Privacy Notices for hkcmglobal.com
(hereinafter referred to as the “Privacy Notices”)
We are pleased that you are visiting our website www.hkcmglobal.com (hereinafter also referred to as the “Website”) and thank you for your interest in our company and our services. Protecting your privacy when using our Website is important to us.
We would like to provide you with the following information regarding the processing of your personal data and your rights as a data subject in connection with the use of our Website:
HKCM GLOBAL GmbH & Co. KG
Turmstraße 30
6312 Steinhausen
Switzerland
E-mail: datenschutz@hkcm.com
Legal notice: www.hkcmglobal.com/legal-notice
(hereinafter also referred to as “we” or “HKCM GLOBAL”)
as controller within the meaning of data protection law and, at the same time, as service provider.
Your personal data are processed exclusively within the framework of the statutory provisions of European Union data protection law, in particular the EU General Data Protection Regulation (hereinafter “GDPR”), and additionally the German Federal Data Protection Act (hereinafter “BDSG”), as well as other statutory data protection provisions.
The terminology used, such as “personal data” or “processing”, corresponds to the definitions in Art. 4 GDPR. If you would like to take a look at the GDPR or the BDSG yourself, you can find them online at: eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32016R0679 and www.gesetze-im-internet.de/bdsg_2018/.
These Privacy Notices do not apply to other websites operated by us or to third-party websites linked from the Website. Please therefore consult the privacy notices provided there, where applicable. We may also provide you with further privacy notices in other situations involving contact or data processing, which you should likewise take note of where applicable.
1. Subject Matter of Data Protection, Categories of Data and Sources
The subject matter of data protection is the protection of personal data. Personal data are any information relating to an identified or identifiable natural person (a data subject).
We regularly process the following categories of data relating to you:
• Master data, in particular surname, first name, form of address and postal address.
• Contact data, in particular your e-mail address and telephone number.
• Contract data, in particular data arising in connection with your orders.
• Invoice/payment data, in particular information on your method of payment and other data relating to the relevant payment processing and invoicing.
• Content data, in particular your text entries in free-text fields and data contained in correspondence between you and us.
• Usage data, in particular the pages of our Website you visit, access times, your IP address and information in cookies.
Your personal data originate from you, in particular from the information you provide, your orders and your use of our Website.
2. Processing Purposes and Legal Bases
We process your data only for specified purposes and to the extent permitted by an applicable legal provision. We will process your data for the following purposes and on the following legal bases:
• Performance of a contract or implementation of pre-contractual measures (Art. 6(1)(b) GDPR): In particular, we process your personal data in order to carry out and administer your orders on our Website.
• Compliance with a legal obligation (Art. 6(1)(c) GDPR): In addition, we process your personal data to comply with statutory obligations, such as commercial and tax-law retention obligations.
• Consent (Art. 6(1)(a) GDPR): We will also process certain data only on the basis of your prior express and voluntary consent. In that case, the specific purposes arise from the content of the relevant declaration of consent. You have the right to withdraw any consent you may have given at any time with effect for the future (see also section 17).
• Safeguarding legitimate interests (Art. 6(1)(f) GDPR): We will also process certain data to safeguard our legitimate interests, for example to provide and operate this Website.
You can find out in section 13 how you can object to such processing and under what conditions we must cease or restrict our processing.
For further details concerning the purposes and legal bases of individual processing operations in connection with our Website, please refer to the explanations in the following sections.
3. Server Log Data
You can generally visit our Website without providing information about yourself. However, the following information about access may be stored when you visit our Website:
• IP address of the requesting device,
• retrieved file,
• HTTP response code,
• the previous website from which you visit the Website (referrer URL),
• date, time and time zone of the server request,
• browser type and version,
• operating system used by the requesting device,
• search term through which the Website was found, for example via Google.
We process this usage data on the basis of Art. 6(1) sentence 1(f) GDPR in order to provide the Website, ensure technical operation and safeguard the security of our information technology systems. In doing so, we pursue the interest of enabling and permanently maintaining the use and technical functionality of our Website. These data are processed automatically when our Website is accessed. You cannot use our Website without this provision. We do not use these data to draw conclusions about your identity.
The data collected automatically are generally deleted after 7 days, unless we exceptionally require them for the purposes stated above for a longer period. In such a case, we delete the data without delay once the purpose no longer applies.
As the collection and storage of your server log data are essential for the smooth operation of the Website, an objection is generally not possible.
4. Cloud Infrastructure / Hosting (AWS)
We operate our platform on the cloud infrastructure of Amazon Web Services (AWS). The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, as the European contracting party of Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA (hereinafter jointly “AWS”).
AWS processes personal data on our behalf as a processor within the meaning of Art. 28 GDPR. We have concluded a corresponding data processing agreement with AWS, which governs compliance with instructions, the security of processing and the rights of data subjects.
We use AWS because it enables the platform to be operated reliably, securely and efficiently. AWS provides the server capacity, database storage, network infrastructure and security functions necessary to ensure that our Website and the underlying applications are available around the clock, load quickly and are protected against attacks. This includes computing power for our applications, databases for your customer data, a global content delivery network for fast loading times, services for sending e-mails (such as booking confirmations), extensive security and encryption mechanisms, and tools for monitoring, logging and automated infrastructure management. Optional functions such as location-based services or speech output are also implemented through AWS.
We rely on two legal bases for the processing of your personal data on this infrastructure. To the extent that processing serves the performance of our contractual obligations to you – namely hosting the platform, storing and processing your customer data in the context of the contractual relationship, and sending transactional e-mails – the legal basis is Art. 6(1)(b) GDPR. To the extent that processing serves the provision of secure, high-performance and stable platform operations, monitoring system security (monitoring, logging, WAF) and internal management, we rely on our legitimate interest pursuant to Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the technical availability, integrity and security of our services and in efficient operational management.
For certain optional functions, we obtain your consent. This concerns, in particular, the sending of promotional e-mails, analytical evaluations and the use of Location Service and Polly, insofar as these go beyond the contractually owed service. Consent is obtained via our consent management tool CCM19 (see section 7.c)) on the basis of Art. 6(1)(a) GDPR. You may withdraw this consent at any time with effect for the future.
The AWS resources we use are located in the Frankfurt (EU) and Zurich (Switzerland) regions. An adequacy decision of the European Commission exists for Switzerland, meaning that processing in Zurich does not constitute a third-country transfer. As AWS Inc. (USA), as the parent company, may technically access the systems, there is a theoretical risk of access from the USA. This is addressed contractually through the EU Standard Contractual Clauses contained in the data processing agreement and through additional technical and organisational measures. No further third-country transfer takes place.
The server log data arising in the course of AWS operations (IP address, access time, accessed resource, HTTP status code, referrer, browser and device information) are processed in accordance with our explanations on server log data (section 3). For usage data stored in individual AWS services (e.g. database content in RDS/DynamoDB, files in S3, messages in SQS/SNS), the retention periods and deletion deadlines stated in the respective substantive sections of these Privacy Notices apply (e.g. order data, contract data, communication data).
AWS is integrated into our TOM concept. This includes AWS’s contractual obligation to comply with data protection requirements, the use of encryption (KMS, TLS), identity and access management (IAM, principle of least privilege), network security (VPC, Security Groups, WAF), continuous monitoring and logging (CloudWatch, CloudTrail), and patch and change management via CloudFormation and Systems Manager.
You may object at any time to processing based on legitimate interests (Art. 21 GDPR). Where processing is based on your consent, you may withdraw it at any time with effect for the future via the cookie banner (CCM19) or by informal notice to datenschutz@hkcmanagement.de.
5. Communication by Contact Form or E-mail
If you communicate with us via contact form or e-mail, the collection, processing and use of the contact data you voluntarily provide (such as name and e-mail address) take place solely for the relevant purpose, either to receive and, where appropriate, answer your enquiry/enquiries and for technical administration. The data you provide via our contact forms are encrypted during transmission using Transport Layer Security (TLS), widely known by its predecessor name Secure Socket Layer (SSL).
Data transmitted in the course of communication by contact form or e-mail are processed pursuant to Art. 6(1)(b) GDPR where this concerns the initiation of a contractual relationship, or pursuant to Art. 6(1)(f) GDPR. In the latter case, we have a legitimate interest in handling contact enquiries voluntarily addressed to us.
We delete the data you provide as soon as the purpose of collection has ceased completely, subject to the fulfilment of continuing statutory retention obligations.
