Privacy Policy

×

Pimsy is designed to make conversations around skin and skincare more approachable, supportive, and less overwhelming.

While Pimsy is cool and has a huge personality, our legal team is all business and zero fun. So if you are reading this, prepare yourself for a slightly boring time.

This Privacy Policy provides information about the processing of personal data when using the informational website at www.pimsy.ai (“pimsy.ai”) and the AI skin companion at www.pimsy.app (“pimsy.app”; collectively, the “Services”).

Pimsy is created and operated by:

System Akvile GmbH
Gänsemarkt 33, c/o Impact Hub
20354 Hamburg, Germany
Email: team@systemakvile.com

System Akvile GmbH is the controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection laws.

I. Provision of the Website and Creation of Log Files

We use the services of Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (“Vercel”) for the hosting and provision of our website.

We use Vercel as a hosting platform to deliver our website. This serves the purpose of ensuring a secure, fast, and reliable delivery of our online content. Each time our website is accessed, Vercel automatically collects data and information from the computer system of the accessing device, which your browser automatically transmits to Vercel.

The following data is collected in this process:

(1) Information about the browser type and version used

(2) The User’s operating system

(3) The user’s IP address

(4) The website that referred you to our site (referrer URL)

The data is stored in our system’s log files. This data is not stored together with other personal data of the User.

The legal basis for the collection and temporary storage of the data is Art. 6(1)(f) GDPR.

The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the User’s computer. For this purpose, the User’s IP address must remain stored for the duration of the session. Vercel, which is headquartered in the United States, is certified under the Data Privacy Framework, which is intended to ensure a level of data protection appropriate to the requirements of the GDPR when transferring data to a third country. Further information on data protection at Vercel can be found in the provider’s privacy policy at: https://vercel.com/legal/privacy-policy.

Data is stored in log files to ensure the website functions properly. Additionally, we use the data to technically optimize the website and to ensure the security of our IT systems. The data is not analyzed for marketing purposes in this context.

These purposes also constitute our legitimate interest in data processing pursuant to Art. 6(1)(f) GDPR.

The data is deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. In the case of data collection for the provision of the website, this is the case when the respective session has ended.

In the case of data stored in log files, this occurs after seven days at the latest. Storage beyond this period is possible. In this case, the users’ IP addresses are deleted or anonymized so that the client making the request can no longer be identified.

The collection of data for the provision of the website and the storage of data in log files is absolutely necessary for the operation of the website. Consequently, the User has no right to object.

II. Use of Cookies

Our website uses cookies. Cookies are text files that are stored in or by the web browser on the user’s computer system. When a user visits a website, a cookie may be stored on the user’s operating system. This cookie contains a unique string of characters that allows the browser to be uniquely identified when the website is visited again.

1. Use of technically necessary and analytics cookies

We use cookies to ensure our website functions properly. Some elements of our website require that the browser accessing the site can be identified even after a page change.

When visiting our website, the user is informed about the use of cookies and, in the case of non-technically necessary cookies, their consent to the processing of the personal data used in this context is obtained. In this context, a reference to the Privacy Policy is also provided.

The use of technically necessary cookies and similar technologies in the “technically necessary” category is based on Section 25(2)(2) of the German Telemedia Act (TTDSG). Subsequent data processing is based on legitimate interests pursuant to Article 6(1)(f) of the GDPR.

The purpose of using technically necessary cookies is to enable users to use websites. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary for the browser to be recognized even after a page change.

Cookies are stored on the user’s computer and transmitted from there to our site. Therefore, as a user, you have full control over the use of cookies. By changing the settings in your web browser, you can disable or restrict the storage of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are disabled for our website, it may no longer be possible to use all website features to their full extent.

We also use third-party cookies on our website. The legal basis for the use of cookies and the subsequent data processing is your consent pursuant to Section 25(1) of the German Telemedia Act (TTDSG) and Article 6(1)(a) of the GDPR. Specifically, the following cookie-based tools are used:

a) Google Analytics

Provided you have given your consent, the web analytics service Google Analytics is used on this website. The controller is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

Google Analytics uses cookies that enable an analysis of your use of our websites. The information collected via the cookies regarding your use of this website is generally transmitted to a Google server in the United States and stored there.

IP address anonymization is enabled by default in Google Analytics. Due to IP anonymization, your IP address is truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there. According to Google, the IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.

