data with third parties only if this is necessary in conjunction with the handling of the contract; for instance, with the financial institution tasked with the processing of payments.
Any further transfer of data shall not occur or shall only occur if you have expressly consented to the transfer. Any sharing of your data with third parties in the absence of your express consent, for instance for advertising purposes, shall not occur.
The basis for the processing of data is Art. 6(1)(b) GDPR, which permits the processing of data for the fulfilment of a contract or for pre-contractual actions.
Order processing via dropshipping
If you order goods from us, your order may be shipped to you directly from our dealers (dropshipping). For this purpose, we pass on your name, the delivery address and – as far as this is necessary for delivery – your telephone number to the shipping company. This information is passed on exclusively for the purpose of delivering the goods.
The legal basis for data processing is Art. 6(1)(b) GDPR (fulfilment of contract) and our legitimate interest in the fastest and most effective possible purchase processing in accordance with Art. 6(1)(f) GDPR.
We use the following dealer in the context of dropshipping:
Printful, Inc.
11025 Westlake Dr, Charlotte, NC 28273, USA
Email: [email protected]
TAX ID: 90-0674740
Printify, Inc.
108 West 13th Street,
Wilmington, Delaware 19801
Email: [email protected]
Payment services
We integrate payment services of third-party companies on our website. When you make a purchase from us, take out a paid membership, renew a subscription, or change a payment method, payment-related data may be processed by the respective payment service provider. This may include your name, billing address, e-mail address, payment amount, selected payment method, bank account or card information, transaction identifiers, subscription identifiers, mandate or authentication data, fraud-prevention data, and other information required for payment processing, refunds, chargebacks, accounting, and compliance.
For these transactions, the contractual and data protection provisions of the respective provider apply. The use of payment service providers is based on Art. 6(1)(b) GDPR (contract processing) and on our legitimate interest in smooth, secure, and reliable payment processing (Art. 6(1)(f) GDPR). Insofar as your consent is requested for certain actions, Art. 6(1)(a) GDPR is the legal basis for data processing; consent may be revoked at any time with effect for the future. We also process payment and invoice data where this is necessary to comply with statutory retention, accounting, and tax obligations (Art. 6(1)(c) GDPR).
We use the following payment services / payment service providers within the scope of this website, depending on the payment methods actually displayed at checkout:
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). If you choose PayPal, the payment data you enter or that is generated during checkout will be transmitted to PayPal. PayPal may process personal data as an independent controller for payment processing, recurring payments, fraud prevention, risk management, compliance, and the operation of the PayPal account or payment service.
If you take out a paid membership or subscription and choose PayPal, PayPal may store and manage a billing agreement, subscription, mandate, or recurring payment profile. We receive from PayPal the data required to allocate the payment to your account and to manage your membership, such as the payment status, transaction ID, subscription ID, payer information, billing cycle, payment amount, refund status, failed payment status, or cancellation status.
Data transfers within the PayPal group and to third countries may be based on Binding Corporate Rules, Standard Contractual Clauses, adequacy decisions, or other mechanisms under Chapter V GDPR. Details can be found in PayPal’s privacy statement and transfer information: https://www.paypal.com/de/legalhub/paypal/privacy-full and https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
Apple Pay
The payment service provider is Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (hereinafter “Apple Pay”). If you choose Apple Pay, the payment transaction is processed through Apple Pay, the payment card issuer, the relevant card network, and, where applicable, our payment gateway. Apple may process device information, tokenized payment information, transaction data, and other data required for the authorization and processing of the payment. We do not receive your full payment card number from Apple Pay.
Further information can be found in Apple’s privacy policy: https://www.apple.com/legal/privacy/de-ww/.
Google Pay
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google Pay”). If you choose Google Pay, the payment transaction is processed through Google Pay, the payment card issuer, the relevant card network, and, where applicable, our payment gateway. Google may process payment method information, tokenized payment data, transaction data, device data, and other data required for authentication and payment processing. We do not receive your full payment card number from Google Pay.
You can find Google’s privacy policy here: https://policies.google.com/privacy.
Stripe
The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter “Stripe”). Stripe may process payment data, billing data, transaction data, device data, fraud-prevention data, and other information required to process payments and comply with legal obligations. Depending on the checkout configuration, Stripe may enable card payments and other payment methods such as Apple Pay, Google Pay, Klarna, Wero, or other local payment methods.
If you take out a paid membership or subscription and choose a Stripe-based payment method, Stripe may store and manage payment method references, customer IDs, subscription IDs, mandate data, recurring payment status, renewal dates, failed payment information, and other data required for recurring billing. We receive from Stripe the data required to allocate the payment to your user account, manage your membership, send billing-related notices, process refunds or chargebacks, and comply with tax and accounting duties. We do not deliberately store full credit card numbers or CVC/CVV codes on our website; such data is processed by Stripe or the relevant payment interface. We may store the last four digits of a card, the card brand, expiry date, payment method reference, and transaction/subscription identifiers if these are returned to us by Stripe for customer support, billing, and renewal notices.