Where your data are processed on the basis of legitimate interests, you may object to the storage of your personal data at any time. In this case, we will no longer process your data unless we can demonstrate compelling legitimate grounds or are otherwise legally obliged to store them. To exercise your right to object to storage, please contact us in writing or by e-mail.
Please note, however, that we cannot guarantee complete data security for communications via the contact form and that communication by e-mail does not take place via a secure data connection. Therefore, please refrain from sending confidential information, such as bank or credit-card data, by these means. We recommend using a secure means of transmission, such as postal mail, to send confidential information.
6. Orders
6.1 Order Processing
In order to enable you to select and order products and pay for them in our portal, we process your data in the course of order transactions. Processing takes place for the purpose of providing contractual services in the operation of our portal, processing orders and providing customer services. When an order is placed via the portal, in particular your master data, contact data and contract data are processed.
Processing takes place on the basis of Art. 6(1)(b) GDPR (performance of order transactions) or Art. 6(1)(c) GDPR, insofar as storage serves to fulfil statutory retention obligations. The information marked as mandatory is required to establish and perform the contract. Without these data, we are unable to perform the contract with you. In addition, you may provide voluntary information that is not required to process the order (e.g. telephone number). We process this information on the basis of Art. 6(1)(f) GDPR because we have a legitimate interest in efficiently handling your enquiries, optimising customer communication and avoiding misdeliveries. You may object to processing of this voluntary information at any time, e.g. by sending a message to datenschutz@hkcm.com.
We disclose data to third parties only in connection with the order, in particular payment processing and delivery, or in the context of statutory rights and obligations. Data are processed in third countries only where this is necessary to perform the contract (e.g. for delivery to a place of delivery outside the EU).
Data you provide in connection with an order are deleted after the expiry of applicable statutory warranty, limitation and retention periods.
6.2 Payment Processing
For payment processing, we work with the providers Worldline Switzerland Ltd., Hardturmstraße 201, CH-8005 Zürich, and PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
For payment processing purposes, your payment data (name of your credit institution, IBAN, BIC, CVV) are transferred to the relevant payment service provider. We do not store your payment data ourselves.
Please therefore note the relevant privacy and security information of the payment service providers:
• Worldline Switzerland Ltd., https://worldline.com/en-ch/compliancy/privacy,
• PayPal (Europe) S.à r.l. et Cie, S.C.A., www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE,
The legal basis for this processing is Art. 6(1)(b) GDPR, as payment processing is necessary for performance of the contract with you.
7. Analysis E-mail / Newsletter Distribution
7.1 Analysis E-mails
Where, as part of providing our services, we send you analyses booked by you by e-mail (“Analysis E-mails”) to the e-mail address stored with us, this takes place for performance of the contract on the basis of Art. 6(1)(b) GDPR. You may deactivate receipt of Analysis E-mails at any time during the term of a subscription via the relevant link at the end of an Analysis E-mail and via our portal. Deactivation of Analysis E-mails does not constitute termination of the relevant subscription. If you would like to receive Analysis E-mails again, you may request them again at any time during the term of a subscription via the portal. Further information on Analysis E-mails can be found in our General Terms and Conditions (https://hkcm.com/agb).
7.2 Newsletter, Lead Magnet Campaigns and Free Content
We offer interested parties the opportunity to request our newsletter and free content (e.g. fundamental analyses, market analyses, newsletter specials or comparable information offers; hereinafter jointly the “Newsletter”) via our Website, landing pages and marketing platforms used by us.
To subscribe to our Newsletter, it is sufficient to provide the mandatory information marked with (*). This generally includes name, e-mail address and country. In addition, you may be able to provide further voluntary information that helps us select and design the Newsletter in a manner appropriate to your interests.
For Newsletter distribution, we use the double opt-in procedure, i.e. we will send you a Newsletter by e-mail only after you have expressly confirmed that we should activate the Newsletter service. We will send you a notification e-mail and ask you to confirm, by clicking a link contained in that e-mail, that you wish to receive our Newsletter. By completing this separate double opt-in procedure, you give your consent to receive the Newsletter.
We send Newsletters only following the relevant registration, i.e. with your consent on the basis of Art. 6(1)(a) GDPR. Recourse to other legal bases remains expressly reserved. Where the contents of a Newsletter are specifically described in connection with registration, these are decisive for the scope of consent. Otherwise, our Newsletters contain information on our products, offers, campaigns and our company.
If you no longer wish to receive Newsletters from us later, you may withdraw your consent at any time. A notice in text form (e.g. e-mail, letter) sent to the contact details stated above or to info@hkcm.com is sufficient for this purpose. Naturally, every Newsletter also contains an unsubscribe link.
7.3 Distribution Service Provider
Analysis E-mails, Newsletters and other transactional and promotional e-mails (hereinafter jointly “E-mails”) are sent using the distribution service provider Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, subsidiary of SendinBlue SAS, 17 rue de Salneuve, 75017 Paris, France; hereinafter “Brevo”). The data processing takes place on our behalf on the basis of a data processing agreement we have concluded with Brevo. Under it, Brevo undertakes to protect our users’ data, process them only on our behalf and, in particular, not disclose them to third parties.
You can view Brevo’s privacy policy here: https://www.brevo.com/legal/privacypolicy/.
Brevo processes your data for two main purposes. First, to send transactional E-mails, i.e. booking confirmations, cancellation confirmations, updates to your subscription and access data. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). These E-mails are necessary for the performance of our contractual obligations; withdrawal is not possible in this respect. Second, to send promotional E-mails, i.e. newsletters, campaign-specific promotional e-mails, prize notifications (e.g. discount codes, free subscriptions) and other marketing communications. The legal basis for this is your consent pursuant to Art. 6(1) sentence 1(a) GDPR, which you have given as part of the double opt-in procedure or via our cookie banner (CCM19).
In connection with E-mail distribution, Brevo processes the following categories of data on our behalf: e-mail address, name, customer number, contract data (subscription type, term, status), opening and click data (tracking), IP address (when tracking pixels are retrieved), and device and browser information.
The E-mails contain web beacons or tracking pixels (one-pixel image files) that make it possible to track your user behaviour – in particular whether you have opened the E-mail and which links you have clicked. Brevo may also carry out conversion tracking, i.e. determine whether a desired action takes place after a link is clicked. Technical information such as retrieval time, IP address, browser and operating-system data is collected pseudonymously. Direct personal identification is thereby excluded. Tracking is not possible if you have disabled the display of images by default in your e-mail program.
Brevo hosts its systems in the European Union (France). Where access from third countries occurs in the course of support or maintenance activities, Brevo ensures an adequate level of data protection through EU Standard Contractual Clauses and additional technical and organisational measures.
Data based on your consent (promotional E-mails, Newsletter) are stored until you withdraw your consent. You may withdraw your consent to promotional E-mails at any time with effect for the future – via the unsubscribe link in every E-mail, our cookie banner (CCM19), or informal notice to us. The lawfulness of processing carried out before withdrawal remains unaffected.
7.4 HubSpot (CRM and Marketing Automation)
We use HubSpot (HubSpot Ireland Ltd., 2nd Floor, 30 North Wall Quay, Dublin 1, Ireland; HubSpot Inc., 25 First Street, Cambridge, MA 02141, USA; hereinafter “HubSpot”) as a customer relationship management system (CRM) and for marketing automation. HubSpot processes personal data on our behalf on the basis of a data processing agreement concluded with HubSpot.
You can view HubSpot’s privacy notices here: https://legal.hubspot.com/privacy-policy.
HubSpot processes your data for three main purposes. First, to send our Newsletter and targeted marketing campaigns by e-mail. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Second, for marketing automation, lead scoring and profiling, i.e. to analyse your interactions with our E-mails and our Website in order to create user profiles, lead scores and segments for interest-based communications. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Third, for CRM synchronisation and customer administration, i.e. to store and manage your master data (name, e-mail address), contract data (subscription type, term, status), usage data (login activities) and marketing data (segmentations, campaign assignments) for internal customer support and contract administration. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR in efficient customer administration and contract processing.
HubSpot processes the following categories of data on our behalf: master data (name, e-mail address, customer number), contract data (subscription type, term, status), usage data (login activities, Website interactions), marketing data (opening and click rates, form entries, lead scores, segmentations, lifecycle stages), technical data (IP address, browser/device information, cookie IDs).
