Privacy Policy
Cyber Fidelity AG · Germany
Last updated: 11 June 2026
Privacy at a glance
The essentials
We handle personal data responsibly, process only what is necessary, and comply with all applicable data protection requirements.
Purposes of processing
Fulfilling contractual obligations, handling enquiries, operating and improving our online presence, and complying with legal requirements.
Data we collect
Identity and contact details, contractual and billing information, and technical data generated when you use our website or services.
Retention
Data is erased as soon as it is no longer required for its original purpose, subject to applicable statutory retention obligations.
Disclosure to third parties
Data is passed on only to the extent required — to service providers supporting our operations, such as hosting, communication, and analytics tools.
Your rights
You may at any time request information about, correction of, or erasure of data held about you, and withdraw any consent previously given. For enquiries: hello@cyber-fidelity.com
Table of Contents
- Preamble
- Responsible
- Rights of Data Subjects
- Overview of Processing Operations
- Relevant Legal Bases
- General Information on Data Retention and Erasure
- Security Measures
- Provision of the Online Offer and Web Hosting
- Cloud Services
- Management, Organization and Tools
- Contact and Inquiry Management
- Business Services
- Business Processes and Procedures
- Video Conferences, Online Meetings, Webinars and Screen Sharing
- Newsletter and Electronic Notifications
- Promotional Communication via Email, Post, Fax or Telephone
- Surveys and Questionnaires
- Customer Reviews and Rating Procedures
- Presence in Social Networks (Social Media)
- Transmission of Personal Data
- International Data Transfers
- Amendment and Update
- Contact Option
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to simply as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offer").
The terms used are not gender-specific.
Responsible
Cyber Fidelity AGSchorner Str. 1a
82065 Baierbrunn
Germany
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to this data, as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without delay, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with the legal requirements, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
- Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, the supervisory authority of your place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Overview of Processing Operations
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Master data
- Contact data
- Contract data
- Content data
- Usage data
- Meta, communication and procedural data
- Log data
- Image and/or video recordings
- Audio recordings
- Payment data
- Employee data
Categories of Data Subjects
- Service recipients and clients
- Prospective customers
- Communication partners
- Users
- Business and contractual partners
- Third parties
- Participants
- Customers
- Depicted persons
- Employees
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations
- Communication
- Security measures
- Office and organizational procedures
- Remarketing
- Affiliate tracking
- A/B testing
- Organizational and administrative procedures
- Feedback
- Surveys and questionnaires
- Profiles with user-related information
- Provision of our online offer and user-friendliness
- Information technology infrastructure
- Public relations
- Sales promotion
- Business processes and economic procedures
- Artificial intelligence (AI)
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Furthermore, should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6 (1) (1) (a) GDPR) — The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6 (1) (1) (b) GDPR) — Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 (1) (1) (c) GDPR) — Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 (1) (1) (f) GDPR) — Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject which require the protection of personal data are not overridden.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection rules apply in Germany. These include in particular the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, the data protection laws of the individual federal states (Länder) may apply.
Notice on the applicability of the GDPR and the Swiss FADP: This privacy notice serves both to provide information pursuant to the Swiss Federal Act on Data Protection (FADP) and pursuant to the General Data Protection Regulation (GDPR). For this reason, please note that, due to the broader territorial scope and greater comprehensibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss FADP — "processing" of "personal data", "overriding interest", and "particularly sensitive personal data" — the terms used in the GDPR are applied, namely "processing" of "personal data" as well as "legitimate interest" and "special categories of data". However, the legal meaning of these terms continues to be determined in accordance with the Swiss FADP where the Swiss FADP applies.
General Information on Data Retention and Erasure
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consents are withdrawn or there are no further legal bases for the processing. This concerns cases in which the original purpose of the processing no longer applies or the data is no longer required. Exceptions to this rule apply where statutory obligations or legitimate interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax-law reasons, or whose storage is necessary for the prosecution of legal claims or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.
Where multiple statements regarding the retention period or erasure deadlines of a piece of data exist, the longest period is always decisive. Data that is no longer retained for the originally intended purpose but on the basis of legal requirements or other grounds is processed exclusively for the reasons that justify its retention.
