Privacy Policy
Deutsche Version →Preamble
With the following privacy policy, we would like to inform you which types of your personal data (hereinafter also referred to briefly as "data") we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: 8 June 2026
Table of contents
- Preamble
- Controller
- Overview of processing
- Applicable legal bases
- Security measures
- Transfer of personal data
- International data transfers
- General information on data retention and deletion
- Rights of data subjects
- Provision of the online offering and web hosting
- Data protection information for whistleblowers
- Changes and updates
- Definitions
Controller
Werbegrafik König,
Mauerstr 23
10117 Berlin, Germany
Authorized representative: Johannes Wolfgang König
Email address: hannes@gospl.io
Overview of processing
The following overview summarizes the types of data processed and the purposes of their processing, and identifies the categories of data subjects concerned.
Types of data processed
- Inventory data.
- Employee data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication and procedural data.
- Log data.
Categories of data subjects
- Employees.
- Users.
- Third parties.
- Whistleblowers.
Purposes of processing
- Security measures.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
- Whistleblower protection.
Applicable legal bases
Applicable legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection provisions may apply in your country or ours of residence or establishment. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) — The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Legal obligation (Art. 6(1)(c) GDPR) — Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) — Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject which require the protection of personal data.
National data protection provisions in Germany: In addition to the GDPR's data protection provisions, national data protection regulations apply in Germany. This includes, in particular, the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains, among other things, specific provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transmission of data as well as automated decision-making in individual cases, including profiling. State data protection laws of the individual German federal states may also apply.
Note on the applicability of the GDPR and the Swiss FADP: This privacy notice serves to provide information under both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For this reason, please note that, due to its broader territorial scope and greater comprehensibility, we use the terminology of the GDPR. In particular, instead of the terms "processing" of "personal data", "overriding interest" and "particularly sensitive personal data" used under the Swiss FADP, we use the GDPR terms "processing" of "personal data", "legitimate interest" and "special categories of data". However, the legal meaning of these terms continues to be determined under the Swiss FADP to the extent that it applies.
Applicability of data protection provisions at the place of establishment: In the country in which the controller is established, national data protection provisions apply in addition to the General Data Protection Regulation (GDPR).
Security measures
In accordance with statutory requirements, and taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, availability and segregation of such data. We have also established procedures to ensure the exercise of data subject rights, the deletion of data, and appropriate responses to threats to data. Furthermore, we take the protection of personal data into account as early as the development and selection of hardware, software and processes, in line with the principles of data protection by design and by default.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect the data transmitted by users through our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between a website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure successor to SSL, ensures that all data transmissions meet the highest security standards. Where a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL – a signal to users that their data is being transmitted securely and in encrypted form.
Transfer of personal data
In the course of our processing of personal data, the data may be transferred to, or disclosed to, other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks, or providers of services and content embedded in a website. In such cases, we comply with statutory requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.
International data transfers
Data processing in third countries: Where we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to other persons, bodies or companies (which will be apparent from the postal address of the respective provider, or where the privacy policy expressly refers to the transfer of data to third countries), this always takes place in accordance with statutory requirements.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a safe legal framework by the European Commission's adequacy decision of 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the European Commission and establish contractual obligations to protect your data.
This two-fold safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, while the standard contractual clauses serve as an additional safeguard. Should changes occur within the DPF framework, the standard contractual clauses take effect as a reliable fallback. This ensures your data remains adequately protected even in the event of political or legal changes.
For each individual service provider, we indicate whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/.
For data transfers to other third countries, corresponding safeguards apply, in particular standard contractual clauses, explicit consent, or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found on the European Commission's website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
General information on data retention and deletion
We delete personal data that we process in accordance with statutory provisions as soon as the underlying consent is withdrawn or no further legal basis for processing exists. This applies to cases in which the original purpose of processing ceases to apply or the data is no longer required. Exceptions to this rule apply where statutory obligations or particular interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose retention is necessary for the pursuit of legal claims or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data that applies specifically to particular processing operations.
Where multiple retention or deletion periods are specified for a given piece of data, the longest period shall always apply. Data that is no longer retained for its originally intended purpose, but rather due to statutory requirements or other reasons, is processed exclusively for the reasons that justify its retention.
Commencement of periods at year end: Where a period does not expressly begin on a specific date and is at least one year, it automatically begins at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships during which data is stored, the triggering event is the point at which the termination or other conclusion of the legal relationship takes effect.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, arising in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to that data as well as further information and a copy of the data, in accordance with statutory requirements.
- Right to rectification: In accordance with statutory requirements, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with statutory requirements, you have the right to request that data concerning you be deleted without delay, or alternatively, in accordance with statutory requirements, to request a restriction on the processing of that data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with statutory requirements, in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Provision of the online offering and web hosting
We process users' data in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to deliver the content and functions of our online services to the user's browser or end device.
- Types of data processed: Usage data (e.g., pages visited, time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved). Log data (e.g., log files relating to logins or the retrieval of data or access times).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical equipment such as computers and servers). Security measures.