HubSpot Ireland Ltd. is our processor. HubSpot uses sub-processors (e.g. cloud hosting providers) that are contractually obliged to comply with data protection requirements.
HubSpot Inc. (USA) is the parent company of HubSpot Ireland Ltd. and may have access to personal data in the context of support, development and operation. The transfer to the USA takes place on the basis of the EU-US Data Privacy Framework (European Commission adequacy decision). Despite these safeguards, residual risks due to US surveillance laws cannot be entirely excluded.
You may withdraw your consent to Newsletter distribution at any time with effect for the future via our cookie banner (CCM19), the unsubscribe link in marketing E-mails or by informal notice to us. You may also object at any time to processing based on legitimate interests (CRM administration).
8. Cookies
The Website uses cookies and similar technologies, such as HTML5 Storage (hereinafter jointly “Cookies”), in order to optimise the Website. This facilitates, among other things, navigation and a high degree of user-friendliness.
Cookies are small identifiers that our web server sends to your browser and that your device stores under the corresponding standard setting. They can be used, among other things, to determine whether there has already been communication with us from your device. They therefore serve to make use more convenient for you and to optimise our offering. This processing takes place on the basis of Art. 6(1)(f) GDPR with regard to strictly necessary Cookies and on the basis of Art. 6(1)(a) GDPR if you consent to the storage and use of additional first-party Cookies or third-party Cookies. Personal data may then be stored in Cookies if this is technically strictly necessary or you have consented.
When you use our Website, you may give us your consent to use and store additional first-party Cookies or third-party Cookies on your device. You may withdraw consent previously given to the use and storage of Cookies at any time with effect for the future by disabling the Cookie settings described below for additional first-party Cookies (section 8.b)) and third-party Cookies (section 8.c)).
You may also select “do not accept cookies” in your browser settings (including with respect to strictly necessary Cookies). Please refer to your browser’s help function for procedures for technically managing and deleting Cookies in your browser settings.
In addition, you can technically prevent the storage and use of all Cookies using free browser add-ons such as “Adblock Plus” (adblockplus.org/de) in combination with the “EasyPrivacy” list (easylist.to).
However, preventing the storage of all Cookies may lead to functional restrictions of the Website.
a) Strictly Necessary Cookies
The technical structure of the Website requires us to use technically necessary Cookies. Without these technologies, our Website may not be displayed fully correctly or support functions may not be possible. You cannot deselect these Cookies if you wish to use our Website. The legal basis for this processing is our legitimate interest in the functionality of the Website pursuant to Art. 6(1)(f) GDPR.
We use the following Cookies that are strictly necessary for the functionality of our Website:
Name Function/Purpose Storage Period
N User login Until logout
.AspNetCore.MyCookie AuthenticationScheme User can access subdomain Until logout
Cookieconsent_status Cookie banner on homepage 2 years
You can disable strictly necessary Cookies only technically via your browser settings or browser add-ons. This may lead to functional restrictions of the Website.
b) Third-Party Cookies
We use various categories of Cookies only after you have given your consent. You can select the desired Cookies via the cookie banner when visiting our Website. The functions are activated only if you consent and may serve, in particular, to analyse and improve visits to our Website, make it easier for you to use the Website across browsers or devices, recognise you on a subsequent visit, or display advertising (including to tailor advertising to your interests and measure the effectiveness of advertisements). The legal basis for this processing is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Name Function/Purpose Third Party Storage Period
1P JAR Daytime Picker and Bootstrap Java Gstatic.com 1 year
CONSENT Java Script Gstatic.com 1 year
_gat Google Analytics Google.com Max. 15 days
_gatgtag UA_*** Google Analytics Google.com Max. 15 days
gid Google Analytics Google.com Max. 15 days
_gcl_au Library for displaying content Cloudflare.com 14 days
__cfduid Library for displaying content Cloudflare.com 6 months
__stripe_mid Fonts Fontawesome.com 1 year
__utmx Fonts Fontawesome.com 1 year
_utmxx Fonts Fontawesome.com 1 year
_ga Google Analytics from Fontawesome Fontawesome.com 2 years
_ga Google Analytics from Cloudflare Cloudflare.com 2 years
_ga Google Analytics HKCM Google.com 2 years
c) Consent Management Tool
We use CCM19, a consent management tool (hereinafter “CCM19”) of Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn, on our Website. We use CCM19 to request consent for the processing of your device information and personal data by means of Cookies or other technologies. When CCM19 is used, personal data and device information are processed by us, in particular your IP address for the technical delivery of a GDPR-compliant cookie banner.
The legal basis for processing is Art. 6(1)(c) GDPR insofar as processing serves to fulfil statutory verification obligations for granting consent. Otherwise, we have a legitimate interest in providing an attractive, user-friendly and GDPR-compliant cookie banner in order to obtain appropriate consent from our users to set Cookies and process personal data.
Information about the settings you select is stored on your device. Your settings and personal data are deleted after 12 months unless you first delete the information about your user settings yourself in your browser.
Your data are also transmitted to CCM19. We have concluded a data processing agreement with CCM19 by which we oblige the service provider to protect your data and not disclose them to third parties.
You can view CCM19’s privacy policy here: https://www.ccm19.de/datenschutzerklaerung.html.
9. Web Analytics / Google Analytics / Sentry
a) Google Analytics
Provided that you have consented to the use and storage of third-party Cookies, we use Google Analytics, a web analysis service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics uses Cookies. The information generated by the Cookie about your use of our Website is generally transferred to and stored on a Google server in the USA. The legal basis is Art. 6(1)(a) GDPR, as processing takes place on the basis of your consent. The collected information is stored on Google servers, including in the USA. For these cases, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission. We have also concluded Standard Contractual Clauses with Google, the purpose of which is to ensure an adequate level of data protection in the third country. The specific retention period for processed data is not influenced by us, but is determined by Google Ireland Limited. Further information can be found in the privacy notices for Google Analytics: https://policies.google.com/privacy.
On our behalf, Google will use this information to evaluate your use of the Website, compile reports on Website activity and provide us with other services associated with Website use and Internet use. Pseudonymous usage profiles may be created from the processed data.
We use Google Analytics only with IP anonymisation activated. This means that users’ IP addresses are truncated by Google within Member States of the European Union (EU) or other contracting states to the Agreement on the European Economic Area (EEA). Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there. The IP address transmitted by your browser is not combined with other Google data.
The data are deleted as soon as they are no longer required for our recording purposes. In our case, this is generally after 6 weeks.
Data processing associated with Google Analytics takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR. If you do not wish Cookies to be stored by Google Analytics on your device, you may refuse or withdraw your consent in our cookie banner. You may also disable the relevant option in your browser’s system settings. You can delete stored Cookies at any time in your browser’s system settings.
You can also technically prevent the storage and use of Cookies through appropriate browser settings or browser add-ons.
Furthermore, you can prevent Google from collecting the data generated by the Cookie and relating to your use of the Website (including your IP address), and from further processing those data, by downloading and installing the browser plug-in available at the following link: tools.google.com/dlpage/gaoptout?hl=de.
Further information about Google’s use of data, settings and objection options can be found on Google’s websites at the following links:
• www.google.com/intl/de/policies/privacy/partners (“How Google uses data when you use our partners’ sites or apps”),
• www.google.com/policies/technologies/ads (“Advertising”),
• www.google.de/settings/ads (“Manage the information Google uses to show you ads”).
b) Sentry
We use the error-management tool “Sentry” for our Website. The provider of this service is Functional Software, Inc., 132 Hawthorne Street, San Francisco, CA 94107, USA.
Functional Software processes the following data: IP address, browser / device / OS name, e-mail (optional), error log, error recording (abstract activity log), geo-location, timestamp, language: user’s language setting (e.g., en-US). Processing serves to identify and remedy technical errors on our Website. The legal basis for this is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Functional Software processes data, including in the USA. Data are transferred on the basis of the EU-US Data Privacy Framework and the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR), which are intended to ensure that your data are also adequately protected in third countries. Further information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
Please note that despite these measures, residual risks may exist, in particular with regard to access rights of US authorities.
Further information on processing by Functional Software can be found in its privacy policy: Privacy Policy 3.3.1 (May 31, 2024).
10. Other Third-Party Services and Content
We use third-party plug-ins on our Website to integrate their content and services, such as fonts (hereinafter jointly “Content”). Your data are processed on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in the economic operation, optimisation (in particular user-friendliness) and usage analysis of our Website, as well as ensuring the security of our technical systems.
