Privacy Policy
The protection of your personal data is very important to us. That is why we process your personal data in accordance with the legal provisions governing data protection.
In our Privacy Policy , we provide information about how we process your personal data, the rights you have under the General Data Protection Regulation (GDPR), and the services used on our website.
In our privacy policy , you will find all relevant information regarding the processing of your personal data when you visit our websites.
If you would like to change your privacy settings, you can adjust your consent here.
Last updated: August 3, 2026
1. Privacy Policy of Westernacher Solutions GmbH
On our website, under the section “ISIDOR – IT Solution for Church Organizations,” we present ISIDOR—the software we developed—along with its features and the underlying processes.
This privacy policy is therefore limited to the ISIDOR product and to the personal data processed when you visit the product website.
For all other data protection-related regulations, please refer to the additional information on our Westernacher Solutions website.
We hereby provide you with information regarding the processing of your personal data by Westernacher Solutions GmbH, as well as your rights under the GDPR in accordance with Article 13 of the GDPR.
1.1 Data Controller
The entity responsible for processing your personal data within the meaning of the GDPR is the
Westernacher Solutions GmbH
Managing Director: Dr. Heiko Pfeffer-Orth
Columbiadamm 37
10965 Berlin, Germany
Phone: +49 30-5858122-5
Email: solutions@westernacher.com
1.2 Data Protection Officer
You can reach our data protection officer at
Krisp Services GmbH & Co. KG
Ms. Heike Kraus
Von-Reichenau-Str. 6a
69231 Rauenberg
Phone: 06222 / 938666
Email: westernacher@krisp.services
1.3 Note on Email Communication and the Secure Exchange of Data
Please be aware that emails sent without end-to-end encryption could be read or altered by unauthorized parties without your knowledge while in transit. We therefore recommend that you do not send us any sensitive information via email in unencrypted form. Emails containing personal data and/or confidential information should be sent using at least transport encryption. If you need further information about encryption options or secure data exchange in general, please contact your direct point of contact. Together, we will find a practical solution to make the exchange of data as secure as possible.
1.4 Personal Data We Process
We process personal data in various contexts.
Customers, suppliers and service providers
Personal data of our customers, suppliers and service providers is processed for order fulfillment, invoicing and subsequent accounting, as well as for administration and communication. This includes in particular:
- Master Data (Last Name, First Name, Address, Contact Information, Payment Information, Customer Status, Partner Status, Customer Number, Partner Number)
- Communication and Order Data (dates and summaries of (customer) conversations, orders placed, order history)
- Data related to order fulfillment (order date, scope of services, cost estimates or invoices, details regarding order fulfillment, deadlines)
Products and Services. In addition, our customers’ personal data may be processed for various purposes in connection with the use of ISIDOR .
1.5 Purposes and Legal Bases for Data Processing
We process your personal data in accordance with the provisions of the GDPR and the Federal Data Protection Act (BDSG), as well as other relevant laws.
The legal basis for the processing of your data is Article 6(1)(b) of the GDPR, to the extent that the processing is necessary for the performance of a contract or a pre-contractual legal relationship.
If special categories of personal data are required for this purpose, we will first request your consent in accordance with Article 9(2)(a) of the GDPR in conjunction with Article 7 of the GDPR.
In addition, we process your data when it is necessary, pursuant to Article 6(1)(f) of the GDPR, to protect our legitimate interests or those of third parties. This may be the case, in particular, when:
- to advertise our own products and other products within the corporate group, as well as for market and opinion surveys
- to ensure the security of our systems
- to prevent and investigate criminal offenses, in particular through data analysis to identify clues that may indicate abuse.
In addition, we process your personal data to the extent necessary to comply with legal obligations, such as regulatory requirements or retention obligations under commercial and tax law. The legal basis for this is the applicable statutory provision in conjunction with Article 6(1)(c) of the GDPR.
To the extent that you have given us your consent—for example, for advertising and marketing purposes—data processing will be carried out exclusively for the purposes specified in your consent. The legal basis for this data processing is Article 6(1)(a) of the GDPR. You may withdraw your consent at any time. The lawfulness of the processing carried out prior to the withdrawal remains unaffected.
If we intend to process your personal data for any other purpose not listed above, we will notify you separately in advance.
1.6 Recipients of Your Data
To the extent necessary for the performance of the contract, we will transfer your data to other service partners, such as locations within the Westernacher Group, for the purposes of project management and sales.
In the context of certain service relationships, your data will be disclosed in particular to payment service providers for the purposes of collecting payments and billing for services used by customers, to tax authorities, banks and tax advisors for the purpose of conducting financial transactions, to credit bureaus to obtain credit information, to debt collection agencies to collect outstanding debts, to attorneys for legal services, to waste management companies for the disposal of physical files and data storage media, and to postal and package delivery service providers for carrying out postal mailings and shipping items (e.g., brochures).
If it is necessary to transfer personal data to recipients in third countries—that is, outside the European Union or the European Economic Area—such transfers will take place exclusively under the conditions set forth in Section 2.6, “International Data Transfers.”
1.7 Duration of Data Retention
We delete your personal data as soon as it is no longer required for the above-mentioned purposes and any existing statutory retention periods have expired.
Record-keeping and retention requirements arise in particular from the German Commercial Code (HGB), the German Fiscal Code (AO), and the Money Laundering Act (GwG). The retention periods specified in these laws are up to ten years.
If claims can be asserted against our company, we will retain the relevant data until the applicable statutory limitation periods have expired. Personal data that is relevant to an ongoing legal dispute will be stored until the dispute is resolved.
1.8 Your Rights
As a data subject, you have various rights under the GDPR, including the right to access, rectification, erasure, restriction of processing, objection, data portability, withdrawal of consent, and the right to lodge a complaint with a supervisory authority.
Details regarding these rights and the respective legal basis can be found in Section [3 Your Rights] of this Privacy Notice.
2. Privacy Notice Regarding the Use of Our Website
We hereby provide you with information regarding the processing of your personal data by Westernacher Solutions GmbH when you visit our website and the rights to which you are entitled under the GDPR (Art. 13 GDPR).
On our website under “ISIDOR – IT Solution for Church Organizations,” we present the ISIDOR software we have developed, its features, and the underlying processes.
2.1 Objectives and Contacts
This Privacy Policy provides information about the nature, scope, and purpose of the processing of personal data when you use our website, its features, