Privacy policy
1. Privacy at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any information that can identify you personally. For detailed information about data protection, please refer to our privacy policy below.
Data collection on this website
Who is responsible for collecting data on this website?
Data on this website is processed by the website operator. You can find their contact details in the section entitled “Information about the controller” in this privacy policy.
How do we collect your data?
Some data is collected when you provide it to us. This may include, for example, information you enter in a contact form.
Other data is collected by our IT systems automatically, or following your consent, when you visit the website. This primarily consists of technical information, such as your web browser, operating system or the time you access a page. This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some data is collected to ensure that the website functions correctly. Other data may be used to analyse your behaviour as a user. Where contracts can be concluded or initiated through the website, the information provided is also processed for quotations, orders or other enquiries relating to contracts.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the source, recipients and purpose of your stored personal data. You also have the right to request that this data be corrected or erased. If you have consented to data processing, you may withdraw that consent at any time with effect for the future. You also have the right, in certain circumstances, to request restriction of the processing of your personal data. You furthermore have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time about this or any other questions concerning data protection.
Analytics tools and third-party tools
When you visit this website, your browsing behaviour may be analysed statistically. This is primarily carried out using analytics software.
Detailed information about these analytics programmes can be found in the privacy policy below.
2. Hosting and content delivery networks (CDNs)
We use the following providers to operate our website and email communications:
Brevo – website email delivery
Website and contact form emails are sent through Brevo using the sending account managed by BenzDigital. This involves processing sender and recipient addresses, message contents and technical delivery data. Messages are transmitted to Brevo over an encrypted SMTP connection. The association’s newsletter is sent through a separate Brevo account. Further information: Brevo privacy policy.
IONOS – email hosting
Our email inboxes are hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Receiving and handling emails involves processing sender and recipient addresses, message contents and technical communication data. Further information: IONOS privacy policy.
Processing on our behalf
We have concluded a data processing agreement for the use of the above service. This agreement is required under data protection law and ensures that the provider processes our website visitors’ personal data only in accordance with our instructions and in compliance with the GDPR.
Raidboxes
The provider is Raidboxes GmbH, Hafenstr. 32, 48153 Münster, Germany (hereinafter “Raidboxes”). When you visit our website, Raidboxes collects various log files, including your IP addresses.
For details, please see the Raidboxes privacy policy: https://raidboxes.io/legal/privacy/.
We use Raidboxes on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in ensuring that our website is delivered as reliably as possible. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device, for example for device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Processing on our behalf
We have concluded a data processing agreement for the use of the above service. This agreement is required under data protection law and ensures that the provider processes our website visitors’ personal data only in accordance with our instructions and in compliance with the GDPR.
Cloudflare
We use the Cloudflare service. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).
Cloudflare provides a globally distributed content delivery network with DNS. Technically, information transferred between your browser and our website is routed through Cloudflare’s network. This enables Cloudflare to analyse traffic between your browser and our website and to act as a filter between our servers and potentially malicious internet traffic. Cloudflare may also use cookies or other technologies to recognise internet users, but these are used solely for the purpose described here.
We use Cloudflare on the basis of our legitimate interest in providing our website as securely and reliably as possible (Article 6(1)(f) GDPR).
Transfers of data to the USA are based on the European Commission’s Standard Contractual Clauses. Details and further information about security and privacy at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every DPF-certified company undertakes to comply with these standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.
Processing on our behalf
We have concluded a data processing agreement for the use of the above service. This agreement is required under data protection law and ensures that the provider processes our website visitors’ personal data only in accordance with our instructions and in compliance with the GDPR.
3. General information and mandatory disclosures
Privacy
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection requirements and this privacy policy.
When you use this website, various personal data is collected. Personal data means information that can identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this takes place.
Please note that transmitting data over the internet, for example when communicating by email, may involve security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information about the controller
The controller responsible for processing data on this website is:
Represented by the committee:
L. Konstantin Guntrum
Telephone: +49 (0) 6133 97170
Email: info@roter-hang.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data, such as names, email addresses or similar information.
Retention period
Unless a more specific retention period is stated in this privacy policy, we retain your personal data until the purpose for processing it no longer applies. If you make a valid request for erasure or withdraw your consent to processing, your data will be erased unless we have other legally permissible grounds for retaining it, such as retention periods under tax or commercial law. In that case, the data will be erased once those grounds cease to apply.