The third-party providers of this Content always receive knowledge of your IP address, because without the IP address they could not transmit the Content to your device. The IP address is necessary to display the Content. Third-party providers may also place Cookies on your device if you have consented to the use and storage of third-party Cookies.
You may withdraw any consent you have given to the storage and use of Cookies for the following services by disabling “Third-Party Cookies” (see section 8.c) above). You can also technically prevent the storage and use of Cookies through appropriate browser settings or browser add-ons.
a) Google Fonts
We integrate Google Fonts (typefaces) of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, into our Website. Further information on Google’s use of data, settings and objection options can be found on Google’s websites at the links listed in section 8. The collected information is stored on Google servers, including in the USA. For these cases, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
b) Google Maps
We use Google Maps on this Website. This enables us to display interactive maps directly on the Website and allows you to use the map function conveniently.
By displaying the interactive map, Google receives the information that you have accessed the relevant subpage of our Website. Basic data such as IP address and timestamp are also transmitted. This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data are directly allocated to your account. Google stores your data as usage profiles and uses them for advertising, market research and/or demand-oriented design of its Website. Such analysis is carried out in particular (even for users who are not logged in) to provide demand-oriented advertising and to inform other users of the social network about your activities on our Website.
Legal bases and control options: The legal basis for displaying the interactive map is Art. 6(1)(a) GDPR, i.e. integration takes place only after your consent. If you do not want your data to be transmitted to Google, you can refuse or withdraw your consent in our cookie banner. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. The easiest way to withdraw consent is also via our cookie banner.
If you do not want collected data to be allocated to your profile with Google, you must log out before visiting the Website. You also have a right to object to the creation of usage profiles; to exercise it, you must contact Google, e.g. at https://about.google/contact-google/. Detailed instructions on managing your own data in connection with Google products can be found at https://support.google.com/accounts/answer/3024190.
The collected information is stored on Google servers, including in the USA. For these cases, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
Further information on the purpose and scope of data collection and processing by Google can be found in Google’s privacy notices. There you will also find further information on your rights in this respect and settings options for protecting your privacy: www.google.de/intl/de/policies/privacy.
c) Content Delivery Network by BunnyCDN
We use a “Content Delivery Network” (CDN) offered by BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia.
A CDN is a service by means of which content from our online offering, in particular large media files such as graphics or scripts, is delivered more quickly with the help of regionally distributed servers connected via the Internet. Users’ data are processed solely for the aforementioned purposes and to maintain the security and functionality of the CDN.
Processing takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR in high-performance, secure and stable provision of our online services. Our legitimate interest lies in optimising loading times, reducing the load on origin servers and increasing availability.
BunnyCDN operates a global CDN with servers including in the USA, Singapore and Brazil. It cannot be technically excluded that personal data (in particular IP addresses and technical connection data) may also be processed via servers outside the EU/EEA during delivery. The data processing agreement therefore contains EU Standard Contractual Clauses for sub-processors in third countries and additional technical and organisational measures to ensure an adequate level of protection.
Further information can be found in BunnyWay’s privacy policy: https://bunny.net/privacy/
d) Bunny Stream
For delivery of our own video content (course videos, analyses, tutorials), we use Bunny Stream (also BunnyWay d.o.o., Slovenia). Bunny Stream stores our video files, converts them into various quality levels and delivers them directly to your device through a worldwide server network. As a result, videos start faster, play without interruption and automatically adapt to your Internet speed – regardless of where you are located. Our own servers are relieved, and you receive the best possible playback quality.
In doing so, we process your IP address, information about your device and browser, and data concerning video use – such as which video you access, at which point you play or pause it, how long you watch and which quality level is selected. For videos that are part of your booked subscription, processing takes place to perform our contract (Art. 6(1)(b) GDPR). For freely accessible videos, we rely on our legitimate interest in high-performance, secure and stable provision of video content.
As with BunnyCDN, delivery takes place via the global edge network. A third-country transfer therefore takes place. It cannot be technically excluded that personal data may also be processed through servers outside the EU/EEA. The data processing agreement therefore contains EU Standard Contractual Clauses for sub-processors in third countries and additional technical and organisational measures to ensure an adequate level of protection.
e) YouTube
We have embedded YouTube videos on our Website, which are hosted by YouTube but can be played directly from our Website. All are embedded in “enhanced privacy mode”, i.e. according to YouTube, playing a video is not used to personalise advertising to the user. However, we have no influence over this.
To increase the protection of your data when visiting our Website, videos are initially deactivated and embedded in the page using a so-called “two-click” solution. This integration ensures that when a page of our web presence containing such videos is accessed, no connection to Google servers is yet established. Only when you activate the videos does your browser establish a direct connection to Google servers.
By activating the video, YouTube receives the information that you have accessed the relevant subpage of our Website. Basic data such as IP address and timestamp are also transmitted. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged in to Google, your data are directly allocated to your account. YouTube stores your data as usage profiles and uses them for advertising, market research and/or demand-oriented design of its Website. Such analysis is carried out in particular (even for users who are not logged in) to provide demand-oriented advertising and to inform other users of the social network about your activities on our Website.
The legal basis for displaying the videos is Art. 6(1)(a) GDPR, i.e. integration takes place only after your consent. If you do not want Cookies to be stored by YouTube on your device, you may refuse or withdraw your consent.
If you do not want collected data to be allocated to your profile with YouTube, you must log out before activating the video. You also have a right to object to the creation of user profiles by YouTube; to exercise it, you must contact YouTube or Google, e.g. at https://about.google/contact-google/. Detailed instructions on managing your own data in connection with Google products can be found at https://support.google.com/accounts/answer/3024190.
The collected information is stored on Google servers, including in the USA. For these cases, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
Further information on the purpose and scope of data collection and processing by YouTube can be found in Google’s privacy policy. There you will also find further information on your rights and settings options for protecting your privacy: www.google.de/intl/de/policies/privacy.
f) TradingView
We have embedded TradingView charts on our Website, which are hosted by TradingView but can be played directly from our Website.
To increase the protection of your data when visiting our Website, charts are initially deactivated and embedded in the page using a so-called “two-click” solution. This integration ensures that when a page of our web presence containing such charts is accessed, no connection to TradingView servers is yet established. Only when you activate the charts does your browser establish a direct connection to TradingView servers.
By activating the chart, TradingView receives the information that you have accessed the relevant subpage of our Website. Basic data such as IP address and timestamp are also transmitted. This occurs regardless of whether TradingView provides a user account through which you are logged in or whether no user account exists. If you are logged in to TradingView, your data are directly allocated to your account. TradingView stores your data as usage profiles and uses them for advertising, market research and/or demand-oriented design of its Website. Such analysis is carried out in particular (even for users who are not logged in) to provide demand-oriented advertising and to inform other users of the social network about your activities on our Website.
The legal basis for displaying the charts is Art. 6(1)(a) GDPR, i.e. integration takes place only after your consent. If you do not want Cookies to be stored by TradingView on your device, you may refuse or withdraw your consent.
If you do not want collected data to be allocated to your profile with TradingView, you must log out before activating the chart. You also have a right to object to the creation of user profiles by TradingView; to exercise it, you must contact TradingView.
The collected information is stored on TradingView servers, including in the USA. We have concluded Standard Contractual Clauses with TradingView, the purpose of which is to ensure an adequate level of data protection in the third country.
Further information on the purpose and scope of data collection and processing by TradingView can be found in TradingView’s privacy policy. There you will also find further information on your rights and settings options for protecting your privacy: https://de.tradingview.com/privacy-policy/
g) n8n
We use the n8n software on our platform for process automation and system integration. n8n is operated as an on-premise installation on our own servers at Hetzner Online GmbH in Germany. Personal data therefore do not leave our controlled system environment; the software manufacturer has no access to the processed data. We are the sole controller in this respect.
n8n is used to automate essentially two types of processes. First, we synchronise customer and usage data in HubSpot. In doing so, we transmit master data such as name, e-mail address and customer number; contract and subscription data such as tariff, term and status; usage data such as login activities; and marketing and CRM data such as segmentations, campaign assignments and contact characteristics from our platform to HubSpot (see the detailed information on HubSpot above under section 7.d)) in order to use these there for customer relationship management, marketing automation and Newsletter distribution. Second, certain customer actions – such as concluding a subscription, cancellation or inactivity – trigger business processes. These include sending booking or cancellation confirmations through Brevo (SendinBlue SAS, Paris), activating free subscriptions or adjusting service content.