During your visit to the website, your user behavior is recorded in the form of “events.” Events may include:

  • Page views
  • First visit to the website
  • Start of the session
  • Your “click path,” interaction with the website
  • Language setting

The following is also collected:

  • Your approximate location (region)
  • Your IP address (in truncated form)
  • Technical information about your browser and the devices you use (e.g., language setting, screen resolution)
  • Your internet service provider
  • The referrer URL (which website or advertising medium you used to access this website)

On behalf of the operator of this website, Google will use this information to evaluate your pseudonymous use of the website and to compile reports on website activity. The reports provided by Google Analytics are used to analyze the performance of our website.

Recipients of the data may include

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as a Processor pursuant to Art. 28 GDPR)
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
  • Alphabet Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Since Google is headquartered in the United States, the transfer of your data to the United States cannot be ruled out. Google ensures an adequate level of data protection through its certification under the EU-U.S. Data Privacy Framework.

The data we send and that is linked to cookies is automatically deleted after 14 months at the latest. Data that has reached its retention period is automatically deleted once a month.

b) Firebase

On our website, we use “Firebase,” a platform for app and web development provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

We use Firebase to technically optimize our website and collect usage statistics. This integration allows us to provide our services more efficiently and improve the user experience.

Depending on the Firebase features used, different data may be collected. This may include, in particular, technical data such as your IP address, device information (model, operating system, browser type), Firebase installation IDs, and information about your usage behavior.

Your data is processed based on your consent pursuant to Art. 6(1)(a) GDPR, provided you have consented via our consent banner, or based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in the technical stability and optimization of our website.

Since Google is headquartered in the United States, the transfer of your data to the United States cannot be ruled out. Google ensures an adequate level of data protection through its certification under the EU-U.S. Data Privacy Framework.

The collected data will only be stored for as long as necessary for the respective processing purpose or as required by statutory retention periods.

2. Withdrawal of Consent and Objection

You may withdraw your consent at any time with future effect by accessing the cookie settings again and changing your selection there. The lawfulness of the processing carried out on the basis of your consent until its withdrawal remains unaffected.

You can also prevent the storage of cookies from the outset by configuring your browser software accordingly. However, if you configure your browser to reject all cookies, this may result in limited functionality on this and other websites.

You can also prevent the collection of data generated by the cookie and related to your use of the website by the respective provider, as well as the processing of this data, by not granting your consent to the setting of the cookie or by declaring your objection via the following links provided as examples:

  • http://tools.google.com/dlpage/gaoptout?hl=de
  • https://marketingplatform.google.com/about/analytics/terms/de/

Further information on data protection and the cookies used by the respective provider can be found on the provider’s website, in particular at

  • https://policies.google.com/?hl=de
  • https://firebase.google.com/support/privacy

The provision of data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are under no obligation to provide the data.

III. Data Processing via Pimsy.app and Other Third-Party Services

Pimsy.app uses artificial intelligence to generate responses to inquiries via the chat box and to operate the platform.

When you use our skin health chat box, we also process special categories of personal data, particularly health data as defined in Article 4(15) and Article 9 of the GDPR. Depending on your input, this includes, in particular, information on skin conditions and complaints (e.g., acne, eczema, psoriasis), symptoms, skin condition, physical characteristics (e.g., skin type, skin color, scars, moles), previous treatments, medication or product use, as well as other health-related information that you voluntarily provide to us in the chat.

The processing of this data is based on your explicit consent pursuant to Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR. For controllers based in Germany, the requirements of § 22 BDSG (appropriate and specific safeguards when processing special categories of data) apply additionally. You may revoke your consent at any time with future effect (Art. 7(3) GDPR).

We process your information to enable the chat and provide personalized, non-medical recommendations on skin care and managing common skin conditions, to ensure the functionality and security of our chatbot (e.g., troubleshooting, detection of misuse), and to improve service quality.

Health data is generally stored only for as long as necessary for the purposes mentioned above. Chat content may be retained in logs for a short period for quality assurance and error analysis and is subsequently deleted or – where possible – pseudonymized/anonymized. Specific retention periods may also result from our internal retention policies and are based on the requirements of the intended purpose as well as legal retention obligations.

Please only enter health information in the chat that you wish to share.

When using the chat field, the following third-party providers are utilized, and the subsequent data processing and/or transfers are carried out.

1. Amazon Web Services

To operate our AI-powered chatbot, we use Amazon Web Services (AWS), a service provided by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (“AWS”), as our cloud infrastructure provider.