Retention and erasure of data: The following general periods apply to retention and archiving under German law:
Security Measures
In accordance with the legal requirements and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as the access, input, disclosure, availability and segregation relating to it. Furthermore, we have established procedures that ensure the exercise of data subject rights, the erasure of data, and responses to threats to the data. Moreover, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services against unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data against unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is signaled by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Provision of the Online Offer and Web Hosting
We process the data of users in order to be able to provide our online services to them. For this purpose, we process the user's IP address, which is necessary in order to transmit the content and functions of our online services to the user's browser or device.
Further information on processing operations, procedures and services:
7 Services / Processors
Provision of the online offer on rented storage space: For the provision of our online offer, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also called a "web host"); legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Collection of access data and log files: Access to our online offer is logged in the form of so-called "server log files". The server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transmitted, notification of successful access, browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used for security purposes, e.g., to avoid overloading the servers (in particular in the case of abusive attacks, so-called DDoS attacks), and to ensure the utilization of the servers and their stability; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR). Erasure of data: Log file information is stored for a maximum of 30 days and then erased or anonymized. Data whose further retention is required for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.
Email dispatch and hosting: The web hosting services we use also include the sending, receipt and storage of emails. For these purposes, the addresses of the recipients and senders, as well as further information concerning the email dispatch (e.g., the providers involved) and the contents of the respective emails, are processed. The aforementioned data may also be processed for the purpose of detecting SPAM. Please note that emails are generally not sent in encrypted form on the internet. As a rule, emails are encrypted during transport, but (unless a so-called end-to-end encryption procedure is used) not on the servers from which they are sent and received. We can therefore accept no responsibility for the transmission path of emails between the sender and receipt on our server; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Content Delivery Network: We use a "Content Delivery Network" (CDN). A CDN is a service with the help of which the content of an online offer, in particular large media files such as graphics or program scripts, can be delivered more quickly and securely with the help of regionally distributed servers connected via the internet; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Amazon Web Services (AWS): Services in the field of the provision of information technology infrastructure and related services (e.g., storage space and/or computing capacities); service provider: Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxembourg; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: aws.amazon.com/de/; privacy policy: aws.amazon.com/de/privacy/; data processing agreement: aws.amazon.com/de/compliance/gdpr-center/. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Amazon CloudFront: Content Delivery Network (CDN); service provider: Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxembourg; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: aws.amazon.com/de/cloudfront/; privacy policy: aws.amazon.com/privacy/; data processing agreement: aws.amazon.com/de/compliance/gdpr-center/. Basis for third-country transfers: Standard Contractual Clauses (provided by the service provider).
gstatic.com: Content Delivery Network (CDN); service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: google.de; privacy policy: policies.google.com/privacy.
Cloud Services
We use software services accessible via the internet and executed on the servers of their providers (so-called "cloud services", also referred to as "Software as a Service") for the storage and management of content (e.g., document storage and management, exchange of documents, content and information with specific recipients, or publication of content and information).
In this context, personal data may be processed and stored on the servers of the providers, insofar as this data is part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include in particular master data and contact data of users, data on transactions, contracts, other processes and their content. The providers of the cloud services furthermore process usage data and metadata, which they use for security purposes and service optimization.
Further information on processing operations, procedures and services:
1 Service / Processor
Microsoft 365 and Microsoft Cloud Services: Provision of applications, protection of data and IT systems, as well as use of system-generated log, diagnostic and metadata for the performance of the contract by Microsoft. The retention of data is governed by the respective documents and company policies; for Defender (protection of data and IT systems) up to 12 months, for print management 10 days; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: microsoft.com/de-de; privacy policy: privacy.microsoft.com/de-de/privacystatement. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Management, Organization and Tools
We use services, platforms and software of other providers (hereinafter referred to as "third-party providers") for the purposes of organizing, administering, planning and providing our services. When selecting the third-party providers and their services, we observe the legal requirements.
In this context, personal data may be processed and stored on the servers of the third-party providers. This may concern various data that we process in accordance with this privacy policy. This data may include in particular master data and contact data of users, data on transactions, contracts, other processes and their content.