In the course of these processes, we process the following categories of personal data: master data (surname, first name, e-mail address, customer number), contract and subscription data (product type, term, status, payment information where necessary for the process), usage data (login times, activity information, in-app interactions), and marketing and CRM data (segment memberships, lead scores, lifecycle stages, campaign assignments, opening and click rates).
The legal basis depends on the respective processing purpose and is assigned on a process-specific basis. For transactional processes required to perform our contractual obligations – in particular the sending of booking confirmations, cancellation confirmations, access data and other transactional e-mails via Brevo, as well as activation of booked services – we rely on Art. 6(1)(b) GDPR (performance of a contract). For internal administrative synchronisations in which we mirror customer data from the platform into HubSpot to ensure efficient customer administration, contract processing and internal management, we rely on our legitimate interest pursuant to Art. 6(1)(f) GDPR. Our legitimate interest lies in a structured, up-to-date and cross-system consistent data basis for customer service, billing and compliance. For marketing-related data flows to HubSpot, insofar as these serve profiling, lead scoring, segmentation for advertising purposes or the distribution of Newsletters and promotional campaigns, we obtain your consent pursuant to Art. 6(1)(a) GDPR. Consent is obtained via our consent management tool CCM19 (see section 8.c)). You may withdraw this consent at any time with effect for the future – via the cookie banner (CCM19), the unsubscribe link in marketing E-mails or by informal notice to us.
Within the n8n workflows, data are transmitted to HubSpot (see section 7.d)) and Brevo (see section 7.c)).
n8n itself does not carry out a third-country transfer, as the software is hosted on-premise in Germany (Hetzner, Nuremberg/Falkenstein). For downstream recipients HubSpot and Brevo, the transfer mechanisms and safeguards described in the relevant sections of these Privacy Notices apply.
The n8n instance is integrated into our TOM concept. This includes n8n’s contractual obligation to comply with data protection requirements, use of encryption (KMS, TLS), identity and access management (IAM, principle of least privilege), network security (VPC, Security Groups, WAF), continuous monitoring and logging (CloudWatch, CloudTrail), and patch and change management via CloudFormation and Systems Manager.
Every workflow implemented in n8n is maintained as a separate entry in our record of processing activities pursuant to Art. 30 GDPR, stating purpose, data categories, recipients, legal basis, retention period and technical safeguards.
You may object at any time to processing based on legitimate interests (Art. 21 GDPR) and withdraw your consent to marketing-related data flows (HubSpot synchronisation for advertising purposes, Newsletter) at any time with effect for the future (Art. 7(3) GDPR) – via the cookie banner (CCM19), the unsubscribe link in marketing E-mails or by informal notice to datenschutz@hkcm.com.
h) Push Notifications
We use the OneSignal service (OneSignal, Inc., 2850 S. Delaware St., San Mateo, CA 94403, USA) on our Website to send push notifications. This enables us, where you have consented, to display notices directly on your device, for example when new analyses are available, your subscription is renewed or we wish to draw your attention to interesting content.
For OneSignal to function, a push token (a device- or browser-specific identifier) is stored on your device when you consent. OneSignal also processes your IP address, browser and device information, the time of delivery and the content of the relevant notification. Where you have consented in our consent management tool CCM19 (see section 7.c)) to the use of push notifications, processing takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR (for data processing) and § 25(1) TDDDG (for access to your device). You may withdraw this consent at any time with effect for the future – via the cookie banner (CCM19) or by informal notice to us. Notifications already delivered cannot technically be recalled, but further dispatch will cease from withdrawal.
Where push notifications serve exclusively to perform our contract (for example, information about provision of a booked analysis or a cancellation confirmation), we additionally rely on Art. 6(1)(b) GDPR (performance of a contract). However, access to the device is also permissible here only with your consent pursuant to § 25(1) TDDDG, which we likewise obtain through CCM19.
OneSignal acts as our processor on the basis of a data processing agreement concluded with us. OneSignal is based in the USA. Personal data are transferred to the USA on the basis of the EU-US Data Privacy Framework, under which OneSignal is certified. Despite these safeguards, residual risks due to US surveillance laws cannot be entirely excluded.
i) LiveChat
We use the LiveChat live-chat service (LiveChat, Inc., One International Place, Suite 1400, 100 Oliver Street, Boston, MA 02110, USA; hereinafter “LiveChat”) on our Website to provide you with a direct communication channel for support enquiries, product questions and general information. When you use the chat, we process the following data: chat history (your messages and our replies), your IP address, browser and device information, time of the conversation, geolocation (country/city based on IP), referrer URL (the page from which you started the chat), and – where you voluntarily provide them in the chat – further content data (e.g. name, e-mail address, customer number, order details). No automatic or manual combination of these chat data with existing customer or prospect profiles in our CRM system (e.g. HubSpot) takes place; in particular, chat data are not assigned to existing profiles for the purposes of creating a comprehensive customer or user profile.
Processing of the above data in connection with LiveChat is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR, namely ensuring the best possible, efficient and secure customer service and answering your enquiries in real time. Where access to your device by means of Cookies or similar technologies is required, we base this access on § 25(1) TDDDG in conjunction with your relevant consent via our consent management tool CCM19 (category “Support / Live Chat”, see section 7.c)). You may object at any time, pursuant to Art. 21 GDPR, to processing of your personal data based on Art. 6(1)(f) GDPR; in that case, live chat may not be available to you or may be available only to a limited extent. You may also withdraw any consent given (in particular for device access) at any time with effect for the future via the cookie banner (CCM19).
LiveChat processes data as our processor on the basis of a data processing agreement concluded with us. LiveChat is based in the USA. Personal data are transferred to the USA on the basis of the EU-US Data Privacy Framework, under which LiveChat (Text, Inc.) is certified. Despite these safeguards, residual risks due to US surveillance laws cannot be entirely excluded. Further information on processing by LiveChat can be found in LiveChat’s privacy notices: https://www.livechat.com/legal/privacy-policy/.
11. Marketing Services and Functions on Our Website
a) Profiling for Advertising Purposes
If we collect personal data from you in the course of visiting the Website (e.g. IP address or data you provide in the contact form), such data may be stored in a profile for advertising purposes. We may combine such data with further information that we obtain indirectly (in particular through your use of the contact form).
We store the data collected from you in order to offer you content tailored to your interests on the Website and in our Newsletter, and to provide you with news and information about our company or service offering that are of interest to you on the basis of your data and tailored to your individual interests. For this purpose, it is technically necessary for us to combine your generated and provided data in usage profiles and evaluate them for the aforementioned purposes. This takes place internally and only for the aforementioned purposes.
The legal basis for profiling for advertising purposes is our legitimate interest in analysing and statistically evaluating the use of our Website, optimising our Website and providing offers and content that are as interest-appropriate as possible. We have carefully balanced these legitimate interests against your interests and fundamental rights and freedoms as a user and concluded that consent is not required and that data processing in the context of profiling for advertising purposes is permissible on the basis of Art. 6(1)(f) GDPR.
Decisive in this respect is the fact that we generally use only basic identifiers, such as location, which we obtain via the IP address; we may combine these basic identifiers with your usage behaviour on the Website, which we collect with Google Analytics, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Only when you provide us with further information and, in particular, enter into a (business) relationship with us via the contact form do we store further identifiers in a profile about you and may also combine them with your usage behaviour in Newsletters and e-mailings. However, no direct conclusions or legal consequences are ever derived for you from processing in connection with profiling for advertising purposes, for example regarding creditworthiness. Nor are you denied any services.
It must also be taken into account that we do not use information from external data sources (such as information from social networks) for profiling and do not use automated selection procedures to create behavioural predictions about you.
Acceptance of profiling is not mandatory; if you wish to prevent profiling, you can refuse the setting of Google Analytics Cookies in our cookie banner. You can also prevent profiling by Google using the following link: https://tools.google.com/dlpage/gaoptout.
The stored information is transferred to and stored on a Google server. On our behalf, Google uses this information to compile a profile about users. Data collected for profiling may be stored by us in our customer relationship management (CRM) system and in the data warehouse.
