Privacy Policy

Created with the Datenschutz-Generator.de by Dr. Thomas Schwenke

Controller

DEALCIRCLE GmbH
Speersort 1
20095 Hamburg
datenschutz@dealcircle.de

The operator of the platform at dub.de is Deutsche Unternehmerbörse DUB.de GmbH, Speersort 1, 20095 Hamburg, a company of the DEALCIRCLE Group. The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described in the context of the platform is DEALCIRCLE GmbH.

Data Protection Officer

https://www.dsextern.de/anfragen
DS EXTERN GmbH
Dipl.-Kfm. Marc Althaus
Frapanweg 22
D-22589 Hamburg

Overview of Processing Activities

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of Data Processed

  • Inventory data.
  • Payment data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication and procedural data.
  • Log data.

Categories of Data Subjects

  • Service recipients and clients.
  • Employees.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Business and contractual partners.
  • Third parties.
  • Customers.

Purposes of Processing

  • Provision of contractual services and fulfillment of contractual obligations.
  • Communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement.
  • Tracking.
  • Conversion measurement.
  • Target group formation.
  • Organizational and administrative procedures.
  • Feedback.
  • Marketing.
  • Profiles with user-related information.
  • Provision of our online offering and user-friendliness.
  • Information technology infrastructure.
  • Financial and payment management.
  • Public relations.
  • Sales promotion.
  • Business processes and management procedures.
  • Provision of AI-supported functions (text creation, translation, search).

Below you will receive an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.

  • Consent (Art. 6(1)(1)(a) GDPR) - The data subject has given their consent to the processing of the personal data concerning them for a specific purpose or several specific purposes.
  • Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR) - The processing is necessary for the performance of a contract to which the data subject is a party, or in order to carry out pre-contractual measures taken at the request of the data subject.
  • Legal obligation (Art. 6(1)(1)(c) GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(1)(f) GDPR) - the processing is necessary to safeguard the legitimate interests of the controller or of a third party, provided that the interests, fundamental rights and freedoms of the data subject requiring the protection of personal data do not override such interests.

National Data Protection Regulations in Germany

In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. These include in particular the Act on Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains in particular special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision-making in individual cases including profiling. Furthermore, the Telecommunications-Digital-Services-Data-Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG) applies, in particular its Section 25 for the storage of and access to information in the users’ terminal equipment. Furthermore, the data protection laws of the individual federal states may apply.

If you are located in Switzerland, we process your data on the basis of the Federal Act on Data Protection (in short, the “Swiss DPA”). Unlike the GDPR, for example, the Swiss DPA generally does not provide that a legal basis for the processing of personal data must be stated, and that the processing of personal data is carried out in good faith, lawfully and proportionately (Art. 6(1) and (2) of the Swiss DPA). In addition, personal data is collected by us only for a specific purpose that is recognizable to the data subject and is only processed in a manner compatible with that purpose (Art. 6(3) of the Swiss DPA).

Note on the Applicability of the GDPR and the Swiss DPA

These data protection notices serve both to provide information under the Swiss DPA and under the General Data Protection Regulation (GDPR). For this reason, we ask you to note that, due to the broader territorial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms “processing” (“Bearbeitung”) of “personal data” (“Personendaten”), “overriding interest” and “particularly sensitive personal data” used in the Swiss DPA, the terms “processing” of “personal data” as well as “legitimate interest” and “special categories of data” used in the GDPR are used. However, the legal meaning of the terms continues to be determined under the Swiss DPA within the scope of the applicability of the Swiss DPA.

Transmission of Personal Data

In the course of our processing of personal data, it may happen that this data is transmitted to or disclosed to other bodies, companies, legally independent organizational units or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.

Data transmission within the group of companies: We may transmit personal data to other companies within our group of companies or grant them access to this data. This concerns in particular the cooperation between DEALCIRCLE GmbH and Deutsche Unternehmerbörse DUB.de GmbH as well as the use of internal systems of the DEALCIRCLE Group for project and transaction management (e.g. for brokering between sellers, buyers and advisors). Insofar as this disclosure takes place for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and business-management interests, or takes place insofar as it is necessary for the fulfillment of our contract-related obligations, or where there is consent of the data subjects or a legal permission.

International Data Transfers

Data Processing in Third Countries

Insofar as we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or the processing takes place in the context of using third-party services or the disclosure or transmission of data to other persons, bodies or companies, this only takes place in accordance with the legal requirements. Insofar as the level of data protection in the third country has been recognized by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is otherwise ensured, in particular through standard contractual clauses (Art. 46(2)(c) GDPR), explicit consent, or in the case of contractually or legally required transmission (Art. 49(1) GDPR). Furthermore, we will inform you of the bases for the third-country transfer for the individual providers from the third country, whereby the adequacy decisions apply as the primary basis. Information on third-country transfers and existing adequacy decisions can be found in the information offering of the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

EU-US Trans-Atlantic Data Privacy Framework

Within the framework of the so-called “Data Privacy Framework” (DPF), the EU Commission has likewise recognized the level of data protection for certain companies from the USA as secure within the framework of the adequacy decision of 10.07.2023. The list of certified companies as well as further information on the DPF can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English). Within the framework of the data protection notices, we inform you which of the service providers used by us are certified under the Data Privacy Framework.