The data generated during chatbot interactions is stored for the technical provision, archiving, and needs-based operation of our chatbot service. We use AWS as a storage platform to ensure the availability, security, and performance of our AI-powered customer communication.

When you use our chatbot, we process the text, questions, and answers you enter (“chat logs”). This data is stored on servers within the European Economic Area (EEA), Frankfurt/Region eu-central-1.

The data processed includes:

  • The content of your messages (including any personal data you may provide to us in the chat)
  • Timestamps of the interaction
  • Technical metadata (e.g., session IDs) required for assigning and continuing the conversation

This data is stored based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in responding to your inquiry.

Although AWS offers its services in the EU, data may be processed by the parent company in the U.S. (Amazon.com Inc.) in the context of support or technical maintenance. AWS is certified under the EU-U.S. Data Privacy Framework, which ensures an adequate level of data protection. In addition, we have entered into a data processing agreement (DPA) with AWS in accordance with Article 28 of the GDPR.

We store your chat data only for as long as necessary to fulfill the specific purpose of the communication. The data is stored regularly on a temporary basis solely for operational and security purposes and is automatically deleted or anonymized without delay, but no later than upon the expiration of any statutory retention periods or upon resolution of your matter.

For more information on data protection at AWS, please refer to the provider’s privacy policy at: https://aws.amazon.com/de/compliance/data-protection/.

2. Groq

To operate our AI-powered chatbot, we use the “Groq” inference platform provided by Groq, Inc., 1891 Landings Dr, Mountain View, CA 94043, USA (“Groq”).

We use Groq to have the requests processed by our chatbot evaluated efficiently and in real time using AI language models. Groq serves as a technical interface (API) through which we forward our requests to the relevant AI models to generate helpful answers for you in natural language.

When you use our chatbot, the text you enter (“prompts”) is transmitted via our servers to Groq’s API interface. This includes:

  • The content of your chat messages
  • Technical metadata of the request (e.g., timestamps, system instructions for the bot)
  • If applicable, the IP address of your device (if this is transmitted as part of the API request)

The transmission of your request data is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in responding to your request.

Since Groq is based in the United States, this constitutes a transfer to a third country. To ensure a level of data protection appropriate to the GDPR, we have entered into standard contractual clauses (Art. 46 GDPR) with Groq. We have also concluded a data processing agreement (DPA) with Groq in accordance with Art. 28 GDPR to ensure that your data is processed exclusively in accordance with our instructions and for the purpose of providing the service.

Groq processes the transmitted data to perform the inference. According to our information and Groq’s applicable terms and conditions, the input data we transmit is not used to train the underlying AI models. After processing, the data is deleted in accordance with the technical requirements of the interface and is not permanently stored on Groq’s servers.

For more information on data protection at Groq, please visit: https://groq.com/privacy-policy/.

3. ElevenLabs

We use the services of ElevenLabs, Inc., 85 5th Ave, New York, NY 10003, USA (“ElevenLabs”) for technical support in processing spoken language in our AI chatbot.

We use ElevenLabs for the temporary processing of speech data to transcribe it into text or to enable voice-based interaction with the chatbot. This also serves the purpose of enabling barrier-free and intuitive communication with our system.

As part of this service, the audio data you provide is transmitted to ElevenLabs. This includes:

  • The audio file or audio stream you provide (your voice/spoken language)
  • Technical metadata required for transcription (timestamps, session ID)

The transmission of audio data is carried out exclusively for the purpose of immediate transcription or processing. The data is deleted from the provider’s systems upon completion of the processing operation and is not stored permanently. According to our agreements with ElevenLabs, the speech data we transmit is not used for training their own AI models.

The processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in responding to your inquiry.

ElevenLabs, which is headquartered in the United States, is certified under the Data Privacy Framework, which is intended to ensure a level of data protection appropriate to the requirements of the GDPR when data is transferred to a third country. We have entered into a data processing agreement (DPA) with ElevenLabs in accordance with Article 28 of the GDPR.

For more information on data protection at ElevenLabs, please visit: https://elevenlabs.io/privacy.

4. LLaMA

We use the language model “LLaMA,” an AI model from Meta Platforms, Inc. (“Meta”), to power our AI chatbot.

We use LLaMA to generate automated, context-aware, and helpful responses to your inquiries. The model serves as the “engine” behind our chatbot, enabling it to understand natural language and process it in real time to address your concerns.

