Last updated: January 2024
In the following, we provide information about the collection of personal data when using:
Personal data is any data that can be related to a specific natural person, such as their name or IP address.
The controller within the meaning of Art. 4 para. 7 EU General Data Protection Regulation (GDPR) is Codum GmbH, Zeller Str. 29, 82067 Zell, Germany, email: tatjana@codum.cc. We are legally represented by Isabella Hoesch and Tatjana Hoesch. Our data protection officer can be reached via email at tatjana@codum.cc.
We detail the scope of data processing, processing purposes, and legal bases below. In principle, the following come into consideration as the legal basis for data processing:
Insofar as we transfer data to service providers or other third parties outside the EEA, the security of the data during the transfer is guaranteed by adequacy decisions of the EU Commission, insofar as they exist (e.g., for Great Britain, Canada, and Israel) (Art. 45 para. 3 GDPR). In the case of data transfer to service providers in the USA, the legal basis for the data transfer is an adequacy decision of the EU Commission if the service provider has certified itself under the EU-US Data Privacy Framework. In other cases (e.g., if no adequacy decision exists), the legal basis for the data transfer is usually standard contractual clauses. These are a set of rules adopted by the EU Commission and are part of the contract with the respective third party. According to Art. 46 para. 2 lit. b GDPR, they ensure the security of the data transfer. Many providers have given contractual guarantees that go beyond the standard contractual clauses to protect the data. These include, for example, guarantees regarding the encryption of data or an obligation on the part of the third party to notify data subjects if law enforcement agencies wish to access the respective data.
Unless expressly stated in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and no legal obligations to retain data conflict with the deletion. If the data is not deleted because it is required for other and legally permissible purposes, its processing is restricted, i.e., the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Data subjects have the following rights against us regarding their personal data:
Data subjects also have the right to complain to a data protection supervisory authority about the processing of their personal data. Contact details of the data protection supervisory authorities are available at https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html.
Within the scope of the business or other relationship, customers, prospective customers, or third parties need to provide us with personal data necessary for the establishment, execution, and termination of a business or other relationship, or that we are legally obliged to collect. Without this data, we will generally have to refuse to conclude the contract or provide a service, or we will no longer be able to perform an existing contract or other relationship. Mandatory data is marked as such.
As a matter of principle, we do not use a fully automated decision-making process according to Art. 22 GDPR to establish and implement the business or other relationship. Should we use these procedures in individual cases, we will inform of this separately if this is required by law.
When contacting us, e.g., by email or telephone, the data provided to us (e.g., names and email addresses) will be stored by us to answer questions. The legal basis for the processing is our legitimate interest (Art. 6 para. 1 s. 1 lit. f GDPR) in answering inquiries directed to us. We delete the data accruing in this context after the storage is no longer necessary or restrict the processing if there are legal retention obligations.
From time to time, we conduct customer surveys to get to know our customers and their wishes better. In doing so, we collect the data requested in each case. It is our legitimate interest to get to know our customers and their wishes better, so the legal basis for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We delete the data when the results of the surveys have been evaluated.
Interested people have the option to subscribe to a free newsletter. We process the data provided during registration exclusively for the purpose of sending the newsletter. Registration occurs by selecting the appropriate field on our website, checking the relevant box on a paper document, or through another clear action, by which interested parties express their consent to the processing of their data. The legal basis for this is Art. 6(1)(a) GDPR. Consent can be revoked at any time, e.g., by clicking the corresponding link in the newsletter or by notifying us via our email address provided above. The processing of data remains lawful even if consent is withdrawn, up until the point of revocation. Based on the recipients' consent (Art. 6(1)(a) GDPR), we also measure the open and click rates of our newsletters to understand which content is relevant to our recipients.
We send newsletters using the tool Brevo from the provider Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin (Privacy Policy: https://de.sendinblue.com/legal/privacypolicy/). The provider processes content, usage, metadata/communication data, and contact data within the EU.
Our website stores information on the terminal equipment of website visitors (e.g., cookies) or accesses information that is already stored in the terminal equipment (e.g., IP addresses). What information this is in detail can be found in the following sections. This storage and access is based on the following provisions:
This data is also stored in log files. It is deleted when its storage is no longer necessary, at the latest after 14 days.
