Controller
Legal contact details
The legal contact details are listed in the imprint. Use the structured contact page for privacy requests and corrections. Requests use the contact route; authority follows the controller's registered seat.
Legal basis
GDPR, BDSG and TDDDG context
The privacy policy describes the current processing operations, purposes, legal bases, recipients, retention periods, data-subject rights and contact channels. This includes server logs, Umami, local settings, export features, Google AdSense, Awin partner links, technical service monitoring and terminal-equipment access relevant under TDDDG.
Access logs
Technical access data
When pages are requested, technical data such as request path, time, status code, latency, browser information, website domain and IP-related connection data may be processed to deliver, secure and troubleshoot the service. Terminal access also requires the TDDDG assessment stated below.
Monitoring
Metrics, logs and health checks
The service can use internal monitoring and logging systems. These systems process operational metrics, structured application logs and availability probe results for reliability and incident response, not advertising profiling. Terminal access also requires the TDDDG assessment stated below.
Server analytics
Minimal Umami page counts
If server-side Umami is enabled, page requests can be counted without a browser tracker. In the baseline configuration the tracked URL excludes the query string and the dispatch omits user agent, language and referrer. Do Not Track is respected. Terminal access also requires the TDDDG assessment stated below.
Browser analytics
Consent-gated Umami events
The browser tracker loads only after the CMP/TCF signal or the first-party analytics prompt grants consent for the configured publisher purposes 1, 8, 9 and 10. The analytics setup is self-hosted and does not send data to a public analytics cloud. It can measure page events, performance metrics, downloads, contact links, outbound links and session context such as site, locale, brand and theme. The German deployment separates TDDDG terminal access from required service functions.
Heatmaps
Optional Umami heatmaps
Heatmaps are loaded only when they are enabled for the site and the CMP grants the stricter heatmap purposes. They help identify which page areas are useful, but the recorder is excluded from contact, imprint and privacy pages. Session replays remain disabled unless a separate explicit opt-in is introduced. The German deployment separates TDDDG terminal access from required service functions.
Advertising
Google AdSense
Configured ad slots use Google AdSense. Google and selected ad technology providers may process data for contextual or personalized ads, frequency capping, aggregated reporting and fraud prevention. For the EEA, UK and Switzerland this requires Google's privacy message or another Google-certified CMP with IAB TCF support. For German visitors, optional advertising follows the consent state and GDPR or TDDDG context.
Affiliate links
Awin and sponsored partners
Sponsored partner cards can link to Awin or advertiser landing pages. No account is required here, but after a click the destination partner may use affiliate tracking, cookies or similar identifiers under its own privacy terms. Sponsored links are marked for search engines. For German visitors, optional advertising follows the consent state and GDPR or TDDDG context.
Browser storage
Local settings and QR attribution
Some tools store preferences such as theme, navigation mode, selected region (federal state) or compact PDF QR attribution in local or session storage. This keeps tools usable without creating an account.
Exports
Downloads, calendar feeds and sharing
CSV, PDF, ICS and sharing features use the selected page state. PDF files can include metadata and a compact QR target. External share targets and calendar applications receive data only when the user actively opens or imports them. Stored scope means a German federal state and stays local unless the user exports it.
Recipients
Processors and third parties
Data can be processed by hosting and database providers, static delivery infrastructure, technical service monitoring, Umami, Google AdSense and its ad technology providers, Awin or advertisers after a sponsored-link click, and communication providers for direct contact requests. Terminal access also requires the TDDDG assessment stated below.
Retention
Storage periods
Operational data is kept only as long as needed for delivery, security, debugging, measurement or legal obligations. Technical logs and metrics use short operational retention periods; Google, Awin and Umami apply their own retention settings. Terminal access also requires the TDDDG assessment stated below.
Rights
Data-subject rights
Data subjects can in particular request access, rectification, erasure, restriction, objection and portability where the GDPR requirements are met.