When you use the chatbot, the text you enter (“prompts”) is processed. We ensure that data processing is as data-minimal as possible. The following are processed:

  • Content of your chat messages
  • Session metadata (e.g., chat history to maintain context)

We integrate the LLaMA model via a specialized infrastructure service provider. In this process, your requests are temporarily transmitted to the service provider’s server for technical processing. We have entered into a data processing agreement (DPA) with this service provider, which ensures that your data is processed exclusively in accordance with our instructions and is not used for training AI models.

Processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in responding to your inquiry. A key aspect of our selection of the AI model is the protection of your privacy: The data you enter is not used to train or improve the LLaMA model or other AI systems from Meta. Meta occasionally transfers personal data to Meta servers in the United States. This data is stored and further processed there. Meta is certified under the Data Privacy Framework. The transfer of data is subject to a level of data protection comparable to that in the EU. We have entered into a data processing agreement (DPA) with Meta in accordance with Article 28 of the GDPR.

Further information on the LLaMA model can be found in Meta’s documentation at: https://llama.meta.com/.

5. Use of WhatsApp Business Platform (Cloud API)

You may choose to communicate with Pimsy through the WhatsApp-Messenger. We access the WhatsApp-Messenger exclusively via the WhatsApp Business Platform Cloud API directly through Meta for Developers. We do not use an external Business Solution Provider (BSP) or the standard WhatsApp Business App. The WhatsApp Business Platform Cloud API is provided by WhatsApp Ireland Limited and Meta Platforms Ireland Limited (collectively, “Meta”), 4 Grand Canal Square, Dublin 2, Ireland.

When you send us a message via WhatsApp-Messenger, your communication is routed through Meta’s infrastructure and transmitted directly to our systems via the WhatsApp Business Platform Cloud API. Unlike the standard WhatsApp Business App, our API-based integration does not access or synchronize any address book or contact list on any device.

Meta processes your message independently in accordance with WhatsApp’s own Privacy Policy before it reaches our systems. We have no control over Meta’s independent processing of your personal data.

a) Data We Process

When you communicate with us through the WhatsApp Business Platform Cloud API, we may process the following personal data. The API only transmits message-level data as described below:

  • Your WhatsApp phone number
  • Your WhatsApp profile name (if available)
  • The content of messages you send to us and messages we send to you
  • Message timestamps
  • Message status information (such as sent, delivered, read, or failed)
  • Technical metadata required to operate the service (e.g., session IDs)
  • Your consent to the processing of health-related information, including the date and time of consent and the applicable consent version

Note: Pimsy currently operates as a text-only service and does not request or accept images, voice notes, or video files. Because we use the WhatsApp Business Platform Cloud API (not the standard WhatsApp Business App), we do not have access to your WhatsApp profile picture, status updates, “last seen” information, or your device contacts.

Depending on what you voluntarily choose to share in your conversation with Pimsy, your messages may contain health-related information, for example information about your skin, skin conditions, symptoms, or treatments.

Pimsy is not a medical service and does not provide medical diagnoses or medical advice. You are not required to share health-related information in order to use Pimsy.

Before starting a conversation with Pimsy, we prompt you to explicitly consent to the processing of health-related information that you may voluntarily choose to share (with direct links provided to our Privacy Policy and Legal Notice / Imprint). Pimsy enforces a strict consent gate: no user messages or queries are processed by our AI systems until explicit affirmative consent is provided. Consent is recorded in our systems with a timestamp for documentation purposes.

Where you voluntarily choose to share health-related information, we process such information on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

b) Purposes of Processing and Legal Bases

We process this data for the following purposes:

aa) Providing the Pimsy AI Assistant and Responding to Your Messages and Requests

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures at your request), insofar as the communication serves the provision of the Pimsy service you have requested. Where no contractual relationship exists, the legal basis is Art. 6(1)(f) GDPR (legitimate interest); our legitimate interest consists in responding to inquiries directed to us. Where information voluntarily shared by you constitutes health data within the meaning of Art. 9 GDPR, such information is processed only on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR.

bb) Continuing Conversations Across Sessions (Conversation History)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in providing a seamless, consistent service experience across multiple interactions. Where conversation history contains health data within the meaning of Art. 9 GDPR, such data is processed on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR.

cc) Improving the Quality and Performance of Our Services

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest consists in continuously improving the quality, reliability, and performance of our AI-based service. Where improvement activities involve processing of special categories of data (health data), processing is based solely on your explicit consent pursuant to Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR.

