Privacy Policy

    General Information

    In this privacy policy, we (onmint GmbH, "we") inform you about the processing of personal data in connection with your use of our website and the other offerings described below.

    Personal data is information relating to an identified or identifiable natural person. This includes, in particular, details that allow conclusions to be drawn about your identity, such as your name, telephone number, address or email address. Certain identifiers, such as your IP address or the device ID of the device you use, are also considered personal data.

    1. Contact

    The point of contact and so-called controller for the processing of your personal data when visiting this website within the meaning of the EU General Data Protection Regulation (GDPR) is Onmint GmbH,

    Am Hamburger Bahnhof 4
    10557 Berlin
    privacy@onmint.io
    www.onmint.io

    For any questions about data protection in connection with our products and services or the use of our website, you can also contact our data protection officer at any time. They can be reached at the postal address above and at the email address given previously (keyword: "Attn: Data Protection Officer"). We expressly point out that when using this email address, the content is not exclusively reviewed by our data protection officer. If you wish to exchange confidential information, please first request direct contact via this email address.

    2. Data Processing on Our Website

    2.1 Accessing Our Website / Connection Data

    Every time you use our website, we collect connection data that your browser automatically transmits to enable you to visit the website. This connection data comprises the so-called HTTP header information, including the user agent, and includes in particular:

    • IP address of the requesting device;
    • method (e.g. GET, POST), date and time of the request;
    • address of the accessed website and path of the requested file;
    • if applicable, the previously accessed or referring website/file (HTTP referrer);
    • information on the browser and operating system used;
    • version of the HTTP protocol, HTTP status code, size of the delivered file;
    • request information such as language, content type, content encoding, character sets.

    We also set the cookie "pll_language" to store the website's set language for one year.

    Processing this connection data is strictly necessary to enable the visit to the website, to ensure the permanent functionality and security of our systems, and for the general administrative maintenance of our website. For the purposes described above, the connection data is also stored temporarily and in a manner limited to what is necessary in internal log files, for example, in order to find and take action against the causes of repeated or malicious access that jeopardises the stability and security of our website.

    The legal basis is Art. 6(1)(b) GDPR, insofar as the page visit occurs in the course of initiating or performing a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in enabling access to the website as well as the permanent functionality and security of our systems. In this case, access to and storage of information on the end device is strictly necessary and is based on the laws implementing the EU ePrivacy Directive in the EU member states, in Germany pursuant to Section 25(2) No. 2 TDDDG.

    For data protection reasons, log files are not permanently stored or analysed by us.

    2.2 Cloudflare

    We use the "Cloudflare" service. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter "Cloudflare").

    Cloudflare offers a globally distributed content delivery network (CDN) with DNS. In doing so, the transfer of information between your browser and our website is technically routed through Cloudflare's network. This enables Cloudflare to analyse the traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the internet. Cloudflare blocks threats and limits abusive bots and crawlers that would slow down access to the website or attack our systems. For these purposes, Cloudflare may also use cookies or other technologies, such as:

    • "__cf_bm" (30 minutes): security cookie, detection of bots and defence against cyberattacks;
    • "_cfuvid" (session): detection and management of incoming connections to implement Cloudflare's policies for reducing traffic and preventing abuse.

    The use of Cloudflare is based on our legitimate interest in providing our website offering in as error-free and secure a manner as possible (Art. 6(1)(f) GDPR). In this case, access to and storage of information on the end device is strictly necessary and is based on the laws implementing the EU ePrivacy Directive in the EU member states, in Germany pursuant to Section 25(2) TDDDG. We have entered into a data processing agreement with Cloudflare. The transfer of personal data to the USA takes place on the basis of the adequacy decision for the USA, due to Cloudflare's certification under the EU-US Data Privacy Framework.

    Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/en-gb/privacypolicy/.

    2.3 Contacting Us

    You have various options for contacting us. These include, in particular, the contact form, a phone call or an email using the contact details given above. In this context, we process data solely for the purpose of communicating with you.

    The legal basis is Art. 6(1)(b) GDPR, insofar as your details are required to respond to your enquiry or to initiate or perform a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in enabling you to contact us and in being able to respond to your enquiry.