Disclosure of Personal Data Abroad

In accordance with the Swiss DPA, we disclose personal data abroad only if an adequate level of protection for the data subjects is ensured (Art. 16 Swiss DPA). Insofar as the Federal Council has not determined an adequate level of protection (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we take alternative security measures. These may include international treaties, specific guarantees, data protection clauses in contracts, standard data protection clauses approved by the Federal Data Protection and Information Commissioner (FDPIC), or corporate internal data protection rules recognized in advance by the FDPIC or by a competent data protection authority of another country.

According to Art. 16 of the Swiss DPA, exceptions for the disclosure of data abroad may be permitted if certain conditions are met, including the consent of the data subject, contract performance, public interest, protection of life or physical integrity, data that has been made public, or data from a register provided for by law. These disclosures always take place in accordance with the legal requirements.

General Information on Data Storage and Erasure

We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consents are revoked or no further legal bases for the processing exist. This concerns cases in which the original processing purpose ceases to apply or the data is no longer needed. Exceptions to this rule exist where statutory obligations or special interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax-law reasons, or whose storage is necessary for legal prosecution or for the protection of the rights of other natural or legal persons, must be archived accordingly.

Our data protection notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations. Where there are several indications regarding the retention period or erasure deadlines of a piece of data, the longest period shall always be decisive. If a period does not expressly begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the period-triggering event occurred. In the case of ongoing contractual relationships in the context of which data is stored, the period-triggering event is the point at which the termination or other end of the legal relationship takes effect.

Data that is no longer retained for the originally intended purpose, but due to legal requirements or other reasons, we process exclusively for the reasons that justify its retention.

Further Notes on Processing Operations, Procedures and Services

Retention and erasure of data: The following general periods apply to retention and archiving under German law:

  • 10 years - Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, as well as the work instructions and other organizational documents necessary for their understanding, accounting vouchers and invoices (Section 147(3) in conjunction with (1) nos. 1, 4 and 4a AO, Section 14b(1) UStG, Section 257(1) nos. 1 and 4, (4) HGB).
  • 6 years - Other business documents: received commercial or business letters, reproductions of the commercial or business letters sent, other documents insofar as they are relevant for taxation, e.g. hourly wage slips, cost accounting sheets, calculation documents, price markings, but also payroll documents insofar as they are not already accounting vouchers, and cash register tapes (Section 147(3) in conjunction with (1) nos. 2, 3, 5 AO, Section 257(1) nos. 2 and 3, (4) HGB).
  • 3 years - Data required to take into account potential warranty and damages claims or similar contractual claims and rights, as well as to process related inquiries, based on previous business experience and customary industry practices, is stored for the duration of the regular statutory limitation period of three years (Sections 195, 199 BGB).

Retention and erasure of data (Switzerland): The following general periods apply to retention and archiving under Swiss law:

  • 10 years - Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting vouchers and invoices, as well as all necessary work instructions and other organizational documents (Art. 958f of the Swiss Code of Obligations (CO)).
  • 10 years - Data that is necessary to take into account potential damages claims or similar contractual claims and rights, as well as for the processing of related inquiries, based on previous business experience and customary industry practices, is stored for the period of the statutory limitation period of ten years, unless a shorter period of five years is decisive (Art. 127, 128, 130 CO).

Rights of Data Subjects

Rights of Data Subjects under the GDPR

As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of the personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where the personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of the personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw consent given at any time.
  • Right of access: You have the right to request confirmation as to whether data in question is being processed and to obtain information about this data as well as further information and a copy of the data in accordance with the legal requirements.
  • Right to rectification: You have the right, in accordance with the legal requirements, to request the completion of the data concerning you or the rectification of the inaccurate data concerning you.
  • Right to erasure and restriction of processing: You have the right, in accordance with the legal requirements, to request that data concerning you be erased without delay, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with the legal requirements, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
  • Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State in which you habitually reside, the supervisory authority of your place of work, or the place of the alleged infringement, if you consider that the processing of the personal data concerning you infringes the GDPR.

Rights of Data Subjects under the Swiss DPA

  • Right of access: You have the right to request confirmation as to whether personal data concerning you is being processed, and to receive the information necessary for you to assert your rights under this act and to ensure transparent data processing.
  • Right to data disclosure or transfer: You have the right to request the disclosure of your personal data that you have provided to us in a commonly used electronic format.
  • Right to rectification: You have the right to request the rectification of the inaccurate personal data concerning you.
  • Right to object, erasure and destruction: You have the right to object to the processing of your data, as well as to request that the personal data concerning you be erased or destroyed.

Business Services

We process the data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as “contractual partners”), within the framework of contractual and comparable legal relationships as well as associated measures, and with regard to communication with the contractual partners (or pre-contractually), for example to answer inquiries.

We use this data to fulfill our contractual obligations. This includes in particular the obligations to provide the agreed services, any update obligations and remedies in the event of warranty and other performance disruptions. In addition, we use the data to safeguard our rights and for the purpose of the administrative tasks associated with these obligations as well as company organization. Furthermore, we process the data on the basis of our legitimate interests both in the proper and business-oriented management of the company as well as in security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information and rights (e.g. for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the framework of applicable law, we only pass on the data of contractual partners to third parties insofar as this is necessary for the aforementioned purposes or to fulfill legal obligations. The contractual partners are informed of further forms of processing, for example for marketing purposes, within the framework of this privacy policy.

We inform the contractual partners of which data is required for the aforementioned purposes before or in the course of the data collection, e.g. in online forms, by means of special marking (e.g. colors) or symbols (e.g. asterisks or similar), or in person.

