Datenschutzbestimmungen

1. Data Protection at a Glance

Principle
We appreciate your interest. Data protection is a high priority for AIghty20 Elevate AG. You can generally use our websites without providing any personal data. However, if you wish to use our services via our website, the processing of personal data may be required. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain your consent. The processing of personal data, such as your name, address, telephone number, or email address, always complies with the General Data Protection Regulation (GDPR) and the country-specific data protection regulations applicable to AIghty20 Elevate AG. Through this privacy policy, we aim to inform the public about the nature, purpose, and scope of the personal data we collect, use, and process. Additionally, this privacy policy aims to inform you about your rights. As the data controller, AIghty20 Elevate AG has implemented numerous organizational and technical measures to ensure the most comprehensive protection possible of personal data processed through this website. Nevertheless, internet-based data transmissions can inherently have security vulnerabilities, meaning absolute protection cannot be guaranteed. Therefore, you are free to transmit personal data to us through alternative means, such as by mail or telephone.

2. General Information and Mandatory Disclosures

Controller
The controller, in the sense of the General Data Protection Regulation, other data protection laws applicable in the member states of the European Union, and other provisions of a data protection nature, is:

AIghty20 Elevate AG
Florian Muff
Kapellstrasse 6
8355 Aadorf / Switzerland
thomas@aighty20.com

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).

You can contact us directly at any time with all questions and suggestions regarding data protection.

Our Websites
Our websites ("online presences") include the domains:
www.aighty20.com
member.aighty20.com (Member Portal)
or websites associated with
*.aighty20.com / .ch
*.aighty20elevate.com / .ch
*.elevateaighty.20.com / .ch

The following information refers to and applies to the domains listed above.

Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. An informal email notification to us is sufficient for this. The legality of the data processing carried out until the withdrawal remains unaffected by the withdrawal.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)
If data processing is based on Art. 6 para. 1 lit. e or f GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation; this also applies to profiling based on these provisions. You can find the respective legal basis for processing in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims (objection according to Art. 21 para. 1 GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes (objection according to Art. 21 para. 2 GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of data protection violations, you have the right to lodge a complaint with the competent supervisory authority.

In Switzerland, the competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch/

For persons in the EU/EEA, the competent supervisory authority is the data protection authority of your place of residence or work.

Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of data to another controller, this will only be done if it is technically feasible.

SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the padlock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Information, Blocking, Deletion, and Rectification
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of data processing, and, if applicable, a right to rectification, blocking, or deletion of this data. For this and for further questions on the subject of personal data, you can contact us at any time at the address given above.

Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. For this, you can contact us at any time at the address given above. The right to restriction of processing exists in the following cases:

- If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.

- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.

- If we no longer need your personal data, but you require it for the establishment, exercise, or defense of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.

- If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – apart from their storage – may only be processed with your consent or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.

Objection to Promotional Emails
The use of contact data published within the scope of the imprint obligation for sending unsolicited advertising and information material is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, for example, via spam emails.

3. Applicable Legal Bases

Applicable Legal Bases under the GDPR
Below you will find an overview of the legal bases under the GDPR on which we process personal data. Please note that in addition to the GDPR regulations, national data protection requirements may apply in your or our country of residence or establishment. Furthermore, if more specific legal bases are applicable in individual cases, we will inform you of these in the privacy policy.
Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR): The data subject has given consent to the processing of their personal data for one or more specific purposes.
Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR): Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR): Processing is necessary for compliance with a legal obligation to which the controller is subject.
Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR): Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National Data Protection Regulations in Switzerland
If you are located in Switzerland, we process your data based on the Federal Act on Data Protection (hereinafter referred to as "Swiss DPA"). This also applies if our processing of your data otherwise concerns you in Switzerland and you are affected by the processing. Unlike the GDPR, the Swiss DPA generally does not require a legal basis to be stated for the processing of personal data. We only process personal data if the processing is lawful, carried out in good faith, and proportionate (Art. 6 para. 1 and 2 of the Swiss DPA). Furthermore, we only collect personal data for a specific purpose identifiable to the data subject and process it only in a manner compatible with that purpose (Art. 6 para. 3 of the Swiss DPA).
Notice on Applicability of GDPR and Swiss DPA
These privacy notices serve to provide information under both the Swiss Federal Act on Data Protection (Swiss DPA) and the General Data Protection Regulation (GDPR). Therefore, please note that due to their broader territorial application and comprehensibility, the terms of the GDPR are used. Specifically, instead of the terms used in the Swiss DPA such as "processing" of "personal data", "overriding interest", and "particularly sensitive personal data", the terms used in the GDPR, namely "processing" of "personal data", "legitimate interest", and "special categories of data", are employed. However, the legal meaning of these terms will continue to be determined by the Swiss DPA within the scope of its applicability.