    Data collected by us when you contact us is automatically deleted once your enquiry has been fully processed, unless we still require your enquiry to fulfil contractual or statutory obligations (see the "Retention Period" section).

    2.4 Newsletter

    Through our newsletter, we regularly inform you about current developments in digital provenance, data integrity and controlled data use, as well as about our products and services. To sign up for the newsletter, we collect your email address and, in the case of events, additionally your name and, if applicable, your company name.

    We use the so-called double opt-in procedure to sign up for our newsletter, meaning that we will only send you the newsletter by email once you have confirmed, by clicking on a link in our notification email, that you are the holder of the email address provided. Once you confirm your email address, we store your email address, the time of registration and the IP address used for registration for the duration of the subscription, and archive it afterwards for a limited period following unsubscription or revocation. This storage serves solely the purpose of being able to send you the newsletter and to prove your registration. You can unsubscribe from the newsletter at any time. An unsubscribe link is included in every newsletter. A message to the contact details given above or in the newsletter (e.g. by email or letter) is of course also sufficient for this purpose.

    In our newsletters, we use so-called pixels (tiny, invisible image files), which allow us to measure the open rate, as well as links that allow us to measure clicks on the link before redirecting to the target page. This data processing is carried out exclusively on an aggregated basis for statistical evaluation and for the optimisation and further development of our content and customer communication. No usage analysis is carried out at the level of individual newsletter recipients. We also record whether newsletters could be delivered and for which email addresses delivery was not possible. No linking with other data takes place. You can prevent the measurement of the open rate by disabling the loading of images in your email client.

    As soon as you unsubscribe from the newsletter, your registration data is deleted. Deletion also takes place promptly if you have not confirmed your newsletter registration.

    We use Brevo, a service of Sendinblue GmbH, Data Protection Officer, Köpenicker Straße 126, 10179 Berlin, Germany ("Brevo"), to send our newsletter. We use Brevo for email marketing in the event of a newsletter sign-up on our website, as well as for transactional emails, for example when a whitepaper is downloaded. We have entered into a data processing agreement with Brevo. Your data is stored by Brevo in Germany or the European Union and transmitted in encrypted form. To the extent that Brevo works with sub-processors whose parent company is not based in the European Union, the adequacy decision for the USA applies in the case of US companies certified under the EU-US Data Privacy Framework, and/or Brevo and its sub-processors have entered into standard contractual clauses and taken additional measures to protect the data. In connection with the use of Brevo, anonymised data on the use of the newsletter (e.g. clicks, opens) is used for aggregated statistical evaluation.

    The legal basis for sending the newsletter, the aggregated usage analysis and determining deliverability is your consent pursuant to Art. 6(1)(a) GDPR.

    2.5 Job Applications

    You can apply to us for open positions by email or via our careers portal. The purpose of collecting data is to select applicants for the possible establishment of an employment relationship. To process your application, we collect the data you provide (usually: first and last name; email address; application documents such as references and CV; date of earliest possible start date; the channel through which you became aware of the job posting; and, if applicable, telephone number, salary expectations, and Xing or LinkedIn profile). Please note that confidentiality cannot be guaranteed when applications are sent unencrypted by email. As a rule, you can also apply for our positions by post.

    The legal basis for processing your application documents is Art. 6(1)(b) and Art. 88(1) GDPR in conjunction with Section 26(1) sentence 1 of the German Federal Data Protection Act (BDSG).

    We store your personal data upon receipt of your application. If we accept your application and an employment relationship results, we store your application data for as long as it is required for the employment relationship and insofar as statutory provisions establish a retention obligation.

    If we reject your application, we store your application data for a maximum of three months after rejecting your application, unless you give us your consent to longer storage. If you have separately given us your consent, we will store the data you submitted as part of your application in our pool of applicants for a further twelve months after the end of the application process, in order to identify any other potentially interesting positions for you and to contact you again if applicable. The data will be deleted once this period has expired. You may revoke this consent at any time for the future by sending us an email to privacy@onmint.io.

    2.6 Use of Cookies and Comparable Technologies for Analysis and Marketing Purposes

    In order to improve the presentation of the content on our website, we use cookies and comparable technologies (e.g. local storage, fingerprints, pixels, web beacons) for the statistical collection and analysis of general usage behaviour based on access data. In addition, we use services from external providers that process the access data arising from the use of our website in order to enable interest-based advertising to be served, for example in connection with search queries.