Insofar as users are referred to the third-party providers or their software or platforms in the context of communication, business or other relationships with us, the third-party providers may process usage data and metadata for security purposes, for service optimization or for marketing purposes. We therefore ask that you observe the privacy notices of the respective third-party providers.
Further information on processing operations, procedures and services:
1 Service / Processor
Conceptboard: Creation, editing and commenting on digital whiteboards (digital work surfaces for the joint visualization of content), collaboration in real time (simultaneous editing by several people), exchange of files, use of templates, integration with other applications (e.g., video conferencing tools); service provider: Conceptboard Cloud Service GmbH, Mansfelder Str. 56, 06108 Halle (Saale), Germany; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: conceptboard.com/de/; privacy policy: conceptboard.com/de/datenschutzerklaerung/; data processing agreement: conceptboard.com/data-processing-agreement/.
Contact and Inquiry Management
When contacting us (e.g., by post, contact form, email, telephone or via social media) as well as in the context of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to respond to the contact inquiries and any requested measures.
Further information on processing operations, procedures and services:
2 Services / Processors
Contact form: When you contact us via our contact form, by email or other means of communication, we process the personal data transmitted to us in order to respond to and process the respective request. This usually includes information such as name, contact information and, where applicable, further information communicated to us and necessary for appropriate processing. We use this data exclusively for the stated purpose of contacting and communicating with you; legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (1) (b) GDPR), legitimate interests (Art. 6 (1) (1) (f) GDPR).
HubSpot CRM: Management of customer contacts, tracking of sales activities, automation of marketing campaigns, analysis of sales data, creation and management of email campaigns, integration with other tools and platforms, management of customer support requests, AI-supported content generation, personalized email creation, predictive sales forecasts, automatic workflow descriptions and AI chatbots for customer interaction; service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (1) (b) GDPR), legitimate interests (Art. 6 (1) (1) (f) GDPR); website: hubspot.de/pa/crm; privacy policy: legal.hubspot.com/de/privacy-policy; data processing agreement: legal.hubspot.com/dpa. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Business Services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively "contractual partners"), for the purpose of initiating, performing and processing contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken upon request, as well as communication in connection with the respective contractual relationship.
The processing serves in particular to fulfill our principal and ancillary contractual obligations. This includes the provision of the agreed services, any update and information obligations, the handling of warranty and other performance disruptions, the processing of withdrawals, terminations of continuing obligations, reversals, refunds, as well as the handling of other contract-related declarations and inquiries. This covers both one-off contracts and ongoing contractual relationships.
We process in particular master data such as name, address and, where applicable, company; contact data such as email address and telephone number; contract and performance data such as the subject matter of the contract, contract term, order or transaction number; usage and performance data; payment and billing data; as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of carrying out an order.
In addition, we process the data to safeguard our rights and to fulfill legal obligations. This includes in particular commercial and tax-law retention obligations, documentation obligations, and, where applicable, verification and accountability obligations. Furthermore, processing takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners from misuse, endangerment of data, trade secrets and other legal assets. This may also include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisors, or other vicarious agents, insofar as this is necessary for the performance of the contract or for the fulfillment of legal obligations.
Personal data is disclosed to third parties only insofar as this is necessary for the performance of the contract, for carrying out pre-contractual measures, for safeguarding legitimate interests, or for fulfilling legal obligations. We provide separate information on any processing beyond this, in particular for marketing purposes, within this privacy policy.
We inform contractual partners of which data is required in the individual case at the time of data collection, for example in online forms by means of corresponding labeling, or in personal contact.
The data is erased as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations stand in the way. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the context of a specific order is erased by us after completion of the order and expiry of any retention periods, provided that no further legal or contractual storage obligations exist.
The legal basis for the processing is Art. 6 (1) (b) GDPR for carrying out pre-contractual measures and for fulfilling the respective contractual relationship, as well as Art. 6 (1) (c) GDPR for fulfilling legal obligations. Where processing is based on legitimate interests, it takes place on the basis of Art. 6 (1) (f) GDPR.