4. Overview of Processing Activities

The following overview summarizes the types of data processed, the purposes of their processing, and the data subjects involved.

Types of Data Processed
- Master data (e.g., names, addresses)
- Content data (e.g., entries in online forms)
- Contact data (e.g., email, phone numbers)
- Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status)
- Usage data (e.g., visited websites, interest in content, access times)
- Contract data (e.g., subject matter of contract, term, customer category)
- Payment data (e.g., bank details, invoices, payment history)
- Event data (e.g., data via Facebook Pixel, Meta Pixel, LinkedIn Insight Tag)

Categories of Data Subjects
- Business and contractual partners
- Prospective customers
- Communication partners
- Customers
- Users (e.g., website visitors, users of online services)

Purposes of Processing
- Provision of our online services and user-friendliness
- Office and organizational procedures
- Content Delivery Network (CDN)
- Direct marketing (e.g., via email or postal mail)
- Feedback (e.g., collecting feedback via online form)
- Interest-based and behavioral marketing
- Conversion measurement (measuring the effectiveness of marketing campaigns)
- Contact inquiries and communication
- Marketing
- Profiles with user-related information (creation of user profiles)
- Reach measurement (e.g., access statistics, recognition of returning visitors)
- Remarketing
- Security measures
- Tracking (e.g., interest-based/behavioral profiling, use of cookies)
- Management and response to inquiries
- Audience segmentation
- Provision of contractual services and fulfillment of contractual obligations

5. Security Measures

In accordance with legal requirements and considering the state of the art, implementation costs, the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security commensurate with the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as controlling access, input, disclosure, and separation of the data, and ensuring its availability. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data breaches. Moreover, we consider the protection of personal data already during the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.

These security measures include, in particular, the encrypted transmission of data between your browser and our server using TLS encryption.

6. Transfer of Personal Data

In the course of our processing of personal data, it may occur that data is transmitted to or disclosed to other entities, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data, which serve to protect your data.

7. International Data Transfers

Data processing in third countries: If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA), or Switzerland) or if processing occurs in the context of using third-party services or disclosing/transferring data to other individuals, entities, or companies, this is done only in compliance with legal requirements.

Subject to explicit consent or contractually or legally required transfer, we only process or have data processed in third countries with a recognized level of data protection, contractual obligation through so-called standard contractual clauses of the EU Commission, upon the existence of certifications, or binding internal data protection regulations (Art. 44 to 49 GDPR, EU Commission information page).

EU-US Data Privacy Framework
Within the framework of the so-called "Data Privacy Framework" (DPF), the EU Commission has recognized the level of data protection for certain companies from the USA as adequate. You can find the list of certified companies and further information on the DPF on the website of the U.S. Department of Commerce. We will inform you in our privacy policy which service providers we use are certified under the Data Privacy Framework.

8. Deletion of Data

The data we process will be deleted in accordance with legal requirements as soon as the consents permitting their processing are revoked or other permissions cease to apply (e.g., if the purpose for processing these data has ceased or they are no longer required for that purpose). If the data are not deleted because they are required for other legally permissible purposes, their processing will be restricted to these purposes. This means the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person.
Our privacy policy may also contain further information on data retention and deletion, which take precedence for the respective processing activities.

Retention periods for various data categories
– Technical data (server log files, IP addresses): 6 months
– Registration data (member portal): 12 months after contract termination
– Communication data (email, telephone): 12 months after completion of the process, tax-relevant communication 10 years
– Master data (name, address, customer contact details): 10 years after contract termination
– Contract data: 10 years after contract termination
– Payment data: 10 years after contract termination
– Usage data (Google Analytics): 14 months (automatic deletion)
– Cookie data: max. 2 years, depending on cookie type
Newsletter data: Until consent is revoked

9. Rights of Data Subjects

As a data subject, you have various rights under the GDPR, particularly those arising from Articles 15 to 21 of the GDPR:

Right of Access (Art. 15 GDPR)
You have the right to request confirmation as to whether data concerning you is being processed, and to access this data, as well as to receive further information and a copy of the data in accordance with legal requirements.