Further information on data protection in connection with the use of Google Analytics can be found here: https://support.google.com/analytics/answer/6004245?hl=de.
b) Advertising with Meta (Facebook Pixel and Conversion Tracking)
The Website also uses advertising measures of Meta (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). By integrating the “Facebook Pixel” on our Website, we can display our advertising measures (“Ads”) to users of our Website and the Facebook social network and measure and evaluate their success (“conversion tracking”). This connection is technically established via the “Facebook Pixel”.
We also use the “Custom Audiences” remarketing function, which likewise uses the Facebook Pixel and displays interest-based advertisements when you visit our Website or other websites that have also embedded the Facebook Pixel. This enables us to show you advertising that may be of interest to you, to make our Website more interesting to you and to market our offering.
Due to the marketing tools used, your browser establishes a direct connection with Meta’s server when you visit our Website – after you have given your consent. We have no influence on the scope and further use of the data collected by Meta through the use of this tool and therefore present the processes known to us: By integrating the Facebook Pixel, Meta receives the information that you have accessed the relevant webpage of our Internet presence or clicked one of our advertisements. If you are registered with a Meta service, Meta can allocate the visit to your account. Even if you are not registered with the Facebook platform or are not logged in, it is possible that the provider may obtain your IP address and other identifiers and use them for profiling.
The legal basis for processing your data is Art. 6(1)(a) GDPR, i.e. integration takes place only after you have given your consent. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. The easiest way to withdraw consent is via our cookie banner. In addition, logged-in users can object directly with the provider or via the following link: www.facebook.com/settings/?tab=ads#_. You may also disable the relevant option in your browser’s system settings. You can delete stored Cookies at any time in your browser’s system settings.
Your data are stored as long as they are required for the respective purpose or until you object to storage of your data or withdraw your consent.
The collected information is stored on Meta servers, including in the USA. For these cases, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission. We have also concluded Standard Contractual Clauses with Meta, the purpose of which is to ensure an adequate level of data protection in the third country.
Further information on processing by Meta can be found at: www.facebook.com/about/privacy.
c) TikTok Ads
We use the TikTok Advertising service (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and, where applicable, other companies affiliated with TikTok) on our Website and in connection with our presence on TikTok to draw attention to our offers through advertisements and optimise them. When our Website is accessed and/or our TikTok profile is visited, TikTok uses – after you have given your consent – Cookies and similar technologies (e.g. pixels, tags) to collect and evaluate information about your use of our Website or your interaction with our content on TikTok. This includes, in particular, information as to whether you have viewed or clicked an advertisement and which subsequent actions (e.g. accessing certain pages, registration, enquiry) have occurred. On this basis, TikTok can display personalised, interest-based advertisements to users, and we can statistically evaluate the reach and effectiveness of our advertising campaigns.
TikTok delivers advertising materials via so-called “ad servers”. For this purpose, we and other websites use ad server Cookies through which certain parameters for measuring success, such as display of advertisements or clicks by users, can be measured. Through the TikTok Ads Cookies stored on our Website, we can receive information about the success of our advertising campaigns. We cannot personally identify you through these Cookies. As analysis values, the Cookie generally stores the unique Cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions), and opt-out information (indicating that a user no longer wishes to be addressed). Cookies set by TikTok enable TikTok to recognise your Internet browser or device. If a user visits certain pages of an Ads customer and the Cookie stored on the user’s computer has not expired, TikTok and we can recognise that the user clicked the advertisement and was redirected to that page. A different Cookie is allocated to each Ads customer, so Cookies cannot be tracked across other Ads customers’ websites. By integrating TikTok Ads, TikTok receives the information that you have accessed the relevant part of our profile or clicked one of our advertisements. If you are registered with TikTok, TikTok can allocate the visit to your account. Even if you are not registered with TikTok or are not logged in, it is possible that the provider may obtain and store your IP address.
The legal basis for integrating TikTok Advertising, the associated storage and reading of information on your device, and the subsequent processing of personal data is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TTDSG. To the extent that we use information obtained using TikTok to optimise our advertising campaigns and economically evaluate our Website, this is also based on our legitimate interests pursuant to Art. 6(1)(f) GDPR in effective marketing of our online offering. You may withdraw your consent at any time with effect for the future via our cookie banner. You may also control or deactivate personalised advertising in the corresponding settings of the TikTok app or in your TikTok account.
d) TikTok Pixel
We use TikTok Ads with the additional application “TikTok Pixel”. TikTok Pixel is code installed on our profile which then forwards events of Website visitors to us. With TikTok Pixel, we can check the success of our advertising campaigns. When the advertisement loads, we can use a technical procedure to determine how a user interacts after clicking the advertisement and whether one of our services is actually used. This provides us, in statistical form, with information about the total number of views of our advertisements, which advertisements are particularly popular and which events were triggered (e.g. whether the user subsequently visited our Website and ordered something).
The legal basis for processing is Art. 6(1)(f) GDPR. We want to draw attention to our offering through our advertisements and better plan, implement and optimise our advertising campaigns. These purposes also constitute our legitimate interest.
e) Advertising with Google (Google Ads)
We use Google Ads to draw attention to our offers through advertisements. If you reach our Website through a Google advertisement, Google Ads stores a Cookie on your device.
Google delivers advertising materials via so-called “ad servers”. For this purpose, we and other websites use ad server Cookies through which certain parameters for measuring success, such as display of advertisements or clicks by users, can be measured. Through Google Ads Cookies stored on our Website, we can receive information about the success of our advertising campaigns. These Cookies are not intended to identify you personally. As analysis values, the Cookie generally stores the unique Cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions), and opt-out information (indicating that users no longer wish to be addressed).
Cookies set by Google enable Google to recognise your Internet browser. For example, if a user visits certain pages of an Ads customer’s Website and the Cookie stored on the user’s computer has not expired, Google and the customer can recognise that the user clicked the advertisement and was redirected to that page. A different Cookie is allocated to each Ads customer, so Cookies cannot be tracked across other Ads customers’ websites. By integrating Google Ads, Google receives the information that you have accessed the relevant part of our Internet presence or clicked one of our advertisements. If you are registered with a Google service, Google can allocate the visit to your account. Even if you are not registered with Google or are not logged in, it is possible that the provider may obtain and store your IP address.
Due to the marketing tools used, your browser automatically establishes a direct connection to Google’s server. We do not independently collect personal data in the advertising measures mentioned; rather, we merely provide Google with the possibility to collect data. We receive only statistical evaluations from Google that provide information on which advertisements were clicked how often and at what prices. We do not receive any further data from the use of advertising materials; in particular, we cannot identify users on the basis of this information.
aa) Google Conversion Tracking
We use Google Ads with the additional application “Google Conversion Tracking”. This is a procedure enabling us to check the success of our advertising campaigns. For this purpose, advertisements are provided with a technical feature, e.g. an ID, which allows us to determine how users interact after clicking advertisements and whether one of our services is actually used. This provides us, in statistical form, with information about the total number of readers of our advertisements, which advertisements are particularly popular and, where applicable, further information about consequences of the advertisement.
bb) Google Remarketing
We use Google Ads with the additional application “Google Remarketing”. This procedure enables us to create advertisements based on existing information about you and address you again during your further use of the Internet. This is done through Cookies set when you visit our offerings, through which Google collects and pseudonymously evaluates your usage behaviour when visiting various websites. According to Google’s own statements, data collected in the context of remarketing are not combined with your personal data that may be stored by Google.
The legal basis for processing your data is Art. 6(1)(a) GDPR, i.e. the integration of Google Ads and use of Google Conversion Tracking and Google Remarketing take place only after you have given your consent.
You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. The easiest way to withdraw consent is via our cookie banner or through the following functions: by adjusting your browser software, in particular because suppressing third-party Cookies means you will not receive advertisements from third parties; by configuring your browser to block Cookies from the domain “www.googleadservices.com”, www.google.de/settings/ads, although this setting is deleted if you delete your Cookies; by deactivating interest-based advertisements from providers that are part of the “About Ads” self-regulatory campaign via www.aboutads.info/choices, although this setting is deleted if you delete your Cookies; or by permanently deactivating them in the browsers Firefox, InternetExplorer or Google Chrome via www.google.com/settings/ads/plugin. Please note that in this case you may not be able to use all functions of our Website in full.
We store your data as long as we need them for the relevant purpose or until you object to storage of your data or withdraw your consent.
The collected information is stored on Google servers, including in the USA. For these cases, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission. We have also concluded Standard Contractual Clauses with Google, the purpose of which is to ensure an adequate level of data protection in the third country.