Further information on processing operations, procedures and services:
3 Processing Activities
Data processing in the context of online orders: We process personal data of our customers in order to enable them to select, order and pay for products, goods and related services – both digitally and via postal dispatch. This includes, among other things, the provision in the web application, the processing of the order procedure, and the subsequent delivery or performance of the requested service. Where necessary, we commission external service providers such as shipping or postal companies for delivery. Payment processing takes place via banks and specialized payment service providers. In the course of the ordering process, we collect all necessary information – for example regarding delivery, billing, and contact information for any queries. This data is clearly marked as necessary. Legal basis: Performance of a contract and carrying out pre-contractual measures pursuant to Art. 6 (1) (1) (b) GDPR.
Data analysis: We process the data of our customers and clients in order to enable them to use data analysis, evaluation and consulting, as well as related services. The necessary information includes the information required for analysis, evaluation and billing, as well as contact information for necessary coordination. Insofar as we gain access to information of end customers, employees or other persons, we process this in accordance with the legal and contractual requirements; legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (1) (b) GDPR), legal obligation (Art. 6 (1) (1) (c) GDPR), legitimate interests (Art. 6 (1) (1) (f) GDPR).
Provision of software and platform services: We process the data of our users, registered users and any test users (hereinafter uniformly referred to as "users") in order to be able to provide our contractual services to them, as well as on the basis of legitimate interests in order to ensure the security of our offer and to be able to develop it further. The required information is marked as such in the context of the order, purchase, or comparable conclusion of a contract, and includes the information required for the provision of services and billing, as well as contact information in order to be able to hold any consultations; legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (1) (b) GDPR).
Business Processes and Procedures
Personal data of service recipients and clients – including customers, clients or, in special cases, mandates, patients or business partners as well as other third parties – is processed in the context of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates economic processes in areas such as customer management, sales, payment transactions, accounting and project management.
The collected data serves to fulfill contractual obligations and to design operational processes efficiently. This includes the handling of business transactions, the management of customer relationships, the optimization of sales strategies, and ensuring internal accounting and financial processes. In addition, the data supports the safeguarding of the controller's rights and promotes administrative tasks as well as the organization of the company.
Personal data may be disclosed to third parties insofar as this is necessary for the fulfillment of the stated purposes or legal obligations. After expiry of statutory retention periods, or when the purpose of processing no longer applies, the data is erased. This also includes data that must be stored for longer due to tax-law and statutory verification obligations.
Further information on processing operations, procedures and services:
5 Processing Activities
Customer management and Customer Relationship Management (CRM): Procedures required in the context of customer management and CRM (e.g., customer acquisition in compliance with data protection requirements, measures to promote customer retention and loyalty, effective customer communication, complaint management and customer service with consideration of data protection, data management and analysis to support the customer relationship, administration of CRM systems, secure account management, customer segmentation and target group definition); legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (1) (b) GDPR), legitimate interests (Art. 6 (1) (1) (f) GDPR).
Contact management and contact maintenance: Procedures required in the context of the organization, maintenance and securing of contact information (e.g., the establishment and maintenance of a central contact database, regular updates of contact information, monitoring of data integrity, implementation of data protection measures, ensuring access controls, performing backups and recoveries of contact data, training employees in the effective use of contact management software, regular review of communication history and adjustment of contact strategies); legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 (1) (1) (b) GDPR), legitimate interests (Art. 6 (1) (1) (f) GDPR).