This website is hosted by an external service provider (host). The personal data collected on this website is stored on the servers of the host. This may include IP addresses, contact inquiries, metadata and communication data, website visits, and other data generated through the use of the website. These data are stored in an anonymized manner, and we do not have access to them.The use of the host is based on the purpose of fulfilling contracts with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of providing our online services securely, quickly, and efficiently through a professional provider (Art. 6 para. 1 lit. f GDPR).Our host will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data. We work in trustful cooperation with this host:
Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, CA 94103
Further information can be found in the provider’s privacy policy at https://webflow.com/legal/privacy.
Site visitors can book appointments with us on our website. For this purpose, we process metadata or communication data in addition to the data entered. We have a legitimate interest in offering interested parties a user-friendly option for making appointments. Therefore, the legal basis for data processing is Art. 6 para. 1 s. 1 lit. f GDPR. Insofar as we use a third-party tool for this purpose, the information on this can be found under "Third Parties."
Our website sets cookies. Cookies are small text files that are stored in the web browser on the end device of a site visitor. Cookies help to make the offer more user-friendly, effective, and secure. Insofar as these cookies are necessary for the operation of our website or its functions (hereinafter “Technically Necessary Cookies”), the legal basis for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We have a legitimate interest in providing customers and other site visitors with a functional website. Specifically, we set technically necessary cookies for the following purpose or purposes: Cookies that adopt language settings.
We use third-party services to enhance our platform's functionality. The following are the third-party services we currently use:
We use Calendly to schedule appointments. The provider is Calendly LLC, based in the USA. Calendly processes data such as usage data, contact data, and metadata. The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR, based on user consent. The security of the data transferred to the third country (outside the EEA) is ensured by standard data protection clauses. Further information is available in Calendly’s privacy policy at https://calendly.com/pages/privacy.
We use Typeform for quizzes and forms. The provider is Typeform S.L., based in Spain. Typeform processes data such as entries in online forms and metadata. The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR, based on user consent. The security of the data transferred outside the EEA is ensured by standard data protection clauses. Further information is available in Typeform’s privacy policy at https://admin.typeform.com/to/dwk6gt.
We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
We utilize Google Analytics to understand how visitors interact with our website. This service collects data such as your IP address, browser type, and pages visited, which are transmitted to and stored by Google on servers that may be located outside the European Union. To protect your privacy, we have enabled IP anonymization, ensuring that Google truncates your IP address within EU member states before transmission. The information gathered helps us analyze website usage and improve our services. For more details on how Google processes this data, please refer to Google's Privacy Policy https://policies.google.com/privacy. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
We are represented on social media networks to present our organization and services. The operators of these networks regularly process their users’ data for advertising purposes. Among other things, they create user profiles from their online behavior, which are used, for example, to show advertising on the pages of the networks and elsewhere on the Internet that corresponds to the interests of the users. To this end, the operators of the networks store information on user behavior in cookies on the users’ computers. Furthermore, it cannot be ruled out that the operators merge this information with other data. Users can obtain further information and instructions on how to object to processing by the site operators in the data protection declarations of the respective operators listed below. It is also possible that the operators or their servers are located in non-EU countries, so that they process data there. This may result in risks for users, e.g., because it is more difficult to enforce their rights or because government agencies access the data. If users of the networks contact us via our profiles, we process the data provided to us to respond to the inquiries. This is our legitimate interest, so the legal basis is Art. 6 para. 1 s. 1 lit. f GDPR.
We maintain a profile on Facebook. The operator is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://www.facebook.com/policy.php. A possibility to object to data processing arises via settings for advertisements: https://www.facebook.com/legal/terms/information_about_page_insights_data. Data subjects can exercise their rights both against us and against Facebook. However, according to our agreement with Facebook, we are obliged to forward requests to Facebook. Data subjects will therefore receive a faster response if they contact Facebook directly.
We maintain a profile on Instagram. The operator is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://help.instagram.com/519522125107875.
We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy is available here: https://www.linkedin.com/legal/privacy-policy?_l=de_DE. One way to object to data processing is via the settings for advertisements: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
We reserve the right to change this privacy policy with effect for the future. A current version is always available here. We will notify users of any significant changes, especially if they affect how data is processed.
The content and works created by the site operators on these pages are subject to German copyright law. Duplication, processing, distribution, or any form of commercialization of such material beyond the scope of copyright law shall require the prior written consent of its respective author or creator. Downloads and copies of this site are only permitted for private, non-commercial use. Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is identified as such. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. We will remove such content immediately if we become aware of any infringements.
If you have any questions or comments regarding this privacy policy, please feel free to contact us using the contact information provided above.