    We only use optional cookies and comparable technologies for marketing and analysis purposes if you have given your consent to the data processing pursuant to Art. 6(1)(a) GDPR. Access to and storage of information on the end device takes place on the basis of the laws implementing the EU ePrivacy Directive in the EU member states, in Germany pursuant to Section 25(1) TDDDG.

    2.6.1 Borlabs

    We use the WordPress plugin "Borlabs Cookie" to obtain and manage your consent. This generates a banner that informs you about the data processing on our website and gives you the option of agreeing to all, some, or none of the data processing carried out by optional tools.

    This banner appears on your first visit to our website and whenever you access your settings again in order to change them or revoke consents. The banner also appears on subsequent visits to our website if you have disabled the storage of cookies or if the cookies or information in the local storage of "Borlabs Cookie" have been deleted or have expired.

    The WordPress plugin "Borlabs Cookie" also sets a necessary cookie ("borlabs-cookie") to store the consents and revocations you have given. If you delete your cookies, we will ask you for your consent again the next time you visit the site.

    The data processing by the WordPress plugin "Borlabs Cookie" is necessary in order to provide you with the legally required consent management and to comply with our documentation obligations. The legal basis is Art. 6(1)(f) GDPR, based on our interest in meeting the legal requirements for consent management. In these cases, access to and storage of information on the end device is strictly necessary and is based on the laws implementing the EU ePrivacy Directive in the EU member states, in Germany pursuant to Section 25(2) TDDDG.

    Withdrawing your consent or changing your selection
    You can withdraw your consent for certain tools at any time. To do so, click on the following link: Cookie settings. There you can also change your selection of tools you wish to consent to, as well as find additional information on the cookies and their respective retention periods. Alternatively, you can exercise your withdrawal directly with the provider for certain tools.

    2.6.2 Google Tag Manager

    Our website uses Google Tag Manager, a service offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for persons in the European Economic Area and Switzerland, and by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google") for all other persons.

    The Tag Manager is used to manage the tools and external services we use on our website and allows the use of so-called tags. A tag is a code element embedded in the website's source code, for example, to control which page or service elements and tools are activated and loaded, and in what order. The tool triggers other tags, which may in turn collect data and which are explained further in this privacy policy. In some cases, the data is processed on a Google server in the USA.

    The data processing takes place on the basis of Art. 6(1)(f) GDPR in order to provide our website and integrate the services we use. In these cases, access to and storage of information on the end device is strictly necessary and is based on the laws implementing the EU ePrivacy Directive in the EU member states, in Germany pursuant to Section 25(2) TDDDG.

    We have entered into a data processing agreement with Google Ireland Limited for the use of Google Tag Manager. In the event that personal data is transferred from Google Ireland Limited to Google LLC in the USA, such transfer takes place on the basis of the adequacy decision for the USA, due to Google LLC's certification under the EU-US Data Privacy Framework.

    Further information about Google Tag Manager can be found in Google's Tag Manager information.

    2.6.3 Google Analytics

    Our website uses the web analytics service Google Analytics 4, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for persons in Europe, the Middle East and Africa (EMEA), and by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google") for all other persons. We integrate Google Analytics 4 via Google Tag Manager. If you have not consented to the use of the analysis tools, your data will not be collected as part of Google Analytics 4.

    Google Analytics 4 uses JavaScript and pixels to read information on your end device, as well as cookies to store information on your end device. This is used to analyse your usage behaviour and to improve our website. The access data is compiled by Google on our behalf into pseudonymous usage profiles and transferred to a Google server in the USA. We will process the information obtained in order to evaluate your use of the website and to compile reports on website activity.

    As part of the evaluation, Google Analytics 4 also uses artificial intelligence, such as machine learning, for the automated analysis and enrichment of data. For example, Google Analytics 4 models conversions if there is not enough data available to optimise the evaluation and reports. The data collected as part of the usage analysis by Google Analytics 4 is enriched with data from Google Search Console and linked with data from Google Ads, in particular in order to measure the success of our advertising campaigns (so-called conversions).