Right to Rectification (Art. 16 GDPR)
In accordance with legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.

Right to Erasure and Restriction of Processing (Arts. 17 and 18 GDPR)
In accordance with legal requirements, you have the right to demand that data concerning you be erased without undue delay, or alternatively, in accordance with legal requirements, to demand a restriction of the processing of the data.

Right to Data Portability (Art. 20 GDPR)
You have the right to receive data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format in accordance with legal requirements, or to request its transmission to another controller.

Right to Object (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.

Withdrawal of Consent
You have the right to withdraw granted consents at any time.

Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
In accordance with legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.

10. Business Services

We process data of our contractual and business partners, e.g., customers and prospective customers (collectively referred to as "contractual partners"), within the scope of contractual and similar legal relationships, as well as related measures and communication with the contractual partners (or pre-contractually), e.g., to answer inquiries.

We process this data to fulfill our contractual obligations. This includes, in particular, obligations to provide agreed services, any update obligations, and remedies for warranty and other performance disruptions. We also process the data to safeguard our rights and for administrative tasks associated with these obligations, as well as for corporate organization. Furthermore, we process the data based on our legitimate interests in proper and economical business management, and in security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information, and rights.

Types of data processed: Inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., email, phone numbers); contract data (e.g., subject matter of contract, term, customer category); usage data (e.g., visited websites, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, consent status).
Data subjects: Prospective customers; business and contractual partners; customers.
Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; contact inquiries and communication; office and organizational procedures; management and answering of inquiries.
Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

11. Provision of the Online Offering and Web Hosting

We process user data to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.
Types of Data Processed: Usage data (e.g., visited web pages, interest in content, access times); Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); Content data (e.g., entries in online forms).
Data Subjects: Users (e.g., website visitors, users of online services).
Purposes of Processing: Provision of our online offering and user-friendliness; IT infrastructure (operation and provision of information systems and technical devices); Security measures; Content Delivery Network (CDN).
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Collection of Access Data and Log Files
Access to our online offering is logged in the form of "server log files." Server log files may include the address and name of the accessed web pages and files, the date and time of access, transferred data volumes, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and typically IP addresses and the requesting provider. Server log files can be used for security purposes, for example, to prevent server overload (especially in the case of abusive attacks, so-called DDoS attacks), and also to ensure server utilization and stability.
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Data Deletion: Log file information is stored for a maximum of 6 months and then deleted or anonymized. Data whose further retention is required for evidentiary purposes is exempt from deletion until the final clarification of the respective incident.
Further Information on Processing Procedures, Processes, and Services
Webflow: Hosting and software for creating, providing, and operating websites, blogs, landing pages, and shop systems
Service Provider: Webflow, Inc., 208 Utah Street, San Francisco, CA 94103, USA;
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR);
Website: https://webflow.com
Privacy Policy: https://webflow.com/legal/eu-privacy-policy
Data Processing Agreement: https://webflow.com/legal/dpa
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Services in the field of providing IT infrastructure and related services (e.g., storage space and/or computing capacities)
Service Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website:
Privacy Policy:
Data Processing Agreement:
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Further information: . 
Services in the field of providing IT infrastructure and related services (e.g., storage space and/or computing capacities)
Service Provider: Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus
Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website:
Privacy Policy:
Data Processing Agreement: provided by the service provider.

12. Contact and Inquiry Management

When contacting us (e.g., by mail, contact form, email, phone, or social media) and within the scope of existing user and business relationships, the information provided by the inquiring persons is processed to the extent necessary to answer contact inquiries and any requested measures.

Types of data processed: Contact data (e.g., email, phone numbers); Content data (e.g., entries in online forms); Usage data (e.g., visited websites, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).

Data subjects: Communication partners. Purposes of processing: Contact inquiries and communication; Management and answering of inquiries; Feedback (e.g., collecting feedback via online form); Provision of our online offering and user-friendliness.

Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).