Further information on data protection at Google Ireland Limited, Gordon House, Barrow Street Dublin 4, Ireland, can be found here: www.google.com/intl/de/policies/privacy and here: http://services.google.com/sitestats/de.html.
f) X (formerly Twitter) Ads
We use the X Ads advertising service of X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland (hereinafter “X”) on our Website to show you interest-based advertisements on the X platform (formerly Twitter) and measure the success of our advertising campaigns.
For this purpose, we embed the X Pixel (JavaScript code) on our Website. When you visit our pages, your browser establishes a connection to X servers. Cookies and similar storage technologies are set or read on your device. Through the pixel, X receives information about the pages you access with us, how long you remain there, what you click and whether you perform certain actions – for example, making a purchase, registering or downloading something. The data collected include your IP address, device and browser information, Cookie identifiers and a click ID (a code in the URL showing that you reached us via an X advertisement). If you are logged in to X, X can allocate the visit directly to your X account. Even without a login, X can collect your IP address and device information and create pseudonymous profiles.
We use these data for the following purposes: first, to measure whether users perform a desired action on our Website after clicking an X advertisement (conversion tracking). Second, to create audiences of Website visitors to address them again on X – for example, persons who have abandoned a shopping cart or viewed particular products. In addition, X may use this basis to find users with similar interests and optimise the delivery of our advertisements.
The legal basis for processing is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (for setting and reading Cookies on your device). Integration of the X Pixel and transmission of the data occur only after your consent via our cookie banner. To the extent that we use statistical evaluations supplied by X to optimise our advertising, we additionally rely on our legitimate interest pursuant to Art. 6(1)(f) GDPR in effective marketing of our offering.
X also processes data in the USA. The transfer takes place on the basis of the EU-US Data Privacy Framework and the EU Standard Contractual Clauses contained in the X Ads Data Processing Terms. Please note that despite these safeguards, residual risks may arise due to US surveillance laws.
You may withdraw your consent at any time via our cookie banner. From withdrawal, the X Pixel will no longer be loaded and no further data will be transmitted to X. You can view and delete data already processed via the X privacy settings.
X’s privacy policy is available at: https://x.com/privacy.
g) Microsoft Advertising
We use the Microsoft Advertising service of Microsoft Ireland Operations Limited (Ireland/EU) (formerly Bing Ads) on our Website. Microsoft Advertising is an online marketing service that helps us use the Universal Event Tracking (UET) tool to place advertisements in a targeted manner through the Microsoft Bing search engine. Microsoft Advertising uses Cookies for this purpose. Personal data are processed in the form of online identifiers (including Cookie identifiers), IP addresses, device identifiers and information about device and browser settings.
Microsoft Advertising collects data through UET that enable us to track audiences using remarketing lists. For this purpose, a Cookie is stored on the device used when our Website is visited. Microsoft Advertising can thereby recognise that our Website has been visited and display an advertisement when Microsoft Bing or Yahoo is subsequently used. The information also serves to create conversion statistics, i.e. to record how many users reached one of our Website pages after clicking an advertisement. This tells us the total number of users who clicked our advertisement and were redirected to our Website. However, we receive no information that allows users to be personally identified.
The legal basis for processing your data is Art. 6(1)(a) GDPR, i.e. integration takes place only after your consent. You may withdraw your consent at any time, most easily via our cookie banner. You can also deactivate personalised advertising with Microsoft at: https://about.ads.microsoft.com/de-de/ressourcen/richtlinien/personalisierte-anzeigen.
We store your data as long as we need them for the relevant purpose or until you object to storage of your data or withdraw your consent.
With Microsoft services, transfer of data to Microsoft Corp. in the USA cannot be excluded. Where data are also processed outside the EU, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission. Alternatively, we take appropriate and reasonable measures to ensure an adequate level of data protection, e.g. by concluding EU Standard Contractual Clauses. Further information on data protection at Microsoft can be found in Microsoft’s privacy notices at https://privacy.microsoft.com/de-de/privacystatement.
h) Criteo
We use functions of the Criteo advertising service of Criteo SA, 32 Rue Blanche, 75009 Paris, France (hereinafter “Criteo”) on our Website to show users interest-based advertisements within the Criteo advertising network. Criteo uses JavaScript tags and Cookies or comparable technologies in particular to collect your usage behaviour on our Website and on websites of other Criteo partners and evaluate it in pseudonymous usage profiles. For example, information about products you viewed, placed in the shopping cart or purchased is processed in order to display personalised advertising and measure advertising campaign performance. Further details of data collected by Criteo can be found here: https://www.criteo.com/de/privacy/how-we-use-your-data/
To recognise you or your device, Criteo uses identifiers (e.g. Cookie IDs or mobile advertising IDs) linked to usage events collected by Criteo (e.g. viewed products, shopping-cart actions, purchases and time and location of page access). Criteo organises and analyses these data to decide whether and in what form an advertisement is displayed and to measure the performance of the advertising displayed (e.g. number of ads delivered, views and clicks). We receive from Criteo only aggregated statistical evaluations and cannot directly identify data subjects through them. Details can be found in Criteo’s privacy policy at: https://www.criteo.com/de/privacy/
The legal basis for use of Criteo and the associated storage and reading of information on your device is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG, insofar as Cookies or comparable technologies are set for advertising and analysis purposes. To the extent that we use information obtained via Criteo to evaluate and optimise our advertising measures and design our offering in a manner appropriate to interests, this also takes place on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR in effective marketing of our online offering. You may withdraw your consent at any time with effect for the future via our cookie banner. Criteo provides further objection and deactivation options (opt-out) on its privacy pages.
Criteo and we are joint controllers within the meaning of Art. 26 GDPR. We have concluded an arrangement on joint processing with Criteo, the essential contents of which Criteo describes at the following link: https://www.criteo.com/de/privacy/how-we-use-your-data/
i) Server-Side Tracking and Conversion APIs
In addition to the client-side tracking technologies described above (pixels, tags, Cookies), we use – provided that you have consented to the relevant marketing category through our cookie banner – server-side conversion APIs of the relevant advertising platforms. In this context, our server (not your browser) transmits pseudonymised event data directly to the platforms’ servers.
Measurement and optimisation of advertising campaign success (conversion tracking), allocation of conversions to specific advertisements/campaigns, improvement of delivery algorithms (e.g. lookalike audiences), enabling offline conversion imports (e.g. subsequent subscription renewals, telephone conclusions).
In particular, the following are processed: type of event (e.g. Purchase, Lead, Subscribe, AddToCart, InitiateCheckout), hashed user data (e-mail address, telephone number, name), IP address, platform click IDs, order value, currency, product IDs, transaction ID, timestamp, device/browser-related contextual data. No unencrypted personal data are transmitted; all direct identifiers are hashed on our server before being sent.
We use the following services or advertising platforms:
• Meta Conversions API, provider: Meta Platforms Ireland Limited, Merrion Road, Ballsbridge, Dublin 4, D04 X2K5, Ireland;
• Google Enhanced Conversions / Google Ads API, provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
• TikTok Events API, provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland;
• Microsoft Advertising Universal Event Tracking (UET) Conversion API, provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
The legal basis for processing is Art. 6(1)(a) GDPR (your consent to the relevant marketing category through the cookie banner) in conjunction with § 25(1) TDDDG (access to the device for reading click IDs). Transmission takes place only after consent has been given; without consent, no server-side transmission takes place.
The platforms listed above do not act as our processors, but generally as joint controllers. Corresponding joint-controller arrangements have been concluded. Details of the respective areas of responsibility can be found in the platforms’ privacy notices (links below).
Most recipients are based in, or have their parent company in, the USA. Transfer takes place on the basis of the EU-US Data Privacy Framework (DPF) (European Commission adequacy decision). Please note that despite these safeguards, residual risks due to US surveillance laws may arise.
You may withdraw consent to the relevant marketing category at any time via our cookie banner (CCM19). From withdrawal, we will discontinue server-side transmission for that platform. You may view and request deletion of data already transmitted via the privacy tools of the relevant platform (e.g. Meta: “Activities outside Facebook”, Google: “My Activity”, TikTok: “Privacy settings”).