    Processed data:

    • IP address;
    • user ID and device ID;
    • referrer URL (previously visited page);
    • pages accessed (date, time, URL, title, dwell time);
    • downloaded files;
    • links clicked to other websites;
    • attainment of certain goals (conversions);
    • technical information (operating system; browser type, version and language; device type, brand, model and resolution);
    • approximate location (country, region and, if applicable, city, based on an anonymised IP address).

    Privacy settings:

    • anonymisation of the IP address;
    • advertising features disabled;
    • personalised advertising disabled;
    • retention period of 2 months (with no reset of the retention period upon new activity);
    • cross-device and cross-page tracking disabled (Google Signals);
    • data sharing disabled (in particular Google products and services, benchmarking, technical support, account specialist).

    Cookies used:

    • "ga" (2 years) and "gid" (24 hours): recognising and distinguishing visitors by means of a user ID;
    • "ga_XXX" (2 years): retaining information about the current session;
    • "FPID" (2 years): enabling server-side tracking as well as recognising and distinguishing visitors by means of a user ID;
    • "FPLC" (20 hours): cross-domain tracking with parameters in the URL as part of server-side tracking, using the hashed identifier of the FPID cookie.

    The legal basis for this data processing is your consent pursuant to Art. 6(1)(a) GDPR. Access to and storage of information on the end device then takes place on the basis of the laws implementing the EU ePrivacy Directive in the EU member states, in Germany pursuant to Section 25(1) TDDDG.

    We have entered into a data processing agreement with Google Ireland Limited for the use of Google Analytics 4. In the event that personal data is transferred from Google Ireland Limited to Google LLC in the USA, such transfer takes place on the basis of the adequacy decision for the USA, due to Google LLC's certification under the EU-US Data Privacy Framework.

    2.6.4 Google Ads Conversion Tracking

    Our website uses "Google Ads Conversion Tracking", offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for persons in Europe, the Middle East and Africa (EMEA), and by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google") for all other persons. We integrate Google Ads Conversion Tracking via Google Tag Manager. If you have not consented to the use of the marketing tools, your data will not be collected as part of Google Ads Conversion Tracking.

    This service is used to record and analyse customer actions defined by us (such as clicking a button, visiting a page, downloading a file, or submitting a form). We also record events (such as time spent on the page, scrolling, and interaction with the page and forms). This helps us to evaluate the success of campaigns and advertisements and to optimise the design of our website. We also use and analyse parameters in the URL (such as the visitor's source (e.g. a domain), type of campaign, visit channel (e.g. email, search engine)) to better measure campaigns and assign them to users.

    The service uses cookies, JavaScript, pixels and other technologies for this purpose. Google also processes the data to improve the quality and accuracy of conversions. The data generated in this context may be transferred by Google to a server in the USA for evaluation and stored there.

    The following cookies are set and read by Google:

    • "_gcl_au" (90 days): conversion tracking, storage of ad clicks;
    • "FPAU" (90 days): usage analysis, recording of interaction with advertising and reporting;
    • "IDE" (390 days): recognising and distinguishing visitors by means of a user ID, recording interaction with advertising, serving personalised advertising.

    The legal basis for this data processing is your consent pursuant to Art. 6(1)(a) GDPR. Access to and storage of information on the end device then takes place on the basis of the laws implementing the EU ePrivacy Directive in the EU member states, in Germany pursuant to Section 25(1) TDDDG.

    In the event that personal data is transferred from Google Ireland Limited to Google LLC in the USA, such transfer takes place on the basis of the adequacy decision for the USA, due to Google LLC's certification under the EU-US Data Privacy Framework.

    Further information can be found in Google's privacy policy: https://policies.google.com/privacy

    2.6.5 Server-Side Tracking

    Our website uses services from TAGGRS B.V., 8442 EZ Heerenveen, Coehoorn van Scheltingaweg 1P, Netherlands ("Taggrs") for server-side tracking. In doing so, usage, browser and device data, including the IP address and user agent, is collected using Taggrs' services and further processed on the server side. The purpose of the processing is to evaluate usage data in order to create statistics as well as to measure and optimise conversions. This serves to adapt and improve our website and content. Taggrs uses servers from the service provider TransIP B.V., Vondellaan 47, 2332 AA Leiden, Netherlands, within the European Economic Area.