Additional information on processing procedures, processes, and services
Contact form: If users contact us via our contact form, email, or other communication channels, we process the data provided to us in this context to handle the communicated request;
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

MocoApp: Customer Relationship Management (CRM), project management, time tracking, and invoicing
Service provider: hundertzehn GmbH In der Weid 15, 8122 Binz, Switzerland
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.mocoapp.com
Privacy Policy: https://www.mocoapp.com/datenschutz Data Processing Agreement: provided by the service provider.

fonio.ai: AI-powered telephone assistant for automated processing of incoming calls. fonio handles call answering, transcription, and structured forwarding of inquiries. The service is used to ensure telephone accessibility outside business hours and to answer standard inquiries automatically.
Service provider: fonio GmbH, Joanelligasse 5/16, 1060 Vienna, Austria
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR), Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) — Callers are informed about the AI-powered processing at the beginning of the conversation.
Website:
Privacy Policy: https://docs.fonio.ai/Datenschutz/Datenschutz
Hosting: Hetzner Online GmbH, Nuremberg, Germany (all data remains within the EU)
Data processed: Caller's phone number, conversation content (transcription), time and duration of the call, if applicable, caller's name and request.
Note: fonio uses Large Language Models (LLMs) from OpenAI via Microsoft Azure servers in Europe. No data is transferred to servers outside the EU. Upon the caller's request, all conversation data is deleted in real-time.
Data Processing Agreement: provided by the service provider.

13. Communication via Messenger

For communication purposes, we use messengers and therefore ask you to observe the following information regarding the functionality of the messengers, encryption, the use of communication metadata, and your options for objection.

You can also contact us via alternative channels, e.g., by phone or email. Please use the contact options provided to you or those listed within our online offering.

In the case of end-to-end encryption of content (i.e., the content of your message and attachments), we point out that the communication content (i.e., the content of the message and attached images) is end-to-end encrypted. This means that the content of the messages is not visible, not even to the messenger providers themselves. You should always use an up-to-date version of the messenger with encryption activated to ensure the encryption of message content.

However, we also inform our communication partners that while messenger providers cannot view the content, they can ascertain that and when communication partners communicate with us, as well as process technical information about the device used by the communication partners and, depending on their device settings, also location information (so-called metadata).

Types of data processed: Contact data (e.g., email, phone numbers); Usage data (e.g., visited websites, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); Content data (e.g., entries in online forms).
Data subjects: Communication partners.
Purposes of processing: Contact inquiries and communication; Direct marketing (e.g., via email or postal mail).
Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing operations, procedures, and services:
WhatsApp Business: Messenger with end-to-end encryption; Service provider: WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.whatsapp.com
Privacy Policy: https://www.whatsapp.com/legal/privacy-policy
Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.

14. Cloud Services

We use software services accessible via the internet and executed on the servers of their providers (so-called "cloud services," also referred to as "Software as a Service") for storing and managing content (e.g., document storage and management, exchange of documents, content, and information with specific recipients, or publication of content and information).
In this context, personal data may be processed and stored on the providers' servers, insofar as they are part of communication processes with us or are otherwise processed by us as outlined in this privacy policy. This data may include, in particular, master data and contact data of users, data on processes, contracts, other procedures, and their contents.
Types of data processed: Inventory data (e.g., names, addresses); Contact data (e.g., email, phone numbers); Content data (e.g., entries in online forms); Usage data (e.g., visited websites, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
Data subjects: Customers; employees (e.g., staff, applicants, former employees); interested parties; communication partners.
Purposes of processing: Office and organizational procedures; Information technology infrastructure (operation and provision of information systems and technical devices).
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing operations, procedures, and services
Google Cloud Platform: Cloud storage, cloud infrastructure services, and cloud-based application software, especially for our member portal (member.aighty20.com)
Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://cloud.google.com/
Privacy Policy: https://business.safety.google/privacy/
Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum
Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Further information: https://cloud.google.com/privacy.
Google Firebase: Authentication, real-time database (Firestore), and hosting for our member portal (member.aighty20.com). Firebase is used for user registration, login management, and data storage within the member area.
Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland
Legal basis: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)Website: https://firebase.google.com
Privacy Policy: https://firebase.google.com/support/privacy
Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum
Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Data processed: Email addresses, password hashes, login times, IP addresses, user-generated content in the member area.
Storage location: EU (server location according to Google Cloud configuration).
Microsoft Cloud Services: Cloud storage, cloud infrastructure services, and cloud-based application software (Microsoft 365, OneDrive, Teams); Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://microsoft.com/de-de
Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement
Data Processing Agreement: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA
Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.

15. Newsletters and Electronic Notifications

We send newsletters, emails, and other electronic notifications (hereinafter "newsletters") only with the consent of the recipients or a legal authorization. If the content of a newsletter is specifically described during registration, this description is decisive for the user's consent. Otherwise, our newsletters contain information about our services and us.

