Privacy Policy

Last updated: January 2024

1. Introduction

In the following, we provide information about the collection of personal data when using:

  • our website codum.cc
  • our profiles on social media platforms.

Personal data is any data that can be related to a specific natural person, such as their name or IP address.

1.1. Contact details

The controller within the meaning of Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is Codum GmbH, Zeller Str. 29, 82067 Zell, Germany, email: tatjana@codum.cc. We are legally represented by Isabella Hoesch and Tatjana Hoesch. Our data protection officer can be reached via email at tatjana@codum.cc.

1.2 Scope of Data Processing, Processing Purposes, and Legal Bases

We detail the scope of data processing, processing purposes, and legal bases below. In principle, the following come into consideration as the legal basis for data processing:

  • Art. 6 para. 1 s. 1 lit. a GDPR serves as our legal basis for processing operations for which we obtain consent.
  • Art. 6 para. 1 s. 1 lit. b GDPR is the legal basis insofar as the processing of personal data is necessary for the performance of a contract, e.g., if a site visitor purchases a product from us or we perform a service for them. This legal basis also applies to processing that is necessary for pre-contractual measures, such as in the case of inquiries about our products or services.
  • Art. 6 para. 1 s. 1 lit. c GDPR applies if we fulfill a legal obligation by processing personal data, as may be the case, for example, in tax law.
  • Art. 6 para. 1 s. 1 lit. f GDPR serves as the legal basis when we can rely on legitimate interests to process personal data, e.g., for cookies necessary for the technical operation of our website.

1.3. Data Processing Outside the EEA

Insofar as we transfer data to service providers or other third parties outside the EEA, the security of the data during the transfer is guaranteed by adequacy decisions of the EU Commission, insofar as they exist (e.g., for Great Britain, Canada, and Israel) (Art. 45 para. 3 GDPR). In the case of data transfer to service providers in the USA, the legal basis for the data transfer is an adequacy decision of the EU Commission if the service provider has certified itself under the EU-US Data Privacy Framework. In other cases (e.g., if no adequacy decision exists), the legal basis for the data transfer is usually standard contractual clauses. These are a set of rules adopted by the EU Commission and are part of the contract with the respective third party. According to Art. 46 para. 2 lit. b GDPR, they ensure the security of the data transfer. Many providers have given contractual guarantees that go beyond the standard contractual clauses to protect the data. These include, for example, guarantees regarding the encryption of data or an obligation on the part of the third party to notify data subjects if law enforcement agencies wish to access the respective data.

1.4. Storage Duration

Unless expressly stated in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and no legal obligations to retain data conflict with the deletion. If the data is not deleted because it is required for other and legally permissible purposes, its processing is restricted, i.e., the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

1.5. Rights of Data Subjects

Data subjects have the following rights against us regarding their personal data:

  • Right of access
  • Right to correction or deletion
  • Right to limit processing
  • Right to object to the processing
  • Right to data transferability
  • Right to revoke given consent at any time

Data subjects also have the right to complain to a data protection supervisory authority about the processing of their personal data. Contact details of the data protection supervisory authorities are available at https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html.

1.6. Obligation to Provide Data

Within the scope of the business or other relationship, customers, prospective customers, or third parties need to provide us with personal data necessary for the establishment, execution, and termination of a business or other relationship, or that we are legally obliged to collect. Without this data, we will generally have to refuse to conclude the contract or provide a service, or we will no longer be able to perform an existing contract or other relationship. Mandatory data is marked as such.

1.7. No Automated Decision-Making in Individual Cases

As a matter of principle, we do not use a fully automated decision-making process according to Art. 22 GDPR to establish and implement the business or other relationship. Should we use these procedures in individual cases, we will inform of this separately if this is required by law.

1.8. Making Contact

When contacting us, e.g., by email or telephone, the data provided to us (e.g., names and email addresses) will be stored by us to answer questions. The legal basis for the processing is our legitimate interest (Art. 6 para. 1 s. 1 lit. f GDPR) in answering inquiries directed to us. We delete the data accruing in this context after the storage is no longer necessary or restrict the processing if there are legal retention obligations.

1.9. Customer Surveys

From time to time, we conduct customer surveys to get to know our customers and their wishes better. In doing so, we collect the data requested in each case. It is our legitimate interest to get to know our customers and their wishes better, so the legal basis for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We delete the data when the results of the surveys have been evaluated.

2. Newsletter

Interested people have the option to subscribe to a free newsletter. We process the data provided during registration exclusively for the purpose of sending the newsletter. Registration occurs by selecting the appropriate field on our website, checking the relevant box on a paper document, or through another clear action, by which interested parties express their consent to the processing of their data. The legal basis for this is Art. 6(1)(a) GDPR. Consent can be revoked at any time, e.g., by clicking the corresponding link in the newsletter or by notifying us via our email address provided above. The processing of data remains lawful even if consent is withdrawn, up until the point of revocation. Based on the recipients' consent (Art. 6(1)(a) GDPR), we also measure the open and click rates of our newsletters to understand which content is relevant to our recipients.

We send newsletters using the tool Brevo from the provider Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin (Privacy Policy: https://de.sendinblue.com/legal/privacypolicy/). The provider processes content, usage, metadata/communication data, and contact data within the EU.