dd) Maintaining System Security and Detecting Misuse

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in protecting our systems and users against abuse, unauthorized access, and fraud.

ee) Generating Aggregated, Pseudonymized Service Usage Statistics (Analytics)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in understanding service usage patterns and system performance.

c) Conversation History

Messages received through the WhatsApp Business Platform Cloud API are stored in our conversation history system so that conversations can continue across sessions and the service can be provided consistently. Conversation history may also be reviewed where necessary to provide customer support, investigate technical issues, improve service performance, and maintain security.

d) Analytics and Service Measurement

We collect limited analytics to understand how the service is used and to improve system performance. For example, we may record events such as conversation starts, messages received, returning users, and technical reliability events.

We do not send your text message content or conversation text to Firebase Analytics or Google Analytics.

For analytics purposes, your phone number is transformed using a one-way HMAC (Hash-based Message Authentication Code) cryptographic function before being used as a pseudonymized analytics identifier. The HMAC transformation is a one-way pseudonymization technique pursuant to Art. 4(5) GDPR.

e) Recipients of Data and International Transfers

In the context of the WhatsApp Business Platform Cloud API, the following recipients or categories of recipients may receive your personal data:

  • WhatsApp Ireland Limited / Meta Platforms Ireland Limited (in connection with the operation of the WhatsApp network, message routing, and provision of the Cloud API)
  • Amazon Web Services EMEA SARL (as processor, for cloud hosting and log storage)
  • Groq, Inc. (as processor, for AI inference)
  • Google Ireland Limited (as processor, for Firebase Analytics/Google Analytics, receiving only pseudonymized identifiers)

Where data is processed by or transferred to recipients located outside the European Economic Area (EEA), including Meta Platforms, Inc. (USA), Groq, Inc. (USA), and Google LLC (USA), such transfers are based on appropriate safeguards pursuant to Art. 45 et seq. GDPR, specifically the EU-U.S. Data Privacy Framework adequacy decision or Standard Contractual Clauses (SCCs).

We do not use an external Business Solution Provider (BSP) to relay messages.

f) Relationship with Meta / WhatsApp Ireland Limited

When you send a message to us via the WhatsApp Business Platform Cloud API:

  • Meta acts in a dual capacity:
    • as our data processor (Art. 28 GDPR) for the Cloud API service itself — i.e., receiving, decrypting, temporarily storing, and forwarding messages on our behalf and at our instruction; and
    • as an independent controller for certain platform-level processing activities (spam detection, network integrity, abuse prevention) that Meta carries out for its own purposes.
  • The contractual basis for Meta’s processor role is the WhatsApp Business Data Processing Terms (available at https://www.whatsapp.com/legal/business-data-processing-terms), supplemented by the WhatsApp Business Data Security Terms and, for international transfers, the WhatsApp Business Data Transfer Addendum.
  • We process your personal data independently as a controller for the purposes described in this section.
  • However, you should be aware that Meta may process certain metadata (such as message delivery timestamps and device identifiers) for its own platform-security purposes in accordance with WhatsApp’s Privacy Policy. We recommend reviewing WhatsApp’s Privacy Policy at https://www.whatsapp.com/legal/privacy-policy for details.
  • We access the API interface directly through Meta for Developers and do not use an external Business Solution Provider for this purpose.

g) Data Retention

Conversation history is retained only for as long as necessary to provide the service, maintain service continuity, comply with legal retention obligations, resolve disputes, prevent fraud, and protect our legitimate interests. Specific retention periods are determined by the nature of the data and the applicable purpose; at a minimum, data is deleted or anonymized once the relevant purpose has been fulfilled and no statutory retention obligation requires further storage.

Pseudonymized analytics data is stored separately from conversation content and is retained for a maximum of 14 months. Records documenting your consent (timestamp, consent version, user identifier) are retained for as long as necessary to demonstrate compliance under applicable data protection law.

h) Technical and Organizational Measures (API-Specific)

We use the WhatsApp Business Platform Cloud API directly through Meta for Developers. Our integration does not access or store device address books.

Message processing occurs programmatically via authenticated API endpoints. Access to message content within our systems is restricted to authorized personnel and processors where necessary for the purposes described in this Privacy Policy, protected by authentication and role-based access controls.

IV. Contacting Us via Email

You can contact us via email. The transmission of information contained in the respective email (including personal data) is voluntary, and we process all data you provide in your email.