To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name for personalized addressing in the newsletter, or other information if it is necessary for the purposes of the newsletter.

Double Opt-In Procedure
Subscription to our newsletter generally takes place via a so-called double opt-in procedure. This means that after registration, you will receive an email asking you to confirm your subscription. This confirmation is necessary to prevent anyone from registering with third-party email addresses. Newsletter registrations are logged to be able to prove the registration process in accordance with legal requirements. This includes storing the registration and confirmation times, as well as the IP address. Changes to your data stored with the shipping service provider are also logged.
Deletion and Restriction of Processing
We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to prove a previously given consent. The processing of this data is limited to the purpose of potentially defending against claims. An individual deletion request is possible at any time, provided that the prior existence of consent is simultaneously confirmed. In the event of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist.
Types of data processed: Inventory data (e.g., names, addresses); Contact data (e.g., email, phone numbers); Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); Usage data (e.g., visited websites, interest in content, access times).
Data subjects: Communication partners.
Purposes of processing: Direct marketing (e.g., via email or postal mail).
Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Right to object (Opt-Out): You can unsubscribe from our newsletter at any time, i.e., revoke your consent or object to further receipt. A link to unsubscribe from the newsletter can be found either at the end of each newsletter, or you can use the contact options provided above, preferably email, for this purpose.
Further Information on Processing Operations, Procedures, and Services
Brevo (formerly Sendinblue): Email marketing and newsletter dispatch; Service provider: Sendinblue GmbH, Köpenicker Strasse 126, 10179 Berlin, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.brevo.com/de/
Privacy Policy: https://www.brevo.com/de/legal/privacypolicy/
Data Processing Agreement: provided by the service provider.
Measuring Open and Click-Through Rates
Our newsletters contain a so-called "web beacon," which is a pixel-sized file retrieved from our server when the newsletter is opened. During this retrieval, technical information such as browser and system details, your IP address, and the time of access are collected. This information is used for the technical improvement of our newsletter based on technical data, or to understand target audiences and their reading behavior based on their access locations (which can be determined using the IP address) or access times. This analysis also includes determining whether newsletters are opened, when they are opened, and which links are clicked. The information is assigned to individual newsletter recipients and stored in their profiles until deletion.
Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

16. Surveys and Polls

We conduct surveys and polls to gather information for the communicated survey or polling purpose. The surveys and polls we conduct (hereinafter "surveys") are evaluated anonymously. Personal data is processed only to the extent necessary for the provision and technical execution of the surveys (e.g., processing of the IP address to display the survey in the user's browser or to enable the resumption of the survey using a cookie).
Types of data processed: Contact data (e.g., email, phone numbers); Content data (e.g., entries in online forms); Usage data (e.g., visited websites, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
Data subjects: Communication partners; Participants.
Purposes of processing: Feedback (e.g., collecting feedback via online form).
Legal bases: Legitimate interests (Art. 6 para. 1 lit. f GDPR).

Further information on processing operations, procedures, and services
Typeform: Creation and evaluation of online forms, surveys, feedback forms, etc.
Service provider: TYPEFORM S.L., Carrer Bac de Roda, 163, 08018 Barcelona, Spain
Legal basis: Legitimate interests (Art. 6 para. 1 lit. f GDPR)
Website: https://www.typeform.com
Privacy Policy: https://www.typeform.com/help/a/what-is-typeform-s-privacy-policy-360029095812/
Data Processing Agreement: https://admin.typeform.com/to/dwk6gt.
Google Forms: Creation and evaluation of online forms, surveys, feedback forms, etc.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 lit. f GDPR)
Website: https://www.google.com/forms
Privacy Policy: https://business.safety.google/privacy/
Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum
Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Microsoft Forms: Creation and evaluation of online forms, surveys, feedback forms, etc.
Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 lit. f GDPR)
Website: https://www.microsoft.com/microsoft-365/online-surveys-polls-quizzes
Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement
Basis for third-country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.