Marketing, advertising and sales promotion: Procedures required in the context of marketing, advertising and sales promotion (e.g., market analysis and target group determination, development of marketing strategies, planning and execution of advertising campaigns, design and production of advertising materials, online marketing including SEO and social media campaigns, event marketing and trade fair participation, customer loyalty programs, sales promotion measures, performance measurement and optimization of marketing activities, budget management and cost control); legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Economic analyses and market research: In order to fulfill economic purposes and to identify market trends, the wishes of contractual partners and users, the available data on business transactions, contracts, inquiries, etc. is analyzed. The analyses are carried out for the purposes of economic evaluations, marketing and market research (e.g., to determine customer groups with different characteristics). Where available, profiles of registered users, including their information on services used, are taken into account. The analyses serve the controller alone and are not disclosed externally, unless they are anonymous analyses with aggregated, i.e., anonymized values. In addition, the privacy of users is taken into account; the data is processed for analysis purposes in a pseudonymized manner where possible and, where feasible, in an anonymized manner; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Public relations: Procedures required in the context of public relations and PR (e.g., development and implementation of communication strategies, planning and execution of PR campaigns, creation and distribution of press releases, maintenance of media contacts, monitoring and analysis of media response, organization of press conferences and public events, crisis communication, creation of content for social media and corporate websites, management of corporate branding); legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Video Conferences, Online Meetings, Webinars and Screen Sharing
We use platforms and applications of other providers (hereinafter referred to as "conference platforms") for the purpose of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as "conference"). When selecting the conference platforms and their services, we observe the legal requirements.
Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of the participants listed below. The scope of the processing depends, on the one hand, on which data is required in the context of a specific conference (e.g., provision of access data or real names) and which optional information is provided by the participants. In addition to processing for the purpose of conducting the conference, the participants' data may also be processed by the conference platforms for security purposes or service optimization. The processed data includes personal details (first name, surname), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet access, information on the participants' devices, their operating system, the browser and its technical and language settings, information on the content-related communication processes, i.e., entries in chats as well as audio and video data, as well as the use of other available functions (e.g., surveys). The contents of communications are encrypted to the extent technically provided by the conference providers. If the participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.
Logging and recordings: If text entries, participation results (e.g., from surveys) as well as video or audio recordings are logged, this is communicated transparently to the participants in advance and they are – where necessary – asked for their consent.
Data protection measures of the participants: Please refer to the privacy notices of the conference platforms for details of the processing of your data by them, and select the security and data protection settings that are optimal for you within the settings of the conference platforms. Furthermore, please ensure data and privacy protection in the background of your recording for the duration of a video conference (e.g., by giving notice to fellow residents, locking doors, and, where technically possible, using the function to blur the background). Links to the conference rooms and access data must not be passed on to unauthorized third parties.
Further information on processing operations, procedures and services:
1 Service / Processor
Microsoft Teams: Used for conducting online events and conferences, as well as communication with internal and external participants. Voice transmission, direct messages, group communication and collaboration functions are used. Audio signals are generally not stored, except when recording is activated. Meeting and conference recordings are stored by default for 90 days, unless a different duration is specified. Chat and file content is stored according to the policies determined by the administrator or user. Channels must be renewed every 180 days, otherwise content is erased; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: microsoft.com/de-de/microsoft-teams/; privacy policy: privacy.microsoft.com/de-de/privacystatement. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Newsletter and Electronic Notifications
We send newsletters, emails and other electronic notifications (hereinafter "newsletter") exclusively with the consent of the recipients or on the basis of a legal authorization. Insofar as the contents of a newsletter are named in the context of a registration for it, these contents are decisive for the consent of the users. As a rule, providing your email address is sufficient to register for our newsletter. However, in order to be able to offer you a personalized service, we may ask you to provide your name for personal address in the newsletter, or for further information if this is necessary for the purpose of the newsletter.
Erasure and restriction of processing: We may store the unsubscribed email addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to provide evidence of consent previously given. The processing of this data is limited to the purpose of a potential defense against claims. An individual erasure request is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a block list (so-called "blocklist").
The logging of the registration procedure takes place on the basis of our legitimate interests for the purpose of providing evidence of its proper course. Insofar as we commission a service provider with the sending of emails, this takes place on the basis of our legitimate interests in an efficient and secure dispatch system.
Contents: Information about us, our services, promotions and offers.
Further information on processing operations, procedures and services:
4 Services / Processors
Measurement of open and click rates: The newsletters contain a so-called "web beacon", i.e., a pixel-sized file that is retrieved from our server or that of our dispatch service provider, if we use one, when the newsletter is opened. In the course of this retrieval, technical information, such as details of the browser and your system, as well as your IP address and the time of retrieval, is initially collected. This information is used for the technical improvement of our newsletter. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. The measurement of open and click rates as well as the storage of the measurement results in the profiles of the users and their further processing take place on the basis of the users' consent; legal bases: Consent (Art. 6 (1) (1) (a) GDPR).