    3. “on:mint Content Credentials” Browser Extension

    The “on:mint Content Credentials” browser extension allows you to check selected images for provenance records, Content Credentials in accordance with the C2PA standard, machine-readable AI labelling, and indications of AI generation. A check is only performed if you actively request it via the context menu or the extension icon.

    The check is performed in two steps. First, a hash value is generated from the selected image and transmitted to our API in order to compare it against the records held by on:mint. The image itself is not transmitted in this step. Only if the hash comparison does not return a match is the selected image transmitted to our API for further checking.

    When the extension is used, technically necessary connection data, in particular your IP address, is processed. In addition, the hash value of the selected image, where applicable the selected image itself, and the check result are processed. This information may constitute personal data if the image shows an identified or identifiable person or if the information can otherwise be attributed to such a person.

    The processing is carried out to provide the check you have actively requested and to ensure the functionality and security of our API. The legal basis for the processing of personal data is Art. 6(1)(f) GDPR. Our legitimate interests consist in providing you with the requested check function and in protecting our systems against misuse and attacks.

    The extension accesses the selected image only after you have actively requested the check. Insofar as information on your end device is accessed in this process, such access is strictly necessary to provide the check function you have expressly requested. In Germany, it therefore takes place on the basis of Section 25(2) No. 2 TDDDG.

    An image transmitted to our API is processed exclusively in memory for the duration of the check, is not permanently stored, and is deleted once the check is completed. Hash values and technically necessary connection data are generally processed only for the duration of the check and deleted afterwards. The check typically takes less than one minute.

    The extension does not read your browsing history, does not create usage profiles, and does not use the processed data for advertising purposes.

    For the hosting of our API, we use Scaleway SAS, 8 rue de la Ville-l’Évêque, 75008 Paris, France, as a processor. Under our current technical configuration, the processing takes place exclusively within the European Union.

    Our processing of user data arising in connection with the extension complies with the “Limited Use” requirements of the Chrome Web Store User Data Policy.

    4. Disclosure of Data

    As a rule, we only disclose the data we collect if:

    • you have given your express consent pursuant to Art. 6(1)(a) GDPR,
    • the disclosure is necessary pursuant to Art. 6(1)(f) GDPR to safeguard our interests or to assert, exercise or defend legal claims, and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data,
    • we are legally obliged to make the disclosure pursuant to Art. 6(1)(c) GDPR, or the disclosure is legally permissible and necessary pursuant to Art. 6(1)(b) GDPR for the performance of contracts with you or for carrying out pre-contractual measures taken at your request.

    Some of the data processing may be carried out by our service providers. In addition to the service providers mentioned in this privacy policy, these may include, in particular, data centres that store our website and databases (hosting provider: dogado GmbH, Antonio-Segni-Straße 11, 44263 Dortmund, Germany), IT service providers who maintain our systems, and consulting firms. If we disclose data to our service providers, they may only use the data to perform their tasks. Our service providers have been carefully selected and commissioned by us. They are contractually bound by our instructions, have appropriate technical and organisational measures in place to protect the rights of data subjects, and are regularly monitored by us.

    In addition, data may be disclosed in connection with requests from authorities, court orders and legal proceedings, where this is necessary for the pursuit or enforcement of legal claims.

    5. Data Transfers to Third Countries

    We may use services whose providers are partly based in so-called third countries (such as the USA) or transfer personal data to such countries, i.e. countries whose level of data protection does not correspond to that of the European Union. Where an adequacy decision by the European Commission (Art. 45 GDPR) exists for these countries, we base the data transfer on it. This applies, for example, to transfers to Argentina, Israel, Japan, Canada, the Republic of Korea, New Zealand, Switzerland, Uruguay or the United Kingdom. In the case of the USA, this only applies insofar as the US recipient is certified under the EU-US Data Privacy Framework.

    Where no adequacy decision has been issued for the relevant country, we have taken appropriate precautions to ensure an adequate level of data protection for any data transfers. These include, among other things, the European Union's standard contractual clauses or binding corporate rules (Art. 46 GDPR).

