Privacy Policy
Please note: this is a translation provided for convenience. Only the German version of this privacy policy is legally binding. In the event of any discrepancy, the German text prevails.
1. Data protection at a glance
General information
The following notes provide a straightforward overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in the privacy policy set out below this text.
Data collection on this website
Who is responsible for the collection of data on this website?
Data on this website is processed by the website operator. You can find their contact details in the section “Information on the controller” in this privacy policy.
How do we collect your data?
Some of your data is collected because you provide it to us. This may be data you enter into a contact form, for example.
Other data is collected automatically, or with your consent, by our IT systems when you visit the website. This is mainly technical data such as your browser, your operating system or the time of the page view. This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse how you use the site. Where contracts can be concluded or initiated via the website, the transmitted data is also processed for contract offers, orders or other enquiries.
What rights do you have regarding your data?
You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you may withdraw that consent at any time with effect for the future. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. In addition, you have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this and any further questions on data protection.
Analysis tools and third-party tools
When you visit this website, your browsing behaviour may be analysed statistically. This is done mainly using analysis programs.
Detailed information on these analysis programs can be found in the privacy policy below.
2. Hosting
We host the content of our website with the following providers:
Hetzner
The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hereinafter Hetzner).
For details, please see Hetzner's privacy policy: https://www.hetzner.com/de/legal/privacy-policy/.
Hetzner is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (for example device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Data processing agreement
We have concluded a data processing agreement for the use of the service named above. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.
Strato
The provider is Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (hereinafter “Strato”). When you visit our website, Strato records various log files including your IP address.
Further information can be found in Strato's privacy policy: https://www.strato.de/datenschutz/.
Strato is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (for example device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Data processing agreement
We have concluded a data processing agreement for the use of the service named above. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.
External hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the host or hosts. This may in particular include IP addresses, contact requests, metadata and communication data, contract data, contact details, names, website access records and other data generated through a website.
External hosting takes place for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (for example device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Our host or hosts will process your data only to the extent necessary to fulfil their service obligations and will follow our instructions in relation to this data.
We use the following host:
dogado GmbH
Antonio-Segni-Straße 11
D-44263 Dortmund, Germany
3. General information and mandatory disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various items of personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.
Please note that data transmission over the internet, for example when communicating by email, can have security gaps. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller for data processing on this website is:
BITSS GmbH
Michael Nicolas Köhler
Amselweg 28
63674 Altenstadt
Phone: +49 6047 670 929 0
Email: info@bitss.de
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data such as names or email addresses.
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data remains with us until the purpose for processing it no longer applies. If you assert a justified request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data, such as retention periods under tax or commercial law. In the latter case, deletion takes place once those grounds cease to apply.
General information on the legal bases for data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR, or Art. 9(2)(a) GDPR where special categories of data pursuant to Art. 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, processing also takes place on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device, for example via device fingerprinting, processing additionally takes place on the basis of section 25(1) TDDDG. Consent may be withdrawn at any time. If your data is required for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. We also process your data where this is necessary to fulfil a legal obligation, on the basis of Art. 6(1)(c) GDPR. Processing may further take place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. The legal bases relevant in each individual case are set out in the following paragraphs of this privacy policy.
Information on data transfers to third countries that are not secure under data protection law and to US companies that are not DPF-certified
Among other things, we use tools from companies based in third countries that are not secure under data protection law, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in those countries. Please note that in third countries that are not secure under data protection law, a level of data protection comparable to that of the EU cannot be guaranteed.
Please note that, as a secure third country, the USA generally offers a level of data protection comparable to that of the EU. A transfer of data to the USA is therefore permissible if the recipient holds a certification under the EU-US Data Privacy Framework (DPF) or has suitable additional safeguards in place. Information on transfers to third countries, including the recipients of the data, can be found in this privacy policy.