We erase the data after the expiry of statutory warranty and comparable obligations, i.e. in principle after six years, unless the data is stored in a customer account, e.g. as long as it must be retained for legal reasons of archiving (e.g. for tax purposes, as a rule ten years). Data disclosed to us by the contractual partner in the course of an order, we erase in accordance with the requirements and in principle after the end of the order.

Types of data processed: Inventory data; payment data; contact data; contract data; usage data. Data subjects: Service recipients and clients; prospective customers; business and contractual partners. Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; communication; organizational and administrative procedures; business processes and management procedures; conversion measurement. Retention and erasure: Erasure in accordance with the information in the section “General Information on Data Storage and Erasure”. Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).

Further Notes on Processing Operations, Procedures and Services (Business Services)

Provision of software and platform services: We process the data of our users, registered and any test users (hereinafter uniformly referred to as “users”), in order to be able to provide them with our contractual services as well as on the basis of legitimate interests in order to be able to ensure the security of our offering and to develop it further. The required information is marked as such in the context of the order, purchase or comparable conclusion of a contract and includes the information required for the provision of services and billing as well as contact information in order to be able to hold any consultations; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR).

Event management: We process the data of participants of the events, functions and similar activities offered or organized by us (hereinafter uniformly referred to as “participants” and “events”) in order to enable them to participate in the events and to make use of the services or actions associated with the participation. Insofar as we process health-related data, religious, political or other special categories of data in this context, this takes place within the framework of obviousness (e.g. in the case of thematically oriented events) or serves health care, security, or takes place with the consent of the data subjects; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR).

Brokerage services: We process the information provided by prospective customers in the context of the brokerage inquiry for the purposes of establishing, performing and, where applicable, terminating a contract for the brokerage of offers from providers of the products or services they have requested. We use the contact data of the prospective customers to specify their inquiry by means of the agreed or otherwise permitted communication channel (e.g. telephone or email) and to propose suitable providers or offers to them on the basis of the specified inquiry. In addition, we may, at a later point in time, in accordance with legal requirements, ask prospective customers follow-up questions about the success of our brokerage service. We process the data of the prospective customers as well as the providers in order to fulfill our contractual obligations, to link the inquiry of the prospective customers submitted to us with the offers of the providers matching it and to forward it to corresponding providers, or to propose the providers. We may log the entries in the online form sent by prospective customers in order to be able to prove the existence of the contractual relationship and the consents of the prospective customers in accordance with the legal accountability obligations (Art. 5(2) GDPR). This information is stored for a period of six years in order to be able to comply with the tax-law retention obligations; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR).

Business Processes and Procedures

Personal data of service recipients and clients – including customers, clients or, in special cases, mandates or business partners as well as other third parties – is processed within the framework of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates business management processes in areas such as customer management, sales, payment transactions, accounting and project management.

The collected data serves to fulfill contractual obligations and to structure operational processes efficiently. This includes the handling of business transactions, the management of customer relationships, the optimization of sales strategies as well as ensuring internal accounting and financial processes. In addition, the data supports the safeguarding of the controller’s rights and promotes administrative tasks as well as the organization of the company.

Personal data may be passed on to third parties insofar as this is necessary for the fulfillment of the aforementioned purposes or legal obligations. After the expiry of statutory retention periods or when the purpose of the processing ceases to apply, the data is erased.

Types of data processed: Inventory data; payment data; contact data; content data; contract data; usage data; meta, communication and procedural data; log data. Data subjects: Service recipients and clients; prospective customers; communication partners; business and contractual partners; customers; third parties; users; employees. Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; business processes and management procedures; security measures; provision of our online offering and user-friendliness; communication; marketing; sales promotion; financial and payment management; information technology infrastructure. Retention and erasure: Erasure in accordance with the information in the section “General Information on Data Storage and Erasure”. Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR).

Further Notes on Processing Operations, Procedures and Services (Business Processes)

Contact management and contact maintenance: Procedures that are required in the context of the organization, maintenance and securing of contact information (e.g. the setup and maintenance of a central contact database, regular updates of the contact information, monitoring of data integrity, implementation of data protection measures, ensuring access controls, performance of backups); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR).

Customer account: Customers can create an account within our online offering (e.g. customer or user account, in short “customer account”). If the registration of a customer account is required, customers are informed of this as well as of the information required for registration. The customer accounts are not public and cannot be indexed by search engines. In the course of registration as well as subsequent logins and uses of the customer account, we store the IP addresses of the customers along with the access times in order to be able to prove the registration and to prevent any misuse of the customer account. If the customer account has been terminated, the data of the customer account is erased after the time of termination, unless it is retained for purposes other than provision in the customer account, or must be retained for legal reasons (e.g. internal storage of customer data, ordering processes or invoices). It is the responsibility of the customers to back up their data upon termination of the customer account; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR).

Bookmark list/search agents: Users can create bookmark lists and set up search agents that inform them about new offers matching their criteria. The corresponding entries are stored in the context of the fulfillment of our contractual obligations until the account is deleted, unless the entries are removed by the user or we expressly inform the user of differing storage periods; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR).

Accounting, accounts payable, accounts receivable: Procedures that are required in the recording, processing and control of business transactions in the area of accounts payable and accounts receivable (e.g. creation and verification of incoming and outgoing invoices, monitoring and management of open items, execution of payment transactions, handling of the dunning process, account reconciliation); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legal obligation (Art. 6(1)(1)(c) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR).

Payment Procedures

Within the framework of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer the data subjects efficient and secure payment options and, for this purpose, use other service providers in addition to banks and credit institutions (collectively “payment service providers”).