Data transfer to the United States may take place within the scope of Stripe’s certification under the EU-US Data Privacy Framework (DPF). Where the DPF does not apply, Stripe relies on Standard Contractual Clauses and additional safeguards where required. Details can be found in Stripe’s privacy policy, privacy center, and Data Privacy Framework policy: https://stripe.com/privacy, https://stripe.com/legal/privacy-center, and https://stripe.com/legal/data-privacy-framework.
Wero
We may offer Wero as a payment method, in particular for customers in Germany and other supported European countries. Wero is a European payment solution operated by EPI Company SE, de Lignestraat 13, 1000 Brussels, Belgium (hereinafter “EPI” or “Wero”). Depending on the technical integration, Wero payments may be processed through the Wero app, your banking app, your account-servicing payment service provider, and/or a payment gateway such as Stripe.
If you choose Wero, the data required to initiate, authenticate, execute, confirm, reconcile, refund, or dispute the transaction may be processed. This may include identification and contact data, payment amount, transaction reference, payment status, consent and authentication data, technical identifiers, payment account or wallet data, device data, fraud-prevention data, refund data, and reconciliation/reporting data. The processing serves payment execution, strong customer authentication, fraud prevention, security, dispute handling, refunds, accounting, and compliance with payment-services law. The legal basis is Art. 6(1)(b) GDPR for payment execution, Art. 6(1)(c) GDPR where processing is required by legal obligations, and Art. 6(1)(f) GDPR for fraud prevention, security, operational support, and the defence of legal claims.
Further information can be found in Wero’s privacy information and, where Wero is used through Stripe, Stripe’s Wero terms: https://wero-wallet.eu/privacy-center and https://stripe.com/en-de/legal/wero.
Klarna
The supplier is Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter “Klarna”). Klarna offers various payment options, for example purchase on account, installment payment, direct debit, instant bank transfer, or other Klarna payment methods, depending on availability and checkout configuration. If you choose Klarna, Klarna may collect and process personal data such as contact details, billing and delivery address, date of birth, payment information, order details, transaction data, device data, creditworthiness and fraud-prevention information, and communication data.
Klarna may use cookies and similar technologies for the provision and optimization of its checkout and payment services. Details can be found in Klarna’s privacy policy and cookie information: https://www.klarna.com/de/datenschutz/ and https://www.klarna.com/de/cookie-hinweis/.
Paydirekt
If Paydirekt is still technically offered at checkout, or if legacy Paydirekt transactions must be processed or documented, the provider of this payment service is Paydirekt GmbH, Stephanstraße 14-16, 60313 Frankfurt am Main, Germany (hereinafter “Paydirekt”). If you make a payment via Paydirekt, Paydirekt may collect transaction data and forward it to the bank with which you are registered. In addition to the data required for payment, Paydirekt may also collect further data such as the delivery address or individual items in the shopping basket where this is necessary for transaction processing. Paydirekt authenticates the transaction using the authentication procedure stored with your bank. Neither we nor third parties receive access to your account login data.
Please note that Paydirekt/giropay payment services have been discontinued or replaced in many payment integrations. If this payment method is not displayed at checkout, this section does not apply to current transactions. Where legacy data must be retained, the legal basis is Art. 6(1)(c) GDPR for statutory retention duties and Art. 6(1)(f) GDPR for documentation and defence of legal claims.
Instant transfer / Sofort
The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich, Germany. Sofort is part of the Klarna group. With the help of the “Sofortüberweisung” procedure, we receive a payment confirmation and can immediately begin to fulfill our obligations. If you choose Sofort, payment data and personal data required for payment processing and fraud prevention may be transmitted to Sofort/Klarna. Depending on the procedure, this may include name, billing details, bank details, payment amount, transaction reference, IP address, technical data, and authentication-related information.
For details on payment with Sofort, please refer to the following link: https://www.klarna.com/sofort/.
giropay
If giropay is still technically offered at checkout, or if legacy giropay transactions must be processed or documented, the provider of this payment service was Paydirekt GmbH, Stephanstraße 14-16, 60313 Frankfurt am Main, Germany. giropay was a German online banking-based payment method. If payment via giropay was selected, transaction data was processed and forwarded to the relevant participating bank for authentication and payment execution. Neither we nor third parties received access to your online banking credentials.