Recipients of personal data
In the course of our business we work with various external parties. In some cases this also requires the transfer of personal data to those external parties. We only pass personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so (for example transferring data to tax authorities), where we have a legitimate interest in the transfer pursuant to Art. 6(1)(f) GDPR, or where another legal basis permits the transfer. Where processors are used, we pass on our customers' personal data only on the basis of a valid data processing agreement. In the case of joint processing, a joint controller agreement is concluded.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your explicit consent. You may withdraw consent you have already given at any time. The lawfulness of the data processing carried out up to the point of withdrawal remains unaffected.
Right to object to data collection in particular cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING TAKES PLACE ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE LEGAL BASIS ON WHICH ANY PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING. THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS CONNECTED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work or the place of the alleged infringement. This right exists without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place where technically feasible.
Access, correction and deletion
Within the framework of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of the processing, and where applicable a right to have this data corrected or deleted. You can contact us at any time regarding this and any further questions on personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of the personal data we hold about you, we usually need time to verify this. For the duration of that review you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you may request the restriction of processing instead of deletion.
- If we no longer need your personal data but you require it to exercise, defend or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, a balance must be struck between your interests and ours. For as long as it has not been established whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, that data may, apart from being stored, only be processed with your consent or for the assertion, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
SSL and TLS encryption
For security reasons, and to protect the transmission of confidential content such as orders or enquiries you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the browser address bar changing from “http://” to “https://” and by the padlock symbol in your browser bar.
When SSL or TLS encryption is active, the data you transmit to us cannot be read by third parties.
Objection to advertising emails
We hereby object to the use of contact data published in fulfilment of the legal notice obligation for the purpose of sending advertising and information material that has not been expressly requested. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising being sent, for example by spam email.
4. Data collection on this website
Contact form and email delivery
When you use the contact form, we process the details you enter, in particular your name, company, email address and/or telephone number, subject, urgency, call-back preference and message, in order to handle your enquiry. The form language, contact page and, where present, the campaign parameters UTM source, UTM medium and UTM campaign are also included in the email. The contents of form fields are not stored in the web statistics.
The message is sent from our web server via a STARTTLS-encrypted SMTP connection to the BITSS mailbox designated for enquiries. The provider of the email and SMTP service used for this purpose is netbeat GmbH, Obermünsterstraße 9, 93047 Regensburg, Germany. netbeat's technical service provider is Vautron Rechenzentrum AG, Obermünsterstraße 9, 93047 Regensburg, Germany. Further information is provided in netbeat's privacy policy. According to the provider, the servers used are operated in Germany. The submitted information is processed as an email and retained for as long as required to deal with the enquiry, for possible pre-contractual measures, or to comply with statutory retention duties.
To protect against automated abuse, the form uses a session-based CSRF identifier, an invisible empty field, a minimum completion time and a server-side limit on submission attempts. For that limit, the IP address is transformed with a server-only secret into a non-reversible HMAC value. Only that value and the attempt timestamps are stored, entries older than 24 hours are ignored for the check and are technically removed after a short grace period.
After the SMTP server accepts a successful submission, an anonymous receipt is additionally placed in a protected server-side queue and then counted only in hourly aggregates by contact page, language, subject category and the broad status “local statistics enabled”, “local statistics not enabled” or “no valid selection detected”. This allows the delivery to be counted reliably even where optional cookies or tracking have been rejected. Neither the queue receipt nor the aggregates contain a name, contact details, message, IP address, cookie value, visitor or session identifier, or user agent. The random receipt key is used solely to prevent duplicate counting during a technical retry. Processed receipt keys and aggregates are normally deleted after 730 days, prepared records for messages that were not conclusively sent are discarded after a short technical grace period. Technically configured internal BITSS IP addresses are excluded from this success count without preventing the email itself from being sent. Consent to optional analytics services is not required in order to use the form.
The legal basis is Art. 6(1)(b) GDPR where your enquiry concerns steps prior to entering into a contract or the performance of a contract. Other enquiries are processed on the basis of Art. 6(1)(f) GDPR, our legitimate interests are the appropriate handling of business enquiries and protection of the form against misuse. The technically necessary session is used solely to provide the secure form submission expressly requested by you.
Cookies
Our web pages use what are known as cookies. Cookies are small data packages and do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are deleted automatically at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or until your web browser deletes them automatically.