Further information:
Meta Conversions API: https://developers.facebook.com/documentation/ads-commerce/conversions-api
Google Enhanced Conversions: https://developers.google.com/google-ads/api/docs/conversions/overview?hl=de
TikTok Events API: https://ads.tiktok.com/help/article/events-api?lang=en
Microsoft UET Server-Side: https://learn.microsoft.com/en-us/advertising/guides/uet-conversion-api-integration?view=bingads-13
12. Competitions
We occasionally organise competitions on our Website or via our social media channels. If you participate in a competition, we process the personal data you provide (generally name, e-mail address, where applicable postal address for sending the prize and your date of birth for age verification) exclusively for the purpose of conducting the relevant competition (determining and notifying winners, handing over/sending the prize, documenting proper conduct).
The legal basis is your express consent pursuant to Art. 6(1)(a) GDPR, which you give by submitting the entry form (checkbox “I have read and agree to the terms and conditions of participation and the Privacy Notices”). Participation is voluntary. You may withdraw your consent at any time with effect for the future (informal e-mail to datenschutz@hkcm.com); withdrawal results in exclusion from the ongoing competition.
Recipients of the data are internal persons entrusted with handling the competition, the competition service provider used by us (processor pursuant to Art. 28 GDPR with whom a data processing agreement has been concluded) and, where applicable, a shipping service provider. No data are disclosed to third parties for marketing purposes. Your data are not used for newsletters, advertising or profiling unless you have separately consented to this (double opt-in).
Where the competition service provider uses servers outside the EU/EEA (e.g. USA), transfer takes place on the basis of the EU-US Data Privacy Framework (adequacy decision) and/or EU Standard Contractual Clauses.
Publication of winners: Publication of a name (e.g. “Max M. from Stuttgart has won”) takes place only with your prior express consent (separate checkbox in the entry form or subsequent request by e-mail). Without this consent, the winner will not be publicly named.
You have the following data subject rights: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection to processing (Art. 21 GDPR), withdrawal of consent (Art. 7(3) GDPR) and lodging a complaint with the supervisory authority (Art. 77 GDPR). Details and the supervisory authority’s contact details can be found in section 17 of these Privacy Notices.
13. Applications
If you apply to us through our Website or by e-mail, we process the personal data you provide for the purpose of carrying out the application process. This includes your master and contact data, qualifications, certificates, CV and further information that you provide voluntarily (such as a photograph, salary expectations, notice period or severe disability status). The legal basis is Art. 6(1)(b) GDPR in conjunction with § 26(1) sentence 1 BDSG, as the application process serves to initiate an employment relationship. Where you provide special categories of personal data (e.g. severe disability), we base processing on Art. 9(2)(b) GDPR in conjunction with § 26(3) BDSG.
We use the workwise recruiting software (workwise GmbH, Munich) to receive and manage applications. workwise processes applicant data as our processor on the basis of a data processing agreement concluded with us. The data are hosted on servers in Germany; no third-country transfer takes place. workwise uses sub-processors to provide the service; they are contractually obliged to comply with data protection requirements and – where established in third countries – safeguarded through EU Standard Contractual Clauses. The application form is integrated into our Website via an iFrame / JavaScript code from workwise; technical Cookies and LocalStorage entries may be placed on your device that are strictly necessary for functionality of the form (legal basis: § 25(2) no. 2 TDDDG / Art. 6(1)(f) GDPR).
Your data are made accessible internally only to persons involved in the decision (management, relevant specialist department). No disclosure to other third parties takes place.
14. Recipients of Personal Data
Within our company, only those persons have access to personal data who require it for the respective stated purposes. We disclose your personal data to external third parties only where this is necessary to process or handle your matter, another legal permission exists, or we have your consent.
Data are transferred within our group of companies for sales and marketing purposes on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR.
External recipients may in particular be affiliated companies or external service providers that we use as processors to provide services, for example in the areas of technical infrastructure and maintenance of our Website. We select and regularly review these processors carefully. They may use the data exclusively for purposes specified by us and in accordance with our instructions.
Furthermore, we may be required to transmit personal data to authorities and state institutions, such as public prosecutors’ offices, courts or tax authorities, for compelling legal reasons. Such transfer takes place on the basis of Art. 6(1)(c) GDPR.
We may also disclose your personal data to third parties where participation in promotions, competitions, conclusion of contracts or similar services are offered by us jointly with partners or service providers (e.g. transport service providers). In such cases, data are disclosed on the basis of consent, to perform a contract with you or to safeguard our legitimate interests pursuant to Art. 6(1)(a), (b) and/or (f) GDPR. You will receive further information when you provide personal data in connection with the specific processing operation.
15. Data Processing in Third Countries
As a rule, we do not process your data outside the European Union (EU) or the European Economic Area (EEA). If, in an individual case, we nevertheless transfer your data to third countries outside the EU or EEA (e.g. to perform an order from a third country), we ensure before transfer that either a legally permitted exception applies, the recipient has an adequate level of data protection, or you consent to the data transfer. An adequate level of data protection is ensured, for example, through the EU-US Data Privacy Framework in conjunction with the European Commission’s adequacy decision, conclusion of EU Standard Contractual Clauses or the existence of binding internal data protection rules, known as Binding Corporate Rules (BCR). An adequacy decision of the European Commission exists with regard to the adequate level of data protection in Switzerland (https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32000D0518).
16. Retention Period
We store your personal data only as long as necessary to fulfil the purposes or – in the case of consent – as long as you have not withdrawn consent. A need to store your data may exist, in particular, where the data are still required to perform contractual services or to examine and grant or defend warranty claims.
In the event of an objection, we will no longer process your personal data unless continued processing is permitted or even mandatorily required under the applicable statutory provisions (e.g. in connection with commercial and tax-law retention obligations).
You have the option of deleting your account in your profile. In this case, your personal data are deleted unless their storage is permitted or even mandatorily required under the applicable statutory provisions (e.g. in connection with commercial and tax-law retention obligations).
17. Your Rights
As a data subject affected by data processing, you have numerous rights. In detail, these are:
• Right of access (Art. 15 GDPR, § 34 BDSG): You have the right to obtain information about data stored by us concerning you.
• Right to rectification and erasure (Arts. 16 and 17 GDPR, § 35 BDSG): You may request that we rectify incorrect data and – where the statutory conditions are met – erase your data.
• Right to restriction of processing (Art. 18 GDPR): Where the statutory conditions are met, you may request that we restrict processing of your data (e.g. by blocking).
• Right to data portability (Art. 20 GDPR): If you have provided us with data on the basis of a contract or consent, you may, where the statutory conditions are met, request that you receive the data you provided in a structured and commonly used format or that we transmit them to another controller.
• Right to object to data processing based on legitimate interests (Art. 21 GDPR): You have the right, on grounds relating to your particular situation, to object at any time to processing by us where it is based on legitimate interests within the meaning of Art. 6(1)(f) GDPR. If you exercise your right to object, we will stop processing your data unless we can demonstrate compelling legitimate grounds for continued processing that override your rights, or processing serves the assertion, exercise or defence of legal claims.
• Withdrawal of consent (Art. 7 GDPR): If you have given us consent to process your data, you may withdraw it at any time without stating reasons with effect for the future. This does not affect the lawfulness of processing of your data before withdrawal. If you wish to withdraw your consent to the use of certain Cookies, please note our explanations in section 8.
• Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You may also lodge a complaint with the competent supervisory authority if you believe that processing of your data infringes applicable law. In this regard, you may in particular contact the data protection authority responsible for your place of residence, your place of work or the place of the alleged infringement. The data protection supervisory authority responsible for us is: The Baden-Württemberg Commissioner for Data Protection and Freedom of Information, Postfach 102932, 70025 Stuttgart, Königstraße 10a, 70173 Stuttgart, Tel.: 0711 615541-0, Fax: 0711 615541-15, E-mail: poststelle@lfdi.bwl.de.
If you have questions about the processing of your personal data and your data subject rights, you may contact us at datenschutz@hkcm.com or through the other communication channels stated above.
18. Security
We take technical and organisational security measures to protect your personal data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. These security measures are adapted to the state of the art in each case.
Your personal data transmitted to us in connection with your use of our Website are securely transmitted by encryption. We use the Transport Layer Security (TLS) encryption protocol, widely known by its predecessor designation Secure Sockets Layer (SSL).
Our employees are bound to confidentiality.
19. Changes
From time to time, it may become necessary to adapt the content of these Privacy Notices. We therefore reserve the right to change them at any time. Where a change requires your consent, we will obtain it from you. We recommend that you consult the current version of these Privacy Notices when you visit our Website again. We will also publish the amended version of these Privacy Notices here.
Status: August 2026 (Version 2.1)