Please note that giropay has been deprecated as a payment method in many integrations and is no longer available through certain providers. If this payment method is not displayed at checkout, this section does not apply to current transactions. Where legacy data must be retained, the legal basis is Art. 6(1)(c) GDPR for statutory retention duties and Art. 6(1)(f) GDPR for documentation and defence of legal claims.
American Express
The provider of this payment service is American Express Europe S.A., German Branch, Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter “American Express”). If you choose American Express, payment and transaction data may be transmitted to American Express, the payment gateway, and other entities involved in the card payment process. American Express may process data for payment authorization, fraud prevention, risk management, compliance, refunds, chargebacks, customer service, and accounting.
American Express may transfer data to its parent company or group companies outside the EU/EEA. Data transfers may be based on Binding Corporate Rules, Standard Contractual Clauses, adequacy decisions, or other mechanisms under Chapter V GDPR. For more information, please see the American Express privacy information: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter “Mastercard”). If you choose Mastercard, payment and transaction data may be transmitted to Mastercard, the card-issuing bank, the acquiring bank, the payment gateway, and other entities involved in the card payment process. Mastercard may process data for payment authorization, fraud prevention, risk management, compliance, refunds, chargebacks, customer service, and accounting.
Mastercard may transfer data to its parent company or group companies outside the EU/EEA. The data transfer may be based on Mastercard’s Binding Corporate Rules, Standard Contractual Clauses, adequacy decisions, or other mechanisms under Chapter V GDPR. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
VISA
The provider of this payment service for the European region is Visa Europe Services LLC, London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “Visa”). If you choose Visa, payment and transaction data may be transmitted to Visa, the card-issuing bank, the acquiring bank, the payment gateway, and other entities involved in the card payment process. Visa may process data for payment authorization, fraud prevention, risk management, compliance, refunds, chargebacks, customer service, and accounting.
The United Kingdom currently benefits from an EU adequacy decision for data protection purposes. Visa may transfer data to group companies outside the United Kingdom or the EU/EEA. Such transfers may be based on Standard Contractual Clauses, adequacy decisions, or other mechanisms under Chapter V GDPR. For more information, please refer to Visa’s privacy information: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html and https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
Memberships, subscriptions and recurring payments
We use the WordPress plugin Paid Memberships Pro to manage paid memberships, access rights, checkout, membership levels, orders, renewals, cancellations, and related account functions for Arabic for Nerds+. The provider of the plugin is Stranger Studios, LLC, but the membership data is processed primarily within our own WordPress installation unless a connected payment gateway, e-mail service, hosting provider, or other service described in this Privacy Policy is involved.
For membership and subscription management, we may process the following data: user account data, name, e-mail address, username, billing address, phone number where provided, selected membership level, membership start and end dates, renewal dates, cancellation dates, payment status, order and invoice data, tax/VAT data, discount codes, access status, login and usage data required for access control, and technical data required for security and troubleshooting. If recurring payments are used, PayPal and/or Stripe may create, store and manage the recurring payment, billing agreement, mandate, subscription or customer relationship on their systems and may transmit to us recurring-payment identifiers, subscription IDs, mandate or billing agreement data, payment method references, last four digits and expiry date of a card where applicable, renewal status, failed payment notices, refund and chargeback information, cancellation confirmations and webhook or IPN status updates.
This processing is necessary to provide the paid membership, manage access to paid content, process renewals and cancellations, send billing-related notices, prevent misuse, comply with accounting and tax duties, and document legal claims. The legal basis is Art. 6(1)(b) GDPR for membership and payment performance, Art. 6(1)(c) GDPR for statutory retention, tax, and accounting obligations, and Art. 6(1)(f) GDPR for fraud prevention, IT security, customer support, and documentation of legal claims.
Data Collected to Manage Your Membership/Subscription
At checkout, we collect the information required to set up and manage your membership/subscription, in particular your name, email address, username, password, selected membership level, billing details, order data, and payment status. This information is used to create your account, provide access to Arabic for Nerds+, manage renewals and cancellations, send billing-related notices, and document the contractual relationship.
If you are redirected to an offsite payment gateway such as PayPal or Stripe to complete your payment, or if embedded payment fields from a gateway are used, the payment gateway processes the payment information required for the transaction. We may temporarily store checkout information in a session variable so that your account and membership can be set up correctly when you return to our site.
Depending on the payment method, we may receive and store payment references such as transaction IDs, customer IDs, subscription IDs, payment status, renewal dates, cancellation status, refund or chargeback status, the last four digits of a card, the card brand, and the card expiration date. We use this information for membership management, customer support, invoices, statutory accounting and tax retention, and renewal or expiry notices. We do not deliberately store full credit card numbers or CVC/CVV security codes on our website.
When logged in, we use cookies and technical session data to manage your login status, access rights, visits, page views, security checks, and other account-related functions necessary for the membership service.