The data processed by the payment service providers includes inventory data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as the contract, sum and recipient-related information. The information is required in order to carry out the transactions. However, the entered data is only processed by the payment service providers and stored with them. That is, we do not receive any account- or credit card-related information, but only information with confirmation or negative disclosure of the payment. Under certain circumstances, the data is transmitted by the payment service providers to credit agencies. In this regard, we refer to the terms and conditions and the data protection notices of the payment service providers.

Types of data processed: Inventory data; payment data; contract data; usage data; meta, communication and procedural data. Data subjects: Service recipients and clients; business and contractual partners. Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; business processes and management procedures. Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).

Further Notes on Processing Operations, Procedures and Services (Payment Procedures)

Stripe: Payment services (checkout, subscription and invoice management, customer portal); in the course of the payment process, among other things, email address, customer reference, price, subscription and invoice data as well as the status of the payment method are processed; the complete payment data (e.g. credit card numbers) is collected and stored exclusively by Stripe; service provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legal obligation (Art. 6(1)(1)(c) GDPR); website: https://stripe.com/de; privacy policy: https://stripe.com/de/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Stripe, Inc., supplemented by standard contractual clauses.

Provision of the Online Offering and Web Hosting

We process the data of the users in order to be able to provide them with our online services. For this purpose, we process the IP address of the user, which is necessary in order to transmit the content and functions of our online services to the browser or the end device of the users.

Types of data processed: Log data; content data; meta, communication and procedural data. Data subjects: Users. Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure; security measures. Retention and erasure: Erasure in accordance with the information in the section “General Information on Data Storage and Erasure”. Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR).

Further Notes on Processing Operations, Procedures and Services (Online Offering)

Provision of the online offering on rented infrastructure: For the provision of our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding infrastructure provider (also called “cloud provider”); Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR).

Collection of access data and log files: Access to our online offering is logged in the form of so-called “server log files”. The server log files may include the address and name of the retrieved web pages and files, the date and time of retrieval, the amount of data transferred, notification of successful retrieval, browser type and version, the operating system of the user, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used, on the one hand, for security purposes, e.g. to avoid overloading the servers (in particular in the case of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure the utilization of the servers and their stability. In addition, we log security-relevant events (e.g. logins and essential account actions) in order to prevent misuse and to be able to prove processes; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR). Erasure of data: Log file information is stored for a maximum period of 30 days and then erased or anonymized. Data whose further retention is required for evidentiary purposes is exempt from erasure until the final clarification of the respective incident.

Google Cloud Platform: Services in the field of the provision of information technology infrastructure and associated services (e.g. computing capacity, databases, storage space and delivery of media and user uploads, queuing and scheduling services, monitoring as well as security services such as web application firewall and abuse protection); the processing generally takes place in the Frankfurt am Main region (europe-west3); service provider: Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); website: https://cloud.google.com; privacy policy: https://policies.google.com/privacy; data processing agreement: https://cloud.google.com/terms/data-processing-addendum; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC, supplemented by standard contractual clauses.

Email sending and hosting: We operate our business mailboxes (e.g. for contact and data protection inquiries) via Microsoft 365. For these purposes, the addresses of the recipients and senders as well as further information concerning the email dispatch (e.g. the providers involved) as well as the contents of the respective emails are processed. The aforementioned data may furthermore be processed for the purposes of detecting SPAM. We ask you to note that emails on the Internet are generally not sent in end-to-end encrypted form. We can therefore not assume any responsibility for the transmission route of the emails between the sender and the receipt on our server; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); privacy policy: https://privacy.microsoft.com/de-de/privacystatement; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Microsoft Corporation, supplemented by standard contractual clauses.

The term “cookies” is understood to mean functions that store information on users’ terminal equipment and read it out from them. Cookies can furthermore be used in relation to different concerns, for example for the purposes of the functionality, security and comfort of online offerings as well as the creation of analyses of visitor flows. We use cookies in accordance with the legal provisions. For this purpose, we obtain the prior consent of the users where necessary. Where consent is not necessary, we rely on our legitimate interests. This applies where the storage and reading out of information is essential in order to be able to provide expressly requested content and functions (Section 25(2) TDDDG).

Notes on the possibility of withdrawal and objection (opt-out): Users can withdraw the consents they have given at any time and furthermore object to the processing in accordance with the legal requirements. For this purpose, users can, among other things, restrict the use of cookies in the settings of their browser or adjust the consent settings via the data protection button provided on our pages.

On our platform, we use in particular the following own cookies and comparable storage technologies:

  • amber_session / amber_admin_session (cookie, 7 days): maintenance of the login session; strictly necessary.
  • csrf_token (cookie, session duration): protection against cross-site request forgery attacks; strictly necessary.
  • amber_authed (cookie, 7 days): display of the login status in the user interface; contains no personal content.
  • active_profile (cookie, 1 year): storage of the selected buyer or seller profile.
  • amber_listing_visitor_id (cookie, 400 days): pseudonymous visitor identifier for counting and deduplicating listing views. If you log in with a user account, views previously recorded under this identifier may be linked to your user account in order to provide sellers with aggregated reach information on their listings.
  • Furthermore, we use local storage in the browser (localStorage/sessionStorage) for functional purposes, e.g. for the temporary storage of entries in form wizards and of interface settings.