- Retention and deletion: Deletion in accordance with the information provided in the section "General information on data retention and deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Provision of the online offering on rented storage space: To provide our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a "web host"); Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, an indication of successful retrieval, browser type and version, the user's operating system, the referrer URL (the page previously visited) and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes – for example, to prevent server overload (in particular in the event of abusive attacks, so-called DDoS attacks) – and, on the other hand, to ensure server load and stability; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose continued retention is required for evidentiary purposes is excluded from deletion until the respective incident has been finally clarified.
Data protection information for whistleblowers
Use of our online forms: Please note that it is possible to submit reports anonymously. To help ensure the security of your data when using our online forms, we recommend accessing them in your browser's so-called "incognito mode". Here is how to open an incognito window: a) On a Windows PC: open your browser and press Ctrl+Shift+N; b) On a Mac: open your browser and press Command+Shift+N; c) On mobile devices: switch to private mode via the tab menu.
Providing your name: You have the option of submitting reports anonymously. Unless prohibited by national law, however, we recommend that you provide your name and contact details. This allows us to follow up on the report more effectively and, where necessary, to contact you directly.
Disclosure of data to third parties: Data relating to submitted reports is disclosed by us to third parties only under certain circumstances. This occurs either a) where you have given us your express consent to do so, or b) where there is a legal obligation to disclose the data. Possible third parties include public authorities and government, regulatory or tax authorities, where disclosure is necessary to fulfil a legal or regulatory obligation. In addition, within the framework of statutory provisions, we may engage lawyers and other professional advisors. These are authorized to examine suspected misconduct and to take necessary measures following an investigation, such as initiating disciplinary or legal proceedings. Furthermore, carefully selected and supervised service providers may receive data for these purposes (for example, operators of a web-based reporting system). These service providers are, however, contractually obligated under a data processing agreement to comply with applicable data protection provisions.
- Types of data processed: Inventory data (e.g., full name, home address, contact information, customer number); employee data (information relating to employees and other persons); contact data (e.g., postal and email addresses); content data (e.g., text or image messages and posts, as well as related information such as details of authorship). Usage data (e.g., pages visited, time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features).
- Data subjects: Employees (e.g., staff, applicants, temporary workers); third parties. Whistleblowers.
- Purposes of processing and legitimate interests: Whistleblower protection.
- Retention and deletion: Deletion in accordance with the information provided in the section "General information on data retention and deletion".
- Legal bases: Consent (Art. 6(1)(a) GDPR); legal obligation (Art. 6(1)(c) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Changes and updates
We ask that you periodically inform yourself of the content of our privacy policy. We will update the privacy policy as soon as changes to the data processing we carry out make this necessary. We will notify you as soon as the changes require any action on your part (e.g., consent) or other individual notification.
Where this privacy policy provides addresses and contact information for companies and organizations, please note that such addresses may change over time and we ask that you verify the details before making contact.
Definitions
This section provides an overview of the terms used in this privacy policy. Where terms are defined by law, their statutory definitions apply. The explanations below are intended primarily to aid understanding.
- Employees: Employees are persons in an employment relationship, whether as staff members, salaried employees, or in similar positions. An employment relationship is a legal relationship between an employer and an employee established by an employment contract or agreement. It includes the employer's obligation to pay the employee remuneration while the employee performs work in return. The employment relationship encompasses various phases, including formation (when the employment contract is concluded), performance (when the employee carries out their duties), and termination (when the employment relationship ends, whether through dismissal, termination agreement, or otherwise). Employee data is all information relating to these persons in the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and banking details, working hours, vacation entitlements, health data, and performance evaluations.
- Inventory data: Inventory data comprises essential information required to identify and manage contractual partners, user accounts, profiles, and similar relationships. This data may include, among other things, personal and demographic details such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Inventory data forms the basis for any formal interaction between individuals and services, facilities, or systems by enabling unambiguous identification and communication.
- Content data: Content data comprises information generated in the course of creating, editing, and publishing content of any kind. This category of data may include text, images, videos, audio files, and other multimedia content published across various platforms and media. Content data is not limited to the content itself but also includes metadata that provides information about the content, such as tags, descriptions, author information, and publication dates.
- Contact data: Contact data is essential information that enables communication with individuals or organizations. It includes, among other things, phone numbers, postal addresses, and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Meta, communication and procedural data: Meta, communication, and procedural data are categories comprising information about how data is processed, transmitted, and managed. Metadata, also known as data about data, includes information describing the context, origin, and structure of other data. It may include details such as file size, creation date, document author, and revision history. Communication data captures the exchange of information between users across various channels, such as email traffic, call logs, social media messages, and chat histories, including the persons involved, timestamps, and transmission paths. Procedural data describes the processes and workflows within systems or organizations, including workflow documentation, transaction and activity logs, and audit logs used for tracking and reviewing operations.
- Usage data: Usage data refers to information recording how users interact with digital products, services, or platforms. This data covers a wide range of information showing how users use applications, which features they prefer, how long they remain on particular pages, and the paths they take through an application. Usage data may also include frequency of use, activity timestamps, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experience, personalizing content, and improving products or services. Usage data also plays a key role in identifying trends, preferences, and potential problem areas within digital offerings.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Log data: Log data is information about events or activities recorded within a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system. Log data is often used to analyze system issues, for security monitoring, or to generate performance reports.
- Controller: The "controller" is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, whether collecting, evaluating, storing, transmitting, or deleting it.
Translated from the German original, created with the free privacy policy generator by Dr. Thomas Schwenke at datenschutz-generator.de.