    Where this is not possible, we base the data transfer on the exceptions set out in Art. 49 GDPR, in particular your express consent or the necessity of the transfer for the performance of a contract or for carrying out pre-contractual measures.

    Where a transfer to a third country is envisaged and no adequacy decision or suitable safeguards are in place, it is possible, and there is a risk, that authorities in the relevant third country (e.g. intelligence services) may gain access to the transferred data in order to collect and analyse it, and that the enforceability of your data subject rights cannot be guaranteed. Where consent is obtained for the data transfer via the consent banner, you will also be informed of this.

    6. Retention Period

    In principle, we only store personal data for as long as is necessary to fulfil the purposes for which we collected the data. We then delete the data without delay, unless we still require the data until the expiry of the statutory limitation period for evidentiary purposes in relation to civil law claims, or due to statutory retention obligations.

    For evidentiary purposes, we must retain contract data for three years from the end of the year in which the business relationship with you ends. Any claims become time-barred, at the earliest, under the standard statutory limitation period at this point. Even after this, we may still need to store some of your data for accounting reasons. We are obliged to do so due to statutory documentation obligations, which may arise, for example, from the German Commercial Code, the Fiscal Code, the Banking Act and the Anti-Money Laundering Act. The retention periods specified therein for documents range from two to ten years.

    7. Your Rights

    You have the right at any time to request information about the processing of your personal data by us. As part of providing this information, we will explain the data processing to you and provide an overview of the data stored about you. If data stored by us is incorrect or no longer up to date, you have the right to have this data corrected. You may also request the erasure of your data. If erasure is exceptionally not possible due to other legal provisions, the data will be restricted so that it is only available for that statutory purpose. You may also have the processing of your data restricted, e.g. if you believe that the data we have stored is not correct. You also have the right to data portability, i.e. that we provide you, on request, with a digital copy of the personal data you have provided to us. You also have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, including, where applicable, the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.

    To exercise the rights described here, you can contact us at any time using the contact details given above. This also applies if you would like to receive copies of guarantees demonstrating an adequate level of data protection. Provided that the relevant legal requirements are met, we will comply with your data protection request.

    Your requests to exercise data subject rights and our responses to them are retained for documentation purposes for a period of up to three years, and in individual cases, where there is cause to assert, exercise or defend legal claims, for longer. The legal basis is Art. 6(1) sentence 1(f) GDPR, based on our interest in defending against any civil law claims under Art. 82 GDPR, avoiding fines under Art. 83 GDPR, and fulfilling our accountability obligation under Art. 5(2) GDPR.

    Finally, you have the right to lodge a complaint with a data protection supervisory authority. You can exercise this right, for example, with a supervisory authority in the member state of your habitual residence, place of work or the place of the alleged infringement. In Berlin, the registered office of Onmint GmbH, the competent supervisory authority is: Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59-61, 10555 Berlin.

    8. Right to Withdraw Consent and Right to Object

    You have the right to withdraw any consent you have given us at any time. This means that we will no longer continue the data processing based on this consent in the future. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up until the withdrawal.

    Where we process your data on the basis of legitimate interests, you have the right to object at any time to the processing of your data for reasons arising from your particular situation. If the objection relates to data processing for direct marketing purposes, you have a general right to object, which we will also implement without giving any reasons.

    If you wish to exercise your right of withdrawal or objection, an informal message to the contact details given above is sufficient.

    9. Obligation to Provide Your Data

    Insofar as the provision of your data is required for the conclusion of a contract (e.g. to order services), to fulfil statutory obligations, to make contact, or to use other services and functions (e.g. to sign up for the newsletter), the relevant input fields are marked as mandatory (usually with an asterisk (*)). In this case, a contract cannot be concluded, the specific service cannot be provided, or the function cannot be used without the data provided.

    Other information not marked as mandatory fields is voluntary. Entering such data is then not necessary for the conclusion of a contract, the provision of the service, or the use of the function, and has no effect on the performance of the contract.

    10. Automated Decision-Making

    Automated decision-making, including profiling within the meaning of Art. 22 GDPR, with legal or similarly significant effect does not take place.

    11. Changes to This Privacy Policy

    We occasionally update this privacy policy, for example when we adapt our website or when statutory or regulatory requirements change.

    Last updated: July 2026