Prerequisite for the use of free services: Consent to the dispatch of mailings can be made a prerequisite for the use of free services (e.g., access to certain content or participation in certain promotions). Should users wish to use the free service without subscribing to the newsletter, we ask them to contact us.
Reminder emails for the ordering process: If users do not complete an ordering process, we may remind the users of the ordering process by email and send them a link to continue it. The dispatch takes place on the basis of consent, which users can withdraw at any time; legal bases: Consent (Art. 6 (1) (1) (a) GDPR).
HubSpot email marketing: Sending of emails, creation of personalized campaigns, automation of workflows, segmentation of target groups, integration with CRM systems, analysis of performance through reports and dashboards; service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; legal bases: Consent (Art. 6 (1) (1) (a) GDPR), legitimate interests (Art. 6 (1) (1) (f) GDPR); website: hubspot.com/products/marketing/email; privacy policy: legal.hubspot.com/de/privacy-policy; data processing agreement: legal.hubspot.com/dpa. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Promotional Communication via Email, Post, Fax or Telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as email, telephone, post or fax, in accordance with the legal requirements.
Recipients have the right to withdraw consent given at any time, or to object to promotional communication at any time free of charge via the contact option given above.
After withdrawal or objection, we store the data required to provide evidence of the previous authorization to contact you or send you mailings for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is limited to the purpose of a possible defense against claims. On the basis of the legitimate interest in permanently observing the withdrawal or objection of the users, we furthermore store the data required to avoid renewed contact (e.g., depending on the communication channel, the email address, telephone number, name).
Surveys and Questionnaires
We conduct surveys and questionnaires in order to collect information for the respectively communicated survey or questionnaire purpose. The surveys and questionnaires we conduct (hereinafter "surveys") are evaluated anonymously. Personal data is processed only insofar as this is necessary for the provision and technical implementation of the surveys (e.g., processing of the IP address in order to display the survey in the user's browser, or to enable a resumption of the survey with the help of a cookie).
Further information on processing operations, procedures and services:
1 Service / Processor
Microsoft Forms: Creation of online forms, collection of responses in real time, analysis of results with integrated charts. Integration into other Office applications for further data processing; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: forms.office.com; privacy policy: privacy.microsoft.com/de-de/privacystatement. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Customer Reviews and Rating Procedures
We participate in review and rating procedures in order to evaluate, optimize and promote our services. When users rate us or otherwise provide feedback via the participating rating platforms or procedures, the general terms and conditions of business or use and the privacy notices of the providers additionally apply. As a rule, the rating also requires registration with the respective providers.
In order to ensure that the rating persons have actually used our services, we transmit the data required for this purpose with regard to the customer and the service used to the respective rating platform (including name, email address and order number or item number), with the consent of the customers. This data is used solely to verify the authenticity of the user.
Further information on processing operations, procedures and services:
1 Service / Processor
Trustpilot: Rating platform; service provider: Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen, Denmark; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: de.trustpilot.com; privacy policy: de.legal.trustpilot.com/for-reviewers/end-user-privacy-terms. Data processing agreement: de.legal.trustpilot.com/for-businesses/data-processing-agreement.
Transmission of Personal Data
In the course of our processing of personal data, it may occur that this data is transmitted to, or disclosed to, other entities, companies, legally independent organizational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded in a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.
Data transmission within the organization: We may transmit personal data to other departments or units within our organization or grant them access to it. Where such data sharing takes place for administrative purposes, it is based on our legitimate business and economic interests, or it takes place where it is necessary for the fulfillment of our contract-related obligations, or where consent of the data subjects or a statutory permission exists.
International Data Transfers
Data processing in third countries: Where we transmit data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosing or transmitting data to other persons, entities or companies (which becomes apparent from the postal address of the respective provider or where a data transfer to third countries is expressly indicated in the privacy policy), this is always done in accordance with the legal requirements.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded Standard Contractual Clauses with the respective providers that comply with the requirements of the EU Commission and establish contractual obligations to protect your data.