The legal basis for processing data in connection with contact inquiries is our legitimate interest under Article 6(1)(f) of the GDPR in responding to your inquiry or, in the case of an inquiry based on or for the purpose of establishing a contractual relationship, Article 6(1)(b) of the GDPR. In the case of legitimate interest, our interest outweighs the User’s interest, as we assume that the User is interested in having their inquiry processed.

We process your contact data solely for the purpose of handling the contact inquiry.

The data will be deleted as soon as it is no longer needed to achieve the purpose for which it was collected. For the information in your inquiry, this is the case when it can be inferred from the circumstances that the matter in question has been conclusively resolved, at the latest after six months have elapsed.

V. Social Media Presence

1. LinkedIn

We use the platform and services of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (hereinafter “LinkedIn”). Please note that you use our LinkedIn page and its features at your own risk. This applies in particular to the use of interactive features (e.g., commenting, sharing, rating).

We are jointly responsible with LinkedIn only for the processing of so-called “Insights data,” to the extent that this data is used to generate so-called “Page Insights.” We have entered into an agreement with LinkedIn regarding joint responsibility, which you can access at https://legal.linkedin.com/pages-joint-controller-addendum. The agreement pertains to data processing activities collected in connection with a visit to or interaction with our LinkedIn profile, but only to the extent that this data is also (subsequently) processed for “Page Insights.” “Page Insights” encompass analytics services that help the operator of a LinkedIn profile better understand interactions with their pages. The purpose of the data processing is to generate aggregated statistics for LinkedIn profile operators. LinkedIn provides further information on this here: https://www.linkedin.com/help/linkedin/answer/a547077/linkedin-page-analytics-overview?lang=en. The information available to data subjects regarding “Page Insights” data specifies how and when “Insights data” is collected and used to generate “Page Insights”:

  • When a LinkedIn member visits, follows, or engages with the page, LinkedIn processes personal data to provide the page operator with insights into usage.
  • LinkedIn processes data that the member has provided to LinkedIn, such as data on job title, country, industry, years of experience, company size, and employment status from a member’s profile.
  • LinkedIn processes information about how a member has interacted with your company page, for example, whether a member is a follower.

When you visit our LinkedIn page, LinkedIn collects, among other things, your IP address and other information stored on your computer in the form of cookies. This information is used to provide us, as the operator of the LinkedIn page, with statistical information about the use of the LinkedIn page. We do not receive any personal data from LinkedIn in this context.

The data collected about you in this context is processed by LinkedIn and may be transferred to countries outside the European Union. LinkedIn describes what information it receives and how it is used in its User Agreement and Privacy Policy. For further information, please refer to LinkedIn’s Privacy Policy: https://www.linkedin.com/legal/privacy-policy. If you wish to exercise any data subject rights under the GDPR, please note that we cannot fully comply with these rights without LinkedIn. With regard to LinkedIn’s processing activities, we ask that you contact LinkedIn directly. The respective responsibilities, particularly with regard to safeguarding data subject rights, can be found in the Page Insights Addendum. LinkedIn assumes primary responsibility for fulfilling the GDPR obligations for the joint processing of “Insights data.” This includes fulfilling the following data subject rights. LinkedIn provides further details on exercising these rights in its Privacy Policy.

In addition, we are also solely the controller for certain data processing activities. To provide our information service, we process the following data for communication with LinkedIn users:

  • User interactions (posts, likes, etc.)
  • Profile name and data provided by the user in the conversation history, e.g., for processing inquiries
  • Statistical surveys for targeted advertising

This processing is carried out for the purpose of responding to your inquiries or communicating with you, as well as to publish information about our events and services.

The legal basis for processing data for the purpose of responding to inquiries related to a future contract is Article 6(1)(b) of the GDPR; in all other cases, it is our legitimate interest pursuant to Article 6(1)(f) of the GDPR.

The legitimate interest consists in the effective provision of information to users, customers, and prospective customers, communication with these individuals, and our public image.

To the extent that personal data is transferred to LinkedIn servers in the United States and stored and further processed there, LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, has entered into the Standard Data Protection Clauses with the LinkedIn companies based in the United States.

Once your inquiry has been processed, the personal data you provided will be deleted from our systems. If you interact with us publicly, for example by leaving a comment or “liking” a post, this data will remain publicly accessible on the page until it is deleted by us or by you. To the extent that statutory retention obligations require longer storage, your data will be stored solely for this purpose and blocked for other purposes.