Cookies may originate from us (first-party cookies) or from third-party companies (third-party cookies). Third-party cookies make it possible to integrate certain services of third-party companies within web pages, for example cookies used to process payment services.
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them, for example the shopping basket function or the display of videos. Other cookies may be used to analyse user behaviour or for advertising purposes.
We use technically necessary storage and access operations only where they are strictly required for transmitting a communication or for a website function you have expressly requested. Where such an operation involves personal data, the subsequent processing is also assessed under the GDPR. Optional analytics technologies such as Google Analytics 4 are not treated as necessary and are activated only after your consent. The legal basis for access to the device is then section 25(1) TDDDG and, for subsequent processing of personal data, Art. 6(1)(a) GDPR.
You can set your browser so that you are informed when cookies are set and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when you close the browser. If cookies are deactivated, the functionality of this website may be limited.
If further cookies and services are used on this website, you can find details in this privacy policy.
Server-side basic and security statistics
To ensure reliable operation and to measure reach, security and technical quality, we aggregate data from the server access logs generated as part of web hosting. This processing uses no JavaScript tracking, statistics cookie, visitor or session identifier, and does not access information on your device. The statistics database stores hourly aggregates: the requested path without query parameters, resource type, HTTP status code, HTTP method, transferred data volume, number of requests, coarse source category, and classification as a bot or “human/unknown”. For technically recognised attack and vulnerability scans, the derived attack category, detection signature, assessed severity, detection confidence and IP address are additionally stored.
Full IP addresses associated with recognised attack and vulnerability scans are retained in the protected security report for no more than 30 days. Afterwards, the final octet of an IPv4 address is set to 0 and stored as a /24 network, for IPv6, only the first 48 bits are retained and all remaining bits are set to 0. Full referrer URLs, query parameters, request bodies, cookies and full browser identifiers (user agents) are not stored in the statistics database. For recognised automated requests, the derived bot category and a standardised bot name are stored in the hourly aggregate, unknown bots are grouped together. The basic statistics are not used to create unique visitor counts or sessions. The “human/unknown”, “bot” or “attack scan” assignment is a technical classification only and does not prove identity or that an attack succeeded. Technically configured internal BITSS IP addresses are discarded before usage, bot or attack aggregates are created. Hourly aggregates, including the shortened network value, are normally deleted after 730 days.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are the secure and economical provision of the website, error detection, recognition and prevention of abusive access, and the evaluation and improvement of our online offering. You may object to this processing on grounds relating to your particular situation under Art. 21 GDPR by using the contact details above. The hoster's separately described server log files remain unaffected.
Anonymous evaluation of privacy choices
When you save a selection in the cookie dialog, that decision is transmitted once to the BITSS web server and counted there exclusively in hourly aggregates. The stored dimensions are “Reject all”, “Accept all” or “Custom selection”, whether it is an initial choice or a later change, whether it originated in the banner or settings dialog, the interface language and the current page path without query parameters. Requests technically identified as bots and configured internal BITSS IP addresses are not counted.
No IP address, cookie ID, visitor or session identifier, fingerprint or user-agent is stored in this evaluation. The decision is not linked to page views, interactions or other statistics. Multiple browsers or devices and a deleted or expired consent cookie may be counted again as an initial choice, the figures therefore do not represent uniquely identified natural persons. The hourly aggregates are normally deleted after 730 days. Rejecting optional services is not circumvented by this process, Google Analytics and the detailed local BITSS web statistics remain disabled.
Storing the selection in the necessary first-party cookie serves to apply your decision and avoid asking again on every page view. The anonymously aggregated count serves to verify the technical operation of the consent dialog and assess its use. The legal basis for any technically unavoidable short-term processing is Art. 6(1)(f) GDPR, our legitimate interests lie in demonstrable, user-friendly and economical provision of the privacy settings. The necessary access to the device is based on section 25(2)(2) TDDDG.
Consent-based local BITSS web statistics
If you expressly consent in the privacy settings, BITSS GmbH operates its own web statistics system on the bitss.de web server. The statistics are used to measure reach, origin, campaigns, sessions, interactions, usability and the technical quality of the website. The collected statistics data is not transferred to external analytics providers and is not used for cross-site advertising.
Data processed may include the time, full IP address, requested path, only approved campaign and navigation parameters (such as UTM, click, language or referrer parameters), page title, landing page, referrer and referrer domain, language, browser identifier (user agent), browser, operating system and device type inferred from it, time zone, screen and viewport size, colour depth, pixel density, the number of logical processors reported by the browser, an approximate memory value and, where provided by the browser, processor architecture and bitness, platform and platform version, device class and model, and graphics-adapter information such as vendor, architecture, device identifier or description. Touch support, cookie and Do Not Track settings, network information provided by the browser, navigation and loading times, JavaScript errors, and events such as page views, click paths, downloads, contact links, scroll depth, active and inactive page time, form start and form submission may also be processed. The system may additionally store only a yes/no indication of whether mouse-pointer movement was detected during a page view, coordinates and movement paths are not stored. Hardware and system values are browser-provided information or estimates, may be unavailable and are not treated as a complete device inventory. In the protected statistics area, this information may be combined under a pseudonymous random name into visitor-related sessions and activity timelines. Form field contents, keystrokes, passwords, access tokens and all other query parameters are not collected.
After the local BITSS statistics have been expressly enabled, additional browser-fingerprinting methods are used. These include hashes derived from a locally generated Canvas image, a WebGL rendering and locally calculated audio output, detection against a limited list of common fonts, a technical browser-feature matrix and, where available without an additional permission prompt, counts of audio-input, audio-output and video-input devices and coarse battery information. No image or audio data is sent to the server, only derived hashes and limited technical summaries are stored. From the more stable characteristics, the server uses a secret stored only in the local statistics database to create a pseudonymous fingerprint ID. It is intended to recognise technically identical or similar browser/device profiles but is not reliable proof of identity.
The local statistics also use a hidden test element and a first-party test file to determine whether an advertising or content filter is probably active. Only “probably detected”, “not detected” or “unknown” is stored together with the test method. The result may be affected by browser, DNS, network or security settings and does not identify a specific extension. Installed browser extensions, media-device labels, sensor readings, mouse coordinates and complete movement paths are not collected.
For recognition, the local statistics use the first-party cookies bitss_vid, containing a randomly generated visitor identifier for up to twelve months, and bitss_sid, containing a randomly generated session identifier whose lifetime is renewed to 30 minutes when activity occurs. The identifiers are set only after your consent. Full IP addresses are normally shortened after 30 days: for IPv4, the final octet is set to 0 and stored as a /24 network, for IPv6, only the first 48 bits are retained and all remaining bits are set to 0. This shortened network value is retained no longer than the remaining detailed data, which are normally deleted after 180 days. Statistics needed for longer-term comparisons may subsequently be retained only as monthly aggregates without IP addresses, visitor or session identifiers. Without an external scheduler, the application-internal cleanup is triggered at most once per day by the next visit to a website or statistics page, if no visit occurs, it is performed on the following visit.
The legal basis is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG. Consent is voluntary and is not required to use the website. You can withdraw it at any time via “Privacy settings” with effect for the future. Further collection is then stopped and the statistics identifiers set by BITSS are deleted. Data-subject rights, including access and erasure, can be exercised using the contact details above.
Google Analytics 4
This website uses Google Analytics 4 with measurement ID G-5K7KP0MCHN. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For human visitors, Google Analytics is loaded only after you have expressly consented. If you reject or make no choice, the Google Analytics script and the associated optional analytics access are not loaded.
Google Analytics is used solely for reach and usage analysis. Data processed may include page views, session information, approximate location, and browser and device information. Google Analytics uses first-party cookies. According to Google, these include _ga to distinguish users and _ga_<container-id> to persist session state. The standard duration is up to two years for each. Data may be processed in the USA. Google states that it relies on the EU-U.S. Data Privacy Framework for transfers of EEA personal data to Google LLC in the USA.