General information about the legal bases for processing data on this website
If you have consented to data processing, we process your personal data on the basis of Article 6(1)(a) GDPR or, where special categories of data under Article 9(1) GDPR are processed, Article 9(2)(a) GDPR. Where you have explicitly consented to the transfer of personal data to third countries, processing is also based on Article 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your device, for example through device fingerprinting, processing is additionally based on section 25(1) TDDDG. Consent may be withdrawn at any time. If your data is required to perform a contract or take steps prior to entering into a contract, we process it on the basis of Article 6(1)(b) GDPR. We also process your data on the basis of Article 6(1)(c) GDPR where necessary to comply with a legal obligation. Processing may further be based on our legitimate interests under Article 6(1)(f) GDPR. The following sections explain the legal bases applicable in each case.
Recipients of personal data
In the course of our activities, we work with various external organisations. This sometimes requires personal data to be transferred to them. We disclose personal data to external organisations only where necessary to perform a contract, where we are legally obliged to do so, for example to disclose data to tax authorities, where we have a legitimate interest in disclosure under Article 6(1)(f) GDPR, or where another legal basis permits disclosure. When using processors, we disclose our customers’ personal data only on the basis of a valid data processing agreement. Where processing is carried out jointly, a joint controllership agreement is concluded.
Withdrawal of your consent to data processing
Many processing operations are possible only with your express consent. You may withdraw consent already given at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew your consent.
Right to object to data collection in specific circumstances and to direct marketing (Article 21 GDPR)
WHERE DATA IS PROCESSED ON THE BASIS OF ARTICLE 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA. THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE RELEVANT LEGAL BASIS FOR PROCESSING IS SET OUT IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ESTABLISH, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION UNDER ARTICLE 21(1) GDPR).
WHERE YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING. THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ARTICLE 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of a breach of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work or the place of the alleged infringement. This right exists without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or in performance of a contract, or to have it provided to a third party, in a commonly used, machine-readable format. Where you request direct transfer to another controller, this will be carried out only where technically feasible.
Access, rectification and erasure
Under the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its source and recipients, and the purpose of processing. Where applicable, you also have the right to rectification or erasure. You may contact us at any time about this or any other questions concerning personal data.
Right to restriction of processing
You have the right to request restriction of the processing of your personal data. You may contact us at any time to do so. This right applies in the following circumstances:
- If you dispute the accuracy of the personal data we hold about you, we generally need time to verify it. During this verification, you have the right to request restriction of processing.
- If your personal data has been or is being processed unlawfully, you may request restriction of processing instead of erasure.
- If we no longer need your personal data but you require it to exercise, defend or establish legal claims, you have the right to request restriction of processing instead of erasure.
- If you have objected under Article 21(1) GDPR, your interests must be balanced against ours. Until it has been determined which interests prevail, you have the right to request restriction of processing.
Where processing has been restricted, your data may, apart from being stored, be processed only with your consent, to establish, exercise or defend legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the website operator, this website uses SSL or TLS encryption. You can recognise an encrypted connection when your browser’s address bar changes from “http://” to “https://” and displays a padlock symbol.
When SSL or TLS encryption is enabled, data you send to us cannot be read by third parties.
Objection to promotional emails
We hereby object to the use of contact details published as part of our mandatory legal notice for sending unsolicited advertising and information materials. The website operators expressly reserve the right to take legal action in the event of unsolicited promotional material, such as spam emails.
4. Data collection on this website
Cookies
Our website uses cookies. Cookies are small data packages that do not harm your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted when your visit ends. Persistent cookies remain on your device until you delete them yourself or your browser deletes them automatically.
Cookies may be set by us (first-party cookies) or by third-party companies (third-party cookies). Third-party cookies enable certain services provided by other companies to be incorporated into websites, for example cookies used to process payment services.
Cookies serve various purposes. Many are technically necessary because certain website functions, such as a shopping basket or video display, would not work without them. Other cookies may be used to analyse user behaviour or for advertising.
Cookies required for electronic communications, to provide certain functions you request, such as a shopping basket, or to optimise the website, such as cookies measuring website audiences, are stored on the basis of Article 6(1)(f) GDPR unless another legal basis is stated. The website operator has a legitimate interest in storing necessary cookies to provide technically reliable and optimised services. Where consent to storing cookies or similar recognition technologies has been requested, processing is carried out exclusively on the basis of that consent (Article 6(1)(a) GDPR and section 25(1) TDDDG). Consent may be withdrawn at any time.
You can configure your browser to notify you when cookies are set and allow them only in individual cases, reject cookies in specific cases or generally, and automatically delete cookies when closing the browser. Disabling cookies may restrict the functionality of this website.
This privacy policy explains which cookies and services are used on this website.