Usercentrics: Consent management: Procedures for obtaining, logging, managing and withdrawing consents, in particular for the use of cookies and comparable technologies; the consent status, the time of consent, device information and setting identifiers are stored; the storage duration of the consent documentation is one year; service provider: Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany; Legal bases: Legal obligation (Art. 6(1)(1)(c) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR – proof of consents); website: https://usercentrics.com/de; privacy policy: https://usercentrics.com/de/datenschutzerklaerung/.

Registration, Login and User Account

Users can create a user account. In the course of registration, the required mandatory information is communicated to the users and processed for the purposes of providing the user account on the basis of the performance of contractual obligations. The processed data includes in particular the login information (name, email address, password) as well as profile-related information (e.g. role as buyer or seller, company and search criteria).

In the course of using our registration and login functions as well as the use of the user account, we store the IP address and the time of the respective user action. The storage takes place on the basis of our legitimate interests as well as those of the users in protection against misuse and other unauthorized use. This data is generally not passed on to third parties, unless it is necessary to pursue our claims or there is a legal obligation to do so. The users can be informed by email about processes that are relevant to their user account, such as technical changes.

Types of data processed: Inventory data; contact data; content data; log data. Data subjects: Users. Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; security measures; organizational and administrative procedures. Retention and erasure: Erasure in accordance with the information in the section “General Information on Data Storage and Erasure”; erasure after termination. Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).

Further Notes on Processing Operations, Procedures and Services (Registration/User Account)

WorkOS: Identity and login service for registration, login, password reset and email verification; email address, name, login data, user identifiers, role and profile information as well as login times are processed; service provider: WorkOS, Inc., 548 Market Street, PMB 86125, San Francisco, CA 94104, USA; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR – account security); website: https://workos.com; privacy policy: https://workos.com/legal/privacy; basis for third-country transfers: standard contractual clauses (Art. 46(2)(c) GDPR).

Migration of existing user accounts: For user accounts that have been migrated from the previous DUB platform, we check the entered access data on first login against the previous login information stored in encrypted form and, if successful, transfer the account to our current login system. The password is thereby only processed for the duration of the login process and not stored in plain text; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR).

Erasure of data after termination: If users have terminated their user account, their data with regard to the user account is erased, subject to a legal permission, obligation or consent of the users. It is incumbent on the users to back up their data upon termination before the end of the contract; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR).

Contact and Inquiry Management

When contacting us (e.g. by post, contact form, email, telephone or via social media) as well as within the framework of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to answer the contact inquiries and any requested measures.

Forwarding to selected advisors and providers: Inquiries via the contact forms of our advisor and tool directory (name, position, company, email address, telephone number, message) are forwarded by us to the advisor or provider selected by you in each case, so that they can answer your inquiry. Likewise, in the case of an expression of interest in a listing or purchase request, the contact information provided by you is made accessible to the respective provider or advertiser for contacting you.

Types of data processed: Inventory data; contact data; content data; meta, communication and procedural data. Data subjects: Communication partners. Purposes of processing: Communication; organizational and administrative procedures; feedback; provision of our online offering and user-friendliness. Retention and erasure: Erasure in accordance with the information in the section “General Information on Data Storage and Erasure”. Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); legitimate interests (Art. 6(1)(1)(f) GDPR).

Further Notes on Processing Operations, Procedures and Services (Contact)

Google reCAPTCHA: Protection of forms as well as login and registration processes against misuse and automated access; IP address, device and browser information as well as interaction signals are processed; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR – security and misuse prevention); privacy policy: https://policies.google.com/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC.

HubSpot: Collection and management of inquiries, in particular via the company value calculator, as well as CRM-supported contact management; salutation, name, email address, company details (including industry, company size, revenue and earnings figures, valuation result) as well as the page context of the inquiry and the time of consent are processed; service provider: HubSpot Ireland Limited, HubSpot House, 1 Sir John Rogerson’s Quay, Dublin 2, D02 CR67, Ireland (group: HubSpot, Inc., USA); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR – contact management); website: https://www.hubspot.de; privacy policy: https://legal.hubspot.com/de/privacy-policy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of HubSpot, Inc.

Messaging Function of the Platform

For direct communication between buyers, sellers and advisors, we provide a messaging function.

Stream Chat: Provision of the messaging function; user identifiers, channel and conversation assignments (e.g. to listings and purchase requests), message contents as well as transmitted files and images are processed; our account is set to a European data region, i.e. the storage and processing of the message data take place within the EU; service provider: Stream.io, Inc., 1215 Spruce Street, Suite 300, Boulder, CO 80302, USA; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); website: https://getstream.io; privacy policy: https://getstream.io/legal/privacy/; basis for any third-country transfers (e.g. in the case of the provider’s support access): standard contractual clauses (Art. 46(2)(c) GDPR).

Confidentiality Agreements and Electronic Signature

In order to access confidential information of a sales offer, the conclusion of a confidentiality agreement (NDA), which is signed electronically, may be required.

Docusign: Creation, sending and electronic signature of confidentiality agreements; name, email address, company and address details, role and signing order of the signatories, the document itself as well as status and timestamp information including any reasons for rejection are processed; service provider: Docusign International (EMEA) Limited, Unit 3100, Lake Drive, Citywest Business Campus, Dublin 24, D24 AK82, Ireland (group: Docusign, Inc., USA); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR – proof of the signature), legal obligation (Art. 6(1)(1)(c) GDPR – retention of business documents); website: https://www.docusign.de; privacy policy: https://www.docusign.com/de-de/datenschutz; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Docusign, Inc., supplemented by standard contractual clauses.

Appointment Booking for User Verification

For the verification of certain user profiles, we offer the booking of a personal meeting appointment.