2. Instagram

Please note that you use our Instagram page and its features at your own risk. This applies in particular to the use of interactive features (e.g., commenting, sharing, rating).

We and Meta Platforms Ireland Limited, 4 Canal Square, Dublin 2, Ireland (hereinafter “Meta”), as the provider of Instagram, are jointly responsible for the processing of personal data via our profile (“Insights Data”). The joint controller agreement is available at: https://www.facebook.com/legal/terms/page_controller_addendum.

Under the agreement, Meta is responsible for informing data subjects about the processing. Instagram’s Privacy Policy is available at: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

Data subjects may exercise their rights with respect to any of the Controllers, us and/or Meta. In addition, we are also solely the controller for certain data processing activities. To provide our information service, we process the following data for communication with users:

  • User interactions (posts, likes, etc.)
  • Profile name and data provided by the user in the conversation history, e.g., for processing inquiries

The processing is carried out for the purpose of responding to your inquiries or communicating with you, as well as to publish information about our events and services.

The legal basis for processing for the purpose of responding to inquiries that serve to conclude a future contract is Art. 6(1)(b) GDPR; in all other cases, it is our legitimate interest pursuant to Art. 6(1)(f) GDPR.

The legitimate interest consists in the effective provision of information to users, customers, and prospective customers, communication with these individuals, and our public image.

Meta occasionally transfers personal data to Meta servers in the United States. This data is stored and further processed there. Meta is certified under the Data Privacy Framework. The transfer of data is subject to a level of data protection comparable to that in the EU.

Once your request has been processed, the personal data you provided will be deleted from our systems. If you interact with us publicly, for example by leaving a comment or “liking” a post, this data will remain publicly accessible on the site until it is deleted by us or by you. To the extent that legal retention obligations require longer storage, your data will be stored solely for this purpose and blocked for other purposes.

3. TikTok

We operate a company page on the “TikTok” platform, a service provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland (“TikTok”).

We use our TikTok page to communicate with customers, prospects, and Users, to share information about our company and our services, and to analyze the reach of our posts.

We are jointly controllers with TikTok for the statistical analysis of visits to our TikTok page (so-called “TikTok Insights”). We have entered into a joint controller agreement with TikTok (the “TikTok Page Insights Controller Addendum”). This agreement stipulates that TikTok assumes primary responsibility for fulfilling GDPR obligations related to Insights (in particular regarding the exercise of data subject rights).

When you visit our TikTok page or interact there, TikTok collects information about your usage behavior (e.g., age, gender, region, interests, device categories). We receive only aggregated, anonymized statistical data (“Insights”) from TikTok, which does not allow for any identification of you personally. TikTok uses cookies and similar technologies to track your behavior both on and off the platform.

The processing of Insights data is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR to optimize our corporate communications. Since TikTok is an international service, your data may be transferred to third countries, in particular to the United States. TikTok ensures compliance with an adequate level of data protection through the use of standard contractual clauses and other measures.

Further information on data protection at TikTok can be found in the provider’s privacy policy at: https://www.tiktok.com/legal/page/eea/privacy-policy/de.

VI. Rights of the Data Subject

You have the right, pursuant to Art. 15(1) GDPR, to request, free of charge, information about the personal data we have stored about you. In addition, provided the legal requirements are met, you have the right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), and data portability (Art. 20 GDPR) regarding your personal data.

If the data processing is based on Article 6(1)(e) or (f) of the GDPR, you have the right to object under Article 21 of the GDPR. If you object to data processing, it will cease in the future, unless the Controller can demonstrate compelling legitimate grounds for the continued processing that override the data subject’s interest in the objection. If the data processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, you may withdraw your consent at any time with future effect, without affecting the lawfulness of the processing carried out prior to such withdrawal.

In the cases mentioned above, please contact us in writing or by email using the contact information provided above.

You also have the right to file a complaint with a data protection supervisory authority. The competent authority is the data protection supervisory authority of the state in which you reside or in which the Controller is headquartered.

VII. Automated Decision-Making/Profiling

We do not engage in automated decision-making or profiling (an automated analysis of your personal circumstances).

VIII. Changes to This Privacy Policy

Due to the further development of our website and the services offered through it, or due to changes in legal or regulatory requirements, it may be necessary for us to amend this Privacy Policy. The version currently available on our website is the valid one.

Got it