Consent with Borlabs Cookie
Our website uses Borlabs Cookie consent technology to obtain your consent to storing certain cookies in your browser or using certain technologies, and to document this in accordance with data protection law. The technology is provided by Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany (hereinafter “Borlabs”).
When you enter our website, a Borlabs cookie is stored in your browser to record the consent you have given or withdrawn. This data is not passed to the provider of Borlabs Cookie.
The data collected is retained until you ask us to erase it, delete the Borlabs cookie yourself, or the purpose for storing it no longer applies. Mandatory statutory retention periods remain unaffected. Details of data processing by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
We use Borlabs Cookie consent technology to obtain the consent legally required for the use of cookies. The legal basis is Article 6(1)(c) GDPR.
5. Social media
This website includes functions of the Instagram service. These functions are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and Instagram’s server. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, clicking the Instagram button enables you to link content from this website to your Instagram profile. This allows Instagram to associate your visit with your account. Please note that, as the website provider, we have no knowledge of the content of the data transferred or how Instagram uses it.
This service is used on the basis of your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent may be withdrawn at any time.
Insofar as the tool described here collects personal data on our website and transmits it to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this processing (Article 26 GDPR). Joint responsibility is limited exclusively to collecting the data and transmitting it to Facebook or Instagram. Processing by Facebook or Instagram after transmission is not covered by this joint responsibility. Our respective obligations are set out in a joint controllership agreement, which can be found at: https://www.facebook.com/legal/controller_addendum. Under this agreement, we are responsible for providing privacy information when using the Facebook or Instagram tool and for implementing it on our website in accordance with data protection law. Facebook is responsible for the security of data within its Facebook and Instagram products. You can exercise your data subject rights, such as requests for access to data processed by Facebook or Instagram, directly with Facebook. If you exercise these rights with us, we are obliged to forward your request to Facebook.
Transfers of data to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381.
Further information can be found in Instagram’s privacy policy: https://privacycenter.instagram.com/policy/.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every DPF-certified company undertakes to comply with these standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
6. Analytics tools and advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager enables us to incorporate tracking and analytics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies or carry out independent analyses. It is used solely to manage and deploy the tools incorporated through it. However, Google Tag Manager does collect your IP address, which may also be transferred to Google’s parent company in the United States.
We use Google Tag Manager on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in integrating and managing various tools on its website quickly and easily. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every DPF-certified company undertakes to comply with these standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses functions of the Google Analytics web analytics service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyse visitors’ behaviour. The operator receives usage data such as page views, time spent on the website, operating systems used and users’ origins. This data is associated with the user’s device, but not with a user ID.
Google Analytics also enables us to record mouse movements, scrolling and clicks, among other things. It uses various modelling techniques to supplement the data collected and machine learning technologies to analyse it.
Google Analytics uses technologies such as cookies or device fingerprinting to recognise users and analyse their behaviour. Information collected by Google about the use of this website is generally transferred to a Google server in the USA and stored there.
This service is used on the basis of your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent may be withdrawn at any time.
Transfers of data to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every DPF-certified company undertakes to comply with these standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
IP anonymisation
IP anonymisation is enabled in Google Analytics. Google therefore truncates your IP address within European Union Member States or other countries party to the Agreement on the European Economic Area before transmitting it to the USA. Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there. On behalf of this website’s operator, Google uses this information to evaluate your use of the website, compile reports on website activity and provide other services relating to website and internet use. The IP address transmitted by your browser through Google Analytics is not combined with other data held by Google.
Browser plug-in
You can prevent Google from collecting and processing your data by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
Further information about how Google Analytics handles user data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
7. Newsletter
Newsletter data and Brevo
We use Brevo for our subscription form and newsletter delivery. The embedded form and its Cloudflare Turnstile security check are loaded only after you enable the “Brevo Newsletter” service in Borlabs Cookie. This establishes connections to Brevo and Cloudflare; submitting the form sends your subscription details to Brevo. Enabling the form alone does not subscribe you to the newsletter. Provider information: Brevo privacy policy.
If you wish to receive the newsletter offered on this website, we require your email address and information enabling us to verify that you own that address and agree to receive the newsletter. No other data is collected, except on a voluntary basis. We use this data solely to send the information you requested and use the newsletter service Brevo for subscriptions and delivery.
Data entered in the newsletter subscription form is processed exclusively on the basis of your consent (Article 6(1)(a) GDPR). You may withdraw your consent to the storage of your data and email address and their use for sending the newsletter at any time, for example using the unsubscribe link in the newsletter. Withdrawal does not affect the lawfulness of processing already carried out.