Calendly: Booking of verification appointments; name, email address, language, time zone as well as appointment and status data (booking, cancellation, rescheduling) are processed; service provider: Calendly LLC, 1315 Peachtree St. NE, Atlanta, GA 30309, USA; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); website: https://calendly.com; privacy policy: https://calendly.com/de/pages/privacy; basis for third-country transfers: standard contractual clauses (Art. 46(2)(c) GDPR).

Microsoft Teams: Conduct of the verification meetings by video conference via automatically generated Teams meeting links; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); privacy policy: https://privacy.microsoft.com/de-de/privacystatement; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Microsoft Corporation.

To support our users, we use functions that automatically generate, translate or make text content searchable. In doing so, the respective content concerned (e.g. listing texts, purchase requests, search queries) is transmitted to the service providers named below. Automated decision-making that produces legal effects concerning you or similarly significantly affects you does not take place.

OpenAI (text creation): AI-supported creation and revision of listing texts at the request of the user; the listing contents and user inputs required for generation are transmitted to a language model of the provider OpenAI; we use the OpenAI interface with European data residency, i.e. the processing of the requests and the storage take place in a region within Europe; the contents are not used to train the models; service provider: OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland (group: OpenAI, L.L.C., USA); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR – function requested by the user); website: https://openai.com; privacy policy: https://openai.com/policies/privacy-policy; basis for any third-country transfers (e.g. in the case of the group’s support access): EU-US Data Privacy Framework (DPF) – certification of OpenAI, L.L.C., supplemented by standard contractual clauses.

OpenAI (semantic search): For the provision of our similarity and recommendation search, listing, purchase request and search contents are transmitted to OpenAI in order to calculate mathematical representations (so-called embeddings) from them; for this too we use the OpenAI interface with European data residency; the storage of the representations and the performance of the search take place in our European search infrastructure; service provider: OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland (group: OpenAI, L.L.C., USA); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); privacy policy: https://openai.com/policies/privacy-policy; basis for any third-country transfers: EU-US Data Privacy Framework (DPF) – certification of OpenAI, L.L.C., supplemented by standard contractual clauses.

Elastic Cloud: Search and similarity functions of the platform (full-text and semantic search, search agents and notifications); listing, purchase request and profile contents are indexed; the processing takes place in an EU region (Belgium, europe-west1); service provider: Elasticsearch B.V., Keizersgracht 281, 1016 ED Amsterdam, Netherlands; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR); website: https://www.elastic.co/de; privacy policy: https://www.elastic.co/de/legal/privacy-statement.

DeepL: Machine translation of listing, purchase request and directory texts for the provision of a multilingual offering; service provider: DeepL SE, Maarweg 165, 50825 Cologne, Germany; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR – multilingual offering); website: https://www.deepl.com; privacy policy: https://www.deepl.com/de/privacy.

Newsletter and Electronic Notifications

We send newsletters, emails and further electronic notifications (hereinafter “newsletter”) exclusively with the consent of the recipients or on the basis of a legal basis. Insofar as the contents of a newsletter are named in the course of a subscription to it, these contents are decisive for the consent of the users. For the subscription to our newsletter, it is normally sufficient to provide your email address. However, in order to be able to offer you a personalized service, we may ask for your name for personal address in the newsletter.

Double-opt-in procedure: The subscription to our newsletter takes place in a so-called double-opt-in procedure. That is, after the subscription you receive an email in which you are asked to confirm your subscription. This confirmation is necessary so that no one can register with someone else’s email address. The subscriptions to the newsletter are logged in order to be able to prove the subscription process in accordance with the legal requirements. This includes the storage of the subscription and confirmation time as well as the IP address.

Measurement of open and click rates: The newsletters contain so-called “web beacons”, i.e. pixel-sized files that are retrieved from our server or the server of the dispatch service provider when the newsletter is opened. In the course of this retrieval, technical information, such as information on the browser and your system, as well as your IP address and the time of retrieval, is first collected. This information is used for the technical improvement of our newsletter on the basis of the technical data or the target groups and their reading behavior on the basis of their retrieval locations or the access times. This analysis also includes the determination of whether the newsletters are opened, when they are opened and which links are clicked. A separate possibility of withdrawal solely for the reach measurement is unfortunately not provided; in this case the entire newsletter subscription must be terminated or objected to.

Erasure and restriction of processing: We may store the unsubscribed email addresses for up to three years on the basis of our legitimate interests before we erase them, in order to be able to prove a consent formerly given. The processing of this data is limited to the purpose of a potential defense against claims. An individual erasure request is possible at any time, provided that the former existence of a consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocking list (so-called “blocklist”).

Types of data processed: Inventory data; contact data; meta, communication and procedural data; usage data. Data subjects: Communication partners. Purposes of processing: Direct marketing; analysis of the usage behavior of the newsletter (opens, clicks). Retention and erasure: Until the withdrawal of consent, subsequently for evidentiary purposes. Legal bases: Consent (Art. 6(1)(1)(a) GDPR). Possibility of withdrawal (opt-out): You can terminate the receipt of our newsletter at any time, i.e. withdraw your consents or object to further receipt. You will find a link to terminate the newsletter at the end of each newsletter, or you can use one of the contact options given above, preferably email, for this purpose.