Your selections for the local BITSS statistics and Google Analytics are stored for up to twelve months in the technically necessary first-party cookie bitss_consent_v38. The entry contains the version of the consent interface, time, selections and interface language and is not itself used for reach measurement. Both statistics services can be enabled separately and withdrawn at any time via “Privacy settings” in the footer. After withdrawal, further calls to the deselected service are blocked and the associated cookies under our control are deleted.
Before local statistics start and before Google Analytics is loaded, the browser asks the BITSS web server whether the current IP address is internally excluded. If it is excluded, neither statistics service starts. Both also remain disabled if that check fails for technical reasons.
5. Newsletter
Newsletter data
If you would like to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively to send the requested information and do not pass it on to third parties.
The data entered in the newsletter registration form is processed exclusively on the basis of your consent (Art. 6(1)(a) GDPR). You may withdraw your consent to the storage of the data and the email address, and to their use for sending the newsletter, at any time, for example via the unsubscribe link in the newsletter. The lawfulness of processing operations already carried out remains unaffected by the withdrawal.
The data you provide to us for the purpose of receiving the newsletter is stored by us or by the newsletter service provider until you unsubscribe, and is deleted from the newsletter distribution list after you cancel the newsletter or once the purpose no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Data stored by us for other purposes remains unaffected by this.
After you unsubscribe from the newsletter distribution list, your email address may be stored by us or by the newsletter service provider on a blocklist, insofar as this is necessary to prevent future mailings. The data on the blocklist is used only for this purpose and is not merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage on the blocklist is not limited in time. You may object to this storage if your interests outweigh our legitimate interest.
6. Plugins and tools
YouTube
This website embeds videos from the YouTube website. The site is operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of our pages on which YouTube is embedded, a connection to YouTube's servers is established. The YouTube server is informed which of our pages you have visited.
YouTube may also store various cookies on your device or use comparable recognition technologies such as device fingerprinting. In this way YouTube can obtain information about visitors to this website. Among other things, this information is used to record video statistics, improve usability and prevent fraud attempts. The data collected is also processed within the Google advertising network.
If you are logged into your YouTube account, you enable YouTube to assign your browsing behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account.
YouTube is used in the interest of an appealing presentation of our online offering. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (for example device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Further information on the handling of user data can be found in YouTube's privacy policy at: https://policies.google.com/privacy?hl=de.
The company holds a certification under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Maps
This site uses the map service Google Maps. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to embed map material on our website.
In order to use the functions of Google Maps it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence over this data transfer. When Google Maps is active, Google may use Google Fonts to present typefaces consistently. When Google Maps is called up, your browser loads the required web fonts into its browser cache in order to display text and typefaces correctly.
Google Maps is used in the interest of an appealing presentation of our online offering and to make the locations stated on our website easy to find. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (for example device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
The transfer of data to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
More information on the handling of user data can be found in Google's privacy policy: https://policies.google.com/privacy?hl=de.
The company holds a certification under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google reCAPTCHA
We use Google reCAPTCHA (hereinafter “reCAPTCHA”) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to check whether data entered on this website, for example in a contact form, is entered by a human being or by an automated program. To do so, reCAPTCHA analyses the behaviour of the website visitor on the basis of various characteristics. This analysis begins automatically as soon as the visitor enters the website. For the analysis, reCAPTCHA evaluates various pieces of information such as the IP address, how long the visitor stays on the website or mouse movements made by the user. The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not informed that an analysis is taking place.
In this context Google acts purely as a processor within the meaning of Art. 28 GDPR and will not use the data collected in this way for its own purposes. The tool is used on the basis of a data processing agreement with Google.
The data is stored and analysed on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web offerings against abusive automated spying and against spam. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (for example device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
The company holds a certification under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Wordfence
We have integrated Wordfence on this website. The provider is Defiant Inc., Defiant, Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter “Wordfence”).
Wordfence serves to protect our website against unwanted access or malicious cyber attacks. For this purpose our website maintains a permanent connection to Wordfence's servers so that Wordfence can compare its databases with the access made on our website and block it where necessary.
Wordfence is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its website against cyber attacks as effectively as possible. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (for example device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
The transfer of data to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.wordfence.com/help/general-data-protection-regulation/.
Data processing agreement
We have concluded a data processing agreement for the use of the service named above. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.
7. Our own services
OneDrive
We have integrated OneDrive on this website. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter “OneDrive”).
OneDrive allows us to embed an upload area on our website where you can upload content. If you upload content, it is stored on OneDrive's servers. When you enter our website, a connection to OneDrive is also established so that OneDrive can determine that you have visited our website.
OneDrive is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in a reliable upload area on its website. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR. Consent may be withdrawn at any time.
The company holds a certification under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474.
Data processing agreement
We have concluded a data processing agreement for the use of the service named above. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.
Google Drive
We have integrated Google Drive on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Drive allows us to embed an upload area on our website where you can upload content. If you upload content, it is stored on Google Drive's servers. When you enter our website, a connection to Google Drive is also established so that Google Drive can determine that you have visited our website.
Google Drive is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in a reliable upload area on its website. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR. Consent may be withdrawn at any time.
The company holds a certification under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Data processing agreement
We have concluded a data processing agreement for the use of the service named above. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.
Source: https://www.e-recht24.de
8. Social media presences
We maintain publicly accessible profiles on Facebook, Instagram, YouTube, TikTok, LinkedIn and X. This section explains processing attributable to us when operating these presences. The privacy information of the respective platform applies to any additional processing.
Platform providers and their data processing
Facebook and Instagram are provided in the European Economic Area by Meta Platforms Ireland Limited, Merrion Road, Ballsbridge, Dublin 4, Ireland. Details are provided in the Meta Privacy Policy.
YouTube is a Google service. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is generally responsible for users in the European Economic Area. Details are provided in the Google Privacy Policy.
For users in the European Economic Area, TikTok is provided by TikTok Technology Limited, The Sorting Office, Ropemaker Place, Dublin 2, D02 HD23, Ireland, jointly with TikTok Information Technologies UK Limited. Details are provided in the TikTok Privacy Policy.
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible for LinkedIn in the European Economic Area. Details are provided in the LinkedIn Privacy Policy.
X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, is responsible for X in the European Economic Area. Details are provided in the X Privacy Policy.
When you access one of these platforms or interact with our profile there, the respective provider may process account, contact, content, device, browser, usage, location and cookie data in particular. This may also affect people who are not logged in to the platform. The respective platform provider determines the scope, purposes, legal bases, retention periods and possible transfers to third countries within its services.
Processing by BITSS GmbH
We process information that you send to us or make visible through our social media presences, such as your profile name, comments, reactions, messages and the content of your enquiry. We process this data to present our company, communicate with prospective and existing customers and respond to enquiries. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is public relations and modern communication. Where an enquiry relates to a contract or pre-contractual measures, Art. 6(1)(b) GDPR also applies, expressly granted consent is based on Art. 6(1)(a) GDPR.
Statistics and joint controllership at Meta
The platforms may provide us with aggregated statistics about views and interactions. As a rule, we receive only aggregated evaluations and cannot assign them to individual people. To the extent that Meta collects and processes Insights Data for Facebook or Instagram, BITSS GmbH and Meta Platforms Ireland Limited are joint controllers in accordance with the Page Insights Controller Addendum (Art. 26 GDPR). Under this arrangement, Meta assumes primary responsibility for providing information about the processing and for handling data-subject rights relating to Insights Data.
Your rights and external links
You may exercise your data-protection rights regarding processing for which we are responsible by using the contact details above. For processing for which a platform provider is independently responsible, please contact the respective provider directly. If you contact us first and the request concerns a platform provider exclusively, we will forward it to the extent required.
bitss.de does not integrate social media plugins, tracking pixels or embedded social media feeds from these presences. Merely visiting bitss.de therefore does not establish a connection to Facebook, Instagram, YouTube, TikTok, LinkedIn or X as a result of the profile links. A connection is established only when you follow an external link to the respective platform.