The data you provide to subscribe to the newsletter is stored by us or our newsletter service provider until you unsubscribe, and is then removed from the mailing list when you unsubscribe or the purpose no longer applies. We reserve the right to delete or block email addresses from our mailing list at our discretion on the basis of our legitimate interests under Article 6(1)(f) GDPR.
Data stored by us for other purposes remains unaffected.
After you unsubscribe, your email address may be stored by us or our newsletter service provider on a suppression list where necessary to prevent future mailings. Data on this list is used only for that purpose and is not combined with other data. This serves both your interests and our interest in complying with legal requirements when sending newsletters (a legitimate interest under Article 6(1)(f) GDPR). There is no time limit on storage in the suppression list. You may object to this storage if your interests outweigh our legitimate interests.
8. Plug-ins and tools
YouTube with privacy-enhanced mode
This website embeds videos from YouTube. The website is operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit a page on this website that includes YouTube, a connection is established with YouTube’s servers. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, YouTube can associate your browsing behaviour directly with your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube in privacy-enhanced mode. According to YouTube, videos played in this mode are not used to personalise browsing on YouTube. Advertisements shown in this mode are not personalised either. Privacy-enhanced mode does not set cookies. However, it stores local storage elements in the user’s browser which, like cookies, contain personal data and can be used to recognise users. Details of privacy-enhanced mode can be found here: https://support.google.com/youtube/answer/171780.
Activating a YouTube video may trigger further data processing operations over which we have no control.
We use YouTube in the interest of presenting our online services attractively. This constitutes a legitimate interest under Article 6(1)(f) GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Further information about privacy at YouTube can be found in its privacy policy at: https://policies.google.com/privacy?hl=de.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every DPF-certified company undertakes to comply with these standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Fonts (locally hosted)
This website uses Google Fonts, provided by Google, to display typefaces consistently. The fonts are installed locally. No connection to Google’s servers is established for this purpose.
Further information about Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=de.
Font Awesome (locally hosted)
This website uses Font Awesome to display typefaces consistently. Font Awesome is installed locally. No connection to Fonticons, Inc. servers is established for this purpose.
Further information about Font Awesome can be found in its privacy policy at: https://fontawesome.com/privacy.
OpenStreetMap
Our overview maps for the Wine Experience Trail, the Wine Showcase and the wineries use OpenStreetMap. Once you give consent, map tiles are loaded from the OpenStreetMap Foundation. This transmits data including your IP address, browser information and the requested map areas. Map tiles are provided through a worldwide network of servers.
The map library and our stop data are hosted on our own server. No OpenStreetMap tiles are loaded before you enable the service in Borlabs Cookie. You can withdraw consent at any time through “Privacy settings” in the footer. You can open the external Google Maps and OpenStreetMap links independently of the embedded map; these take you to the respective provider only when you open them.
Further information: OpenStreetMap Foundation privacy policy.
Google Maps
This website uses Google Maps. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to embed maps on our website.
Your IP address must be stored to use Google Maps functions. This information is generally transferred to a Google server in the USA and stored there. The website provider has no influence over this transfer. When Google Maps is enabled, Google may use Google Fonts to display typefaces consistently. When you access Google Maps, your browser loads the necessary web fonts into its cache to display text and typefaces correctly.
We use Google Maps in the interest of presenting our online services attractively and making the places mentioned on our website easy to find. This constitutes a legitimate interest under Article 6(1)(f) GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Transfers of data to the USA are based on the European Commission’s Standard Contractual Clauses. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
Further information about how user data is handled can be found in Google’s privacy policy: https://policies.google.com/privacy?hl=de.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every DPF-certified company undertakes to comply with these standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Cloudflare Turnstile
We use Cloudflare Turnstile (hereinafter “Turnstile”) on this website. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).
Turnstile checks whether information entered on this website, for example in a contact form, has been entered by a person or an automated programme. To do this, it analyses various characteristics of a visitor’s behaviour.
This analysis begins automatically as soon as a visitor enters a website with Turnstile enabled. Turnstile evaluates various information, such as the IP address, time spent on the website and mouse movements. The data collected during this analysis is transmitted to Cloudflare.
Data is stored and analysed on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its website against abusive automated scraping and spam. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Processing is based on Standard Contractual Clauses, which can be found here: https://www.cloudflare.com/cloudflare-customer-scc/.
Further information about Cloudflare Turnstile can be found in the privacy terms at https://www.cloudflare.com/cloudflare-customer-dpa/.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every DPF-certified company undertakes to comply with these standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.