Further Notes on Processing Operations, Procedures and Services (Newsletter)

Twilio SendGrid: Sending of newsletters as well as transactional and operational emails; email address, name, content and template data as well as delivery and interaction information are processed; we use the service with European data residency, i.e. the processing and storage of the email data take place in a region within the EU; service provider: Twilio Inc., 101 Spear Street, San Francisco, CA 94105, USA; Legal bases: Consent (Art. 6(1)(1)(a) GDPR – newsletter), performance of a contract (Art. 6(1)(1)(b) GDPR – transactional emails), legitimate interests (Art. 6(1)(1)(f) GDPR – efficient and secure dispatch); website: https://sendgrid.com; privacy policy: https://www.twilio.com/de-de/legal/privacy; basis for any third-country transfers (e.g. in the case of the group’s support access): EU-US Data Privacy Framework (DPF) – certification of Twilio Inc., supplemented by standard contractual clauses.

Brevo: Management of the newsletter recipient lists (recipient data, subscription status, account type, registration date, blocking list); service provider: Sendinblue SAS (Brevo), 106 boulevard Haussmann, 75008 Paris, France; Legal bases: Consent (Art. 6(1)(1)(a) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR – proof of subscriptions and unsubscriptions); website: https://www.brevo.com/de; privacy policy: https://www.brevo.com/de/legal/privacypolicy.

Error Diagnosis and Stability

Sentry: Monitoring of the technical stability of our online offering through the collection of error events and performance data (including error messages, affected pages and requests, browser and device information as well as pseudonymous user and request identifiers); the event data is received in an EU region; service provider: Functional Software, Inc. (dba Sentry), 45 Fremont Street, San Francisco, CA 94105, USA; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR – error detection and stability); website: https://sentry.io; privacy policy: https://sentry.io/privacy/; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Functional Software, Inc.

Web Analytics, Marketing and Conversion Measurement

We use the following services for reach measurement, for measuring the effectiveness of our marketing measures and for target group formation. With the exception of the cookielessly operated service etracker, the use only takes place with your consent, which you give via our consent management and can withdraw at any time (Art. 6(1)(1)(a) GDPR in conjunction with Section 25(1) TDDDG).

Further Notes on Processing Operations, Procedures and Services (Web Analytics/Marketing)

Google Tag Manager: Management and delivery of the measurement and marketing services used by us; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); privacy policy: https://policies.google.com/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC.

Google Analytics 4: Reach measurement and analysis of the usage behavior of our online offering; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); website: https://marketingplatform.google.com/intl/de/about/analytics/; privacy policy: https://policies.google.com/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC.

Google Ads and conversion measurement: Measurement of the effectiveness of advertising measures and remarketing; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); privacy policy: https://policies.google.com/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC.

Meta Pixel: Conversion measurement and target group formation for advertising on Meta platforms (Facebook, Instagram); service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); privacy policy: https://www.facebook.com/privacy/policy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Meta Platforms, Inc.

etracker

The provider of this website uses the web analytics service etracker (JustRelate Group, etracker GmbH, www.etracker.com) for reach measurement and for the analysis of usage data. etracker is operated in a configuration without cookies and without consent-requiring storage of or access to information on your terminal device. Even if you reject statistical or marketing-related cookies, anonymized usage data is collected in the process — in accordance with the requirements of the EU General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG). The data processing is carried out on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in statistical, data-minimizing reach measurement and the optimization of our online offering.

The web analytics data generated with etracker is processed and stored on behalf of the provider of this website by etracker GmbH (JustRelate Group) exclusively in Germany and is therefore subject to the strict German and European data protection laws and standards. In this respect, etracker has been independently audited, certified and awarded the ePrivacyseal data protection seal of quality. As the privacy of our visitors is important to us, data that could possibly allow a reference to an individual person — such as the IP address or login or device identifiers — is anonymized or pseudonymized as early as possible. It is not used for any other purpose, combined with other data or passed on to third parties.

You can object to the data processing described above at any time by clicking on the following slider. The objection has no disadvantageous consequences. If no slider is displayed, data collection is already being prevented by other blocking measures.



You can find further information on data protection at etracker here.

SalesViewer: Recognition of company visits on the pages of our advisor directory for the acquisition of business prospects; page views, referrer as well as network and device-related identifiers are processed, from which the visiting company (not the individual person) is determined; service provider: SalesViewer GmbH, Universitätsstraße 60, 44789 Bochum, Germany; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); website: https://www.salesviewer.com; privacy policy: https://www.salesviewer.com/de/datenschutz.

Integrated Third-Party Functions and Content

We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may, for example, be graphics, videos, fonts or map functions. The integration always presupposes that the third-party providers of this content process the IP address of the users, since without the IP address they could not send the content to their browser. Third-party providers may furthermore use so-called pixel tags or other identifiers for statistical or marketing purposes.

Further Notes on Processing Operations, Procedures and Services (Third-Party Content)

Google Fonts (obtained from the Google server): Integration of fonts for the purpose of a technically secure, maintenance-free and efficient use of fonts with regard to currency and loading times as well as their uniform display; upon retrieval, the IP address, user-agent information and the referrer are transmitted to Google; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(1)(f) GDPR); website: https://fonts.google.com/; privacy policy: https://policies.google.com/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC.

Google Maps Platform: Address autocompletion and radius functions (e.g. during registration and in the advisor directory); the addresses or locations entered by you, coordinates determined from them as well as your IP address are processed; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(1)(b) GDPR – function requested by you); privacy policy: https://policies.google.com/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC.

YouTube videos: Integration of videos, e.g. in listings and announcements; when the player is loaded, IP address, device information and interaction data are transmitted to YouTube; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); website: https://www.youtube.com; privacy policy: https://policies.google.com/privacy; basis for third-country transfers: EU-US Data Privacy Framework (DPF) – certification of Google LLC.