17. Web Analysis, Monitoring, and Optimization

Web analysis (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offering and can include behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, identify at what times our online offering or its functions or content are most frequently used or invite re-use. We can also understand which areas require optimization.
In addition to web analysis, we may also use testing procedures to, for example, test and optimize different versions of our online offering or its components.
Unless otherwise stated below, profiles, i.e., data summarized for a usage process, can be created for these purposes, and information can be stored in and read from a browser or an end device. The collected data includes, in particular, visited websites and elements used there, as well as technical information such as the browser used, the computer system used, and usage times. If users have consented to the collection of their location data by us or by the providers of the services we use, location data may also be processed.
User IP addresses are also stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect users. Generally, within the scope of web analysis, A/B testing, and optimization, no clear user data (such as email addresses or names) is stored, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Types of Data Processed: Usage data (e.g., visited web pages, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, consent status).
Data Subjects: Users (e.g., website visitors, users of online services).Purposes of Processing: Reach measurement (e.g., access statistics, recognition of returning visitors); Profiles with user-related information (creation of user profiles); Tracking (e.g., interest/behavior-based profiling, use of cookies); Provision of our online offering and user-friendliness.
Security Measures: IP masking (pseudonymization of the IP address).
Legal Bases: Consent (Art. 6 para. 1 lit. a) GDPR); Legitimate Interests (Art. 6 para. 1 lit. f) GDPR).

Further Information on Processing Operations, Procedures, and Services
Google Analytics 4: We use Google Analytics to measure and analyze the use of our online offering based on a pseudonymous user identification number. This identification number does not contain unique data such as names or email addresses. It serves to assign analytical information to an end device to identify which content users have accessed within one or various usage processes, which search terms they have used, have accessed again, or have interacted with our online offering. Likewise, the time and duration of use are stored, as well as the sources of users who refer to our online offering and technical aspects of their end devices and browsers. In this process, pseudonymous user profiles are created with information from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides approximate geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. They are not logged, are not accessible, and are not used for further purposes. When Google Analytics collects measurement data, all IP queries are performed on EU-based servers before the traffic is forwarded to Analytics servers for processing.
Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal Basis: Consent (Art. 6 para. 1 lit. a) GDPR)
Website: https://marketingplatform.google.com/intl/de/about/analytics/ Privacy Policy: https://business.safety.google/privacy/ Data Processing Agreement: https://business.safety.google/adsprocessorterms/ Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses; Opt-Out Option: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for Ad Display: https://adssettings.google.com/authenticated. Further Information: https://business.safety.google/adsservices/.
Google Tag Manager: Google Tag Manager is a solution that allows us to manage so-called website tags via a single interface and thus integrate other services into our online offering (for more information, please refer to other details in this privacy policy). The Tag Manager itself (which implements the tags) does not, for example, create user profiles or store cookies. Google only learns the user's IP address, which is necessary to run Google Tag Manager.
Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal Basis: Consent (Art. 6 para. 1 lit. a) GDPR)
Website: https://marketingplatform.google.com
Privacy Policy: https://business.safety.google/privacy/
Data Processing Agreement: https://business.safety.google/adsprocessorterms
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.

18. Online Marketing

We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of promotional and other content (collectively referred to as "content") based on users' potential interests, as well as measuring their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (a "cookie") or similar methods are used, by means of which information relevant for displaying the aforementioned content about the user is stored. This information may include, for example, viewed content, visited websites, online networks used, as well as communication partners and technical data such as the browser used, the computer system used, and information on usage times and functions utilized. If users have consented to the collection of their location data, this may also be processed.
User IP addresses are also stored. However, we use available IP masking procedures (i.e., pseudonymization by shortening the IP address) to protect users. Generally, within the online marketing process, no clear data of users (such as email addresses or names) are stored, but rather pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.
The information in the profiles is usually stored in cookies or by similar methods. These cookies can generally also be read out later on other websites that use the same online marketing procedure, analyzed for the purpose of displaying content, supplemented with further data, and stored on the server of the online marketing procedure provider.
Exceptionally, clear data may be assigned to the profiles. This is the case, for example, if users are members of a social network whose online marketing procedure we use, and the network links the user profiles with the aforementioned information. Please note that users may enter into additional agreements with the providers, for example, through consent during registration.
In principle, we only receive access to aggregated information about the success of our advertisements. However, through so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e., for example, to a contract conclusion with us. Conversion measurement is used solely to analyze the success of our marketing measures.
Unless otherwise stated, please assume that cookies used are stored for a period of two years.
Types of Data Processed: Usage data (e.g., visited websites, interest in content, access times); Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status); Event data (e.g., data transmitted by us to the platforms via Facebook Pixel, Meta Pixel, LinkedIn Insight Tag).
Data Subjects: Users (e.g., website visitors, users of online services).
Purposes of Processing: Reach measurement (e.g., access statistics, recognition of returning visitors); Tracking (e.g., interest/behavior-based profiling, use of cookies); Conversion measurement (measuring the effectiveness of marketing measures); interest-based and behavior-based marketing; Profiling (creating user profiles); Audience creation; Remarketing; Provision of our online offering and user-friendliness.
Security Measures: IP Masking (pseudonymization of the IP address).
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Opt-Out Option: We refer to the privacy policies of the respective providers and the opt-out options (so-called "opt-out") provided by them. If no explicit opt-out option is specified, you can disable cookies in your browser settings. However, this may limit the functionality of our online offering.