This twofold safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the Standard Contractual Clauses serve as additional security. Should changes occur within the framework of the DPF, the Standard Contractual Clauses act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.
For each individual service provider, we inform you whether they are certified under the DPF and whether Standard Contractual Clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/.
For data transfers to other third countries, corresponding safeguards apply, in particular Standard Contractual Clauses, explicit consents, or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
Amendment and Update
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g., consent) or other individual notification.
Insofar as we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time, and we ask you to check the information before making contact.
Supervisory authority responsible for us:
Bayerisches Landesamt für Datenschutzaufsicht (Bavarian State Office for Data Protection Supervision)Promenade 18
91522 Ansbach
Postal address: Postfach 1349, 91504 Ansbach
Telephone: +49 (0) 981 / 190093-0
Email: poststelle@lda.bayern.de
Homepage: www.lda.bayern.de
Contact Option
If you have any further questions, please feel free to contact us at hello@cyber-fidelity.com or use our contact form.
Presence in Social Networks (Social Media)
We maintain online presences within social networks and, in this context, process user data in order to communicate with the users active there or to offer information about us.
We point out that user data may be processed outside the area of the European Union in this context. This may give rise to risks for the users, because, for example, the enforcement of user rights could be made more difficult.
Furthermore, the data of the users within social networks is, as a rule, processed for market research and advertising purposes. For example, usage profiles can be created based on the usage behavior and the resulting interests of the users. The latter may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For this reason, cookies are, as a rule, stored on the computers of the users, in which the usage behavior and the interests of the users are stored. In addition, data may also be stored in the usage profiles independently of the devices used by the users (in particular if they are members of the respective platforms and logged in there).
For a detailed presentation of the respective forms of processing and the possibilities to object (opt-out), we refer to the privacy policies and information of the operators of the respective networks.
Also in the case of requests for access and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the latter have access to the user data in each case and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you can contact us.
Further information on processing operations, procedures and services:
9 Services / Processors
Instagram: Social network, enables the sharing of photos and videos, the commenting on and favoriting of posts, sending of messages, subscribing to profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: instagram.com; privacy policy: privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
Facebook Pages: Profiles within the social network Facebook — The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page ("fanpage"). This includes in particular information about user behavior (e.g., content viewed or interacted with, actions performed) as well as device information (e.g., IP address, operating system, browser type, language settings, cookie data). Facebook also uses this data to provide us with statistical evaluations via the "Page Insights" service. Users can direct requests for access or erasure directly to Facebook; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: facebook.com; privacy policy: facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
LinkedIn: Social network — We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data of visitors that is used to create the "Page Insights" (statistics) of our LinkedIn profiles. We have concluded a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum"). The rights of the users (in particular the right to access, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn; service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: linkedin.com; privacy policy: linkedin.com/legal/privacy-policy; basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses. Possibility to object (opt-out): linkedin.com/psettings/guest-controls/retargeting-opt-out.
Threads: Social network; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: threads.com. Privacy policy: help.instagram.com/515230437301944.
TikTok: Social network, enables the sharing of photos and videos, the commenting on and favoriting of posts, sending of messages, subscribing to accounts; service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: tiktok.com; privacy policy: tiktok.com/legal/page/eea/privacy-policy/de. Data processing agreement: Provided by the service provider.
TikTok Business: Social network — We and TikTok are jointly responsible for the collection and transmission of event data as well as for the measurement and creation of insights reports (statistics) for profile owners. We have concluded a special agreement on joint responsibility with TikTok; service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; legal bases: Consent (Art. 6 (1) (1) (a) GDPR); website: tiktok.com; privacy policy: tiktok.com/legal/page/eea/privacy-policy/de. Basis for third-country transfers: Standard Contractual Clauses.
X: Social network; service provider: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: x.com. Privacy policy: x.com/de/privacy.
YouTube: Social network and video platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); privacy policy: policies.google.com/privacy; basis for third-country transfers: Data Privacy Framework (DPF). Possibility to object (opt-out): myadcenter.google.com/personalizationoff.
Xing: Social network; service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); website: xing.com. Privacy policy: privacy.xing.com/de/datenschutzerklaerung.