Vimeo: Integration of videos; when the player is loaded, IP address, device information and video metadata are transmitted to Vimeo; service provider: Vimeo.com, Inc., 330 West 34th Street, New York, NY 10001, USA; Legal bases: Consent (Art. 6(1)(1)(a) GDPR); website: https://vimeo.com; privacy policy: https://vimeo.com/privacy; basis for third-country transfers: standard contractual clauses (Art. 46(2)(c) GDPR).

Presence on Social Networks (Social Media)

Facebook and Instagram Presence

At the URLs https://www.facebook.com/dubunternehmerboerse as well as https://www.instagram.com/dealcircle_official/ we operate presences on the social networks “Facebook” and “Instagram”, which are operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. You can find the data protection policies at: https://www.facebook.com/about/privacy and https://help.instagram.com/519522125107875/.

The access to and every interaction on our Facebook fan page or our Instagram presence leads to a processing of personal data, whereby it makes no difference whether you have an account with Facebook or Instagram or not. If, during the access to one of our two presences, you are logged in with your Facebook account, Meta and/or its affiliated companies may combine the information about the access to the Facebook fan page or the Instagram presence with your account information and use this, under certain circumstances, to form profiles. If you do not wish such profile formation, please log out of your Facebook account before accessing our presences.

Facebook and Instagram provide us, via the “Insights” function, with statistical data on the use of our presences (including gender, age range, location, page views, interactions, reach). From this data we cannot draw conclusions about individual visitors. Our use of the data generated by “Insights” takes place on the basis of Art. 6(1)(f) GDPR; our legitimate interests consist of making our presences more attractive. Since we are jointly responsible with Meta for the processing of your data on our presences, we have concluded an agreement with Meta, the content of which you can view here: https://www.facebook.com/legal/terms/page_controller_addendum. You can assert your data subject rights, at your choice, vis-à-vis us or Meta (https://privacycenter.instagram.com/policy/). If you assert your rights vis-à-vis us, we will forward your inquiries there in accordance with our agreement with Meta.

LinkedIn Presence

At the URL https://www.linkedin.com/company/deutsche-unternehmerb-rse/ we operate a presence on the social network LinkedIn, a service of LinkedIn Ireland Unlimited Company. Information on the data processing by LinkedIn can be found at https://www.linkedin.com/legal/privacy-policy. The access to and every interaction on our LinkedIn presence leads to a processing of personal data, regardless of whether you have a LinkedIn account. If you are logged in, LinkedIn may combine the information with your account information and use it for profile formation; please log out beforehand if applicable. LinkedIn provides us, via “Page Insights”, with statistical data from which we cannot draw conclusions about individual visitors (legal basis: Art. 6(1)(f) GDPR). Since we are jointly responsible with LinkedIn, the agreement at https://legal.linkedin.com/pages-joint-controller-addendum applies. You can assert your data subject rights vis-à-vis us; we forward inquiries to LinkedIn in accordance with the agreement.

YouTube Presence

At the URL https://www.youtube.com/channel/UCycZW_tBmElB7Uu2PbOSODw we operate a presence on the social network YouTube, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Information on the data processing by YouTube can be found at https://policies.google.com/privacy. Google provides us, via “YouTube Analytics”, with statistical data on the use of our presence (including reach, interaction, basic statistical data about the audience), from which we cannot draw conclusions about individual visitors (legal basis: Art. 6(1)(f) GDPR). The access to and every interaction on our YouTube presence leads to a processing of personal data, regardless of whether you have a YouTube account. If you are logged in, Google may combine the information with your account information and use it for profile formation; please log out beforehand if applicable.

Types of Data – Explanation of Terms

The following explanations are intended above all to aid understanding.

  • Inventory data: Inventory data comprises essential information that is necessary for the identification and management of contractual partners, user accounts, profiles and similar allocations. This data may include, among other things, personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs).

  • Content data: Content data comprises information that is generated in the course of the creation, editing and publication of content of all kinds. This category can include texts, images, videos, audio files and other multimedia content, as well as metadata that provides information about the content itself, such as tags, descriptions, author information and publication dates.

  • Contact data: Contact data is essential information that enables communication with persons or organizations. It comprises, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.

  • Meta, communication and procedural data: Categories that contain information about the manner in which data is processed, transmitted and managed. Meta data describes the context, origin and structure of other data (e.g. file size, creation date, modification histories). Communication data records the exchange of information between users via various channels (e.g. email traffic, message histories, persons involved, timestamps). Procedural data describes processes and workflows within systems (e.g. logs of transactions and activities, audit logs).

  • Usage data: Usage data relates to information that records how users interact with digital products, services or platforms (e.g. pages visited, duration of visit, click paths, frequency of use, device information, location data). It is valuable for the analysis of user behavior and the optimization of offerings.

  • Log data: Log data is information about events or activities that have been logged in a system or network (e.g. timestamps, IP addresses, user actions, error messages). It is often used for the analysis of system problems, for security monitoring or for the creation of performance reports.

  • Contract data: Contract data is specific information that relates to the formalization of an agreement between two or more parties (e.g. contracting parties, terms, services, price agreements, payment terms, termination rights).

  • Payment data: Payment data comprises all information that is needed to process payment transactions (e.g. bank details, payment amounts, transaction data, invoice information as well as information about the payment status).

Last updated: 17 July 2026