Further Information on Processing Procedures, Methods, and Services
Google Ads and Conversion Measurement: Online marketing method for placing content and advertisements within the service provider's advertising network (e.g., in search results, videos, on websites, etc.), so that they are displayed to users who have a presumed interest in the ads. Furthermore, we measure the conversion of the ads, i.e., whether users interacted with the ads and used the advertised offers as a result
Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR), Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://marketingplatform.google.com
Privacy Policy: https://business.safety.google/privacy/
Data Processing Agreement: https://business.safety.google/adsprocessorterms
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Google Ads Remarketing: Google Remarketing, also known as retargeting, is a technology that adds users who use an online service to a pseudonymous remarketing list, allowing ads to be displayed to these users on other online offerings based on their visit to the online service
Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR)
Website: https://marketingplatform.google.com
Privacy Policy: https://business.safety.google/privacy/
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Meta Pixel and Audience Creation (Custom Audiences): With the help of the Meta Pixel (or comparable functions for transmitting event data or contact information via interfaces in apps), Meta can identify visitors to our online offering as a target audience for displaying advertisements (so-called "Meta Ads"). Accordingly, we use the Meta Pixel to show the Meta Ads we place only to users on Meta platforms and within the services of Meta's cooperating partners who have shown an interest in our online offering. With the Meta Pixel, we also want to ensure that our Meta Ads correspond to the potential interests of users and do not appear intrusive. Furthermore, the Meta Pixel allows us to track the effectiveness of Meta Ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta Ad (so-called "conversion measurement")
Service Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR)
Website: https://www.facebook.com
Privacy Policy: https://www.facebook.com/about/privacy
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Further information: User event data, i.e., behavioral and interest information, is processed for the purposes of targeted advertising and audience creation based on the joint controller agreement.
Facebook Ads: Displaying advertisements within the Facebook platform and evaluating ad results
Service Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR)
Website: https://www.facebook.com
Privacy Policy: https://www.facebook.com/about/privacy
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
Instagram Ads: Displaying advertisements within the Instagram platform and evaluating ad results
Service Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR)
Website: https://www.instagram.com
Privacy Policy: https://instagram.com/about/legal/privacy
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses.
LinkedIn Insight Tag / Conversion Measurement: The LinkedIn Insight Tag allows us to measure conversions, track website visitors, and gain deeper insights into the performance of our LinkedIn campaigns
Service Provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR)
Website: https://www.linkedin.com
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Basis for Third-Country Transfer: Standard Contractual Clauses (https://legal.linkedin.com/dpa)
Opt-Out Option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Microsoft Advertising: Online marketing method for placing content and advertisements within the service provider's advertising network (e.g., in search results, videos, on websites, etc.), so that they are displayed to users who have a presumed interest in the ads
Service Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Legal Basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR), Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://about.ads.microsoft.com/
Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement
Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF)
Opt-Out Option: https://account.microsoft.com/privacy/ad-settings/.

19. Presences on social networks (Social Media)

We maintain online presences within social networks and process user data in this context to communicate with active users there or to offer information about us. We would like to point out that user data may be processed outside the European Union. This may entail risks for users, for example, because the enforcement of user rights could be made more difficult.
Types of data processed: Contact data (e.g., email, phone numbers); Content data (e.g., entries in online forms); Usage data (e.g., visited websites, interest in content, access times); Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, consent status).
Data subjects: Users (e.g., website visitors, users of online services).
Purposes of processing: Contact inquiries and communication; Feedback (e.g., collecting feedback via online form); Marketing.
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing procedures, processes, and services
Facebook Pages: Profiles within the social network Facebook
Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.facebook.com
Privacy Policy: https://www.facebook.com/about/privacy.
Instagram: Social network; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.instagram.com
Privacy Policy: https://instagram.com/about/legal/privacy.
LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.linkedin.com
Privacy Policy: https://www.linkedin.com/legal/privacy-policy.
YouTube: Social network and video platform
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.youtube.com
Privacy Policy: https://policies.google.com/privacy.
TikTok: Social network / video platform
Service provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)
Website: https://www.tiktok.com
Privacy Policy: https://www.tiktok.com/legal/privacy-policy.