3. Data Processing on Our Website

3.1. Notice for Website Visitors from Germany

Our website stores information on the terminal equipment of website visitors (e.g., cookies) or accesses information that is already stored in the terminal equipment (e.g., IP addresses). What information this is in detail can be found in the following sections. This storage and access is based on the following provisions:

  • Insofar as this storage or access is absolutely necessary for us to provide the service of our website expressly requested by website visitors (e.g., to carry out a chatbot used by the website visitor or to ensure the IT security of our website), it is carried out on the basis of Section 25 para. 2 no. 2 of the German Telecommunications Telemedia Data Protection (Telekommunikation-Telemedien-Datenschutz-Gesetz, “TTDSG”).
  • Otherwise, this storage or access takes place based on the website visitor’s consent (Section 25 para. 1 TTDSG).

This data is also stored in log files. It is deleted when its storage is no longer necessary, at the latest after 14 days.

3.3. Web Hosting and Provision of the Website

This website is hosted by an external service provider (host). The personal data collected on this website is stored on the servers of the host. This may include IP addresses, contact inquiries, metadata and communication data, website visits, and other data generated through the use of the website. These data are stored in an anonymized manner, and we do not have access to them.The use of the host is based on the purpose of fulfilling contracts with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of providing our online services securely, quickly, and efficiently through a professional provider (Art. 6 para. 1 lit. f GDPR).Our host will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data. We work in trustful cooperation with this host:

Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, CA 94103

Further information can be found in the provider’s privacy policy at https://webflow.com/legal/privacy.

3.5. Booking of Appointments

Site visitors can book appointments with us on our website. For this purpose, we process metadata or communication data in addition to the data entered. We have a legitimate interest in offering interested parties a user-friendly option for making appointments. Therefore, the legal basis for data processing is Art. 6 para. 1 s. 1 lit. f GDPR. Insofar as we use a third-party tool for this purpose, the information on this can be found under "Third Parties."

3.6. Technically Necessary Cookies

Our website sets cookies. Cookies are small text files that are stored in the web browser on the end device of a site visitor. Cookies help to make the offer more user-friendly, effective, and secure. Insofar as these cookies are necessary for the operation of our website or its functions (hereinafter “Technically Necessary Cookies”), the legal basis for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We have a legitimate interest in providing customers and other site visitors with a functional website. Specifically, we set technically necessary cookies for the following purpose or purposes: Cookies that adopt language settings.

3.7. Third Parties

We use third-party services to enhance our platform's functionality. The following are the third-party services we currently use:

3.7.1. Calendly

We use Calendly to schedule appointments. The provider is Calendly LLC, based in the USA. Calendly processes data such as usage data, contact data, and metadata. The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR, based on user consent. The security of the data transferred to the third country (outside the EEA) is ensured by standard data protection clauses. Further information is available in Calendly’s privacy policy at https://calendly.com/pages/privacy.

3.7.2. Typeform

We use Typeform for quizzes and forms. The provider is Typeform S.L., based in Spain. Typeform processes data such as entries in online forms and metadata. The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR, based on user consent. The security of the data transferred outside the EEA is ensured by standard data protection clauses. Further information is available in Typeform’s privacy policy at https://admin.typeform.com/to/dwk6gt.

3.7.3. Microsoft Clarity

We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.

3.7.4. Google Analytics

We utilize Google Analytics to understand how visitors interact with our website. This service collects data such as your IP address, browser type, and pages visited, which are transmitted to and stored by Google on servers that may be located outside the European Union. To protect your privacy, we have enabled IP anonymization, ensuring that Google truncates your IP address within EU member states before transmission. The information gathered helps us analyze website usage and improve our services. For more details on how Google processes this data, please refer to Google's Privacy Policy https://policies.google.com/privacy. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

4. Data Processing on Social Media Platforms

We are represented on social media networks to present our organization and services. The operators of these networks regularly process their users’ data for advertising purposes. Among other things, they create user profiles from their online behavior, which are used, for example, to show advertising on the pages of the networks and elsewhere on the Internet that corresponds to the interests of the users. To this end, the operators of the networks store information on user behavior in cookies on the users’ computers. Furthermore, it cannot be ruled out that the operators merge this information with other data. Users can obtain further information and instructions on how to object to processing by the site operators in the data protection declarations of the respective operators listed below. It is also possible that the operators or their servers are located in non-EU countries, so that they process data there. This may result in risks for users, e.g., because it is more difficult to enforce their rights or because government agencies access the data. If users of the networks contact us via our profiles, we process the data provided to us to respond to the inquiries. This is our legitimate interest, so the legal basis is Art. 6 para. 1 s. 1 lit. f GDPR.

4.1. Facebook

We maintain a profile on Facebook. The operator is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://www.facebook.com/policy.php. A possibility to object to data processing arises via settings for advertisements: https://www.facebook.com/legal/terms/information_about_page_insights_data. Data subjects can exercise their rights both against us and against Facebook. However, according to our agreement with Facebook, we are obliged to forward requests to Facebook. Data subjects will therefore receive a faster response if they contact Facebook directly.

4.2. Instagram

We maintain a profile on Instagram. The operator is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://help.instagram.com/519522125107875.

4.3. LinkedIn

We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy is available here: https://www.linkedin.com/legal/privacy-policy?_l=de_DE. One way to object to data processing is via the settings for advertisements: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

5. Changes to This Privacy Policy

We reserve the right to change this privacy policy with effect for the future. A current version is always available here. We will notify users of any significant changes, especially if they affect how data is processed.

6. Copyright

The content and works created by the site operators on these pages are subject to German copyright law. Duplication, processing, distribution, or any form of commercialization of such material beyond the scope of copyright law shall require the prior written consent of its respective author or creator. Downloads and copies of this site are only permitted for private, non-commercial use. Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is identified as such. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. We will remove such content immediately if we become aware of any infringements.

7. Questions and Comments

If you have any questions or comments regarding this privacy policy, please feel free to contact us using the contact information provided above.