20. Plugins and embedded functions and content

We integrate functional and content elements into our online offering that are sourced from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may include, for example, graphics, videos, or social media buttons and posts.
Types of data processed: Usage data (e.g., visited web pages, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing procedures, processes, and services
YouTube Videos: Video content
Service provider: Google IrelandLimited, Gordon House, Barrow Street, Dublin 4, Ireland
Website: https://www.youtube.com
Privacy Policy: https://policies.google.com/privacy.
Vimeo: Video content
Service provider: Vimeo Inc., 555 West 18th Street, New York, NY 10011, USA
Website: https://vimeo.com
Privacy Policy: https://vimeo.com/privacy.
Google Maps: We embed maps from the "Google Maps" service; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland
Website: https://mapsplatform.google.com/
Privacy Policy: https://policies.google.com/privacy.
Cloudflare: We use Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) on this website to make our website faster and more secure.
Website: https://cloudflare.com/
Privacy Policy: https://www.cloudflare.com/privacypolicy/

21. Management, Organization, and Auxiliary Tools

We use services, platforms, and software from other providers for the purposes of organizing, managing, planning, and delivering our services.Legal Bases: Legitimate Interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures, and services
Microsoft Power Automate: Business Process Automation
Service Provider: Microsoft Ireland Operations Limited, Dublin 18, Ireland
Website: https://powerautomate.microsoft.com
Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement.
n8n: Workflow Automation (self-hosted on Hostinger VPS)
Service Provider: Hostinger (see Hosting)
Website: https://n8n.io
Privacy Policy: Data processing under our own control.
Zapier: Process Automation
Service Provider: Zapier, Inc., 548 Market St, San Francisco, CA 94104, USA
Website: https://zapier.com
Privacy Policy: https://zapier.com/privacy.
Publer: Social Media Management
Service Provider: Publer Ltd, London, UK
Website: https://publer.io
Privacy Policy: https://publer.io/privacy-policy.

22. Payment Service Providers

In the context of contractual and other legal relationships, we offer efficient and secure payment options to data subjects and, for this purpose, use additional payment service providers in addition to banks and credit institutions. Legal bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).

Further information on processing operations, procedures, and services
Stripe: Payment services;
Service provider: Stripe, Inc., San Francisco, CA, USA
Website: https://stripe.com
Privacy Policy: https://stripe.com/de/privacy.
PayPal: Payment ServicesService provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg
Website: https://www.paypal.com
Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
TWINT: Mobile Payment for Switzerland
Service provider: TWINT AG, Zurich, Switzerland
Website: https://www.twint.ch
Privacy Policy: https://www.twint.ch/datenschutz/

23. Artificial Intelligence

AI is our lever for your efficiency. We analyze, structure, and automate your processes. Fast and precise. We work pragmatically, not dogmatically.

Locally operated models ensure your data security. If your task demands raw performance, we connect the most powerful external systems like OpenAI, Google, or Anthropic. But we don't feed a black box.

Before data leaves our infrastructure, we intervene. We filter, shorten, and pseudonymize the content locally. Truly sensitive information remains with us. At the same time, we know: the best models in the world don't run on a local computer. That's why we combine systems. External AI services receive only the exact information they need for their job. Not a single byte more.
Whether it's about your emails, tickets, system data, or contact details – we reduce everything to the absolute minimum.

We exclusively use restrictive APIs. Your data does not train external models. This is not wishful thinking, but strict system configuration.

Finally, the most important principle: The machine computes, we think. We expertly review every draft and analysis. The AI prepares. However, it never makes individual decisions with legal consequences for you. The responsibility always remains with us.

24. Changes and Updates to the Privacy Policy

We kindly ask you to regularly review the content of our Privacy Policy. We will update the Privacy Policy whenever changes to our data processing activities require it. We will inform you as soon as the changes require an action on your part (e.g., consent) or any other individual notification.

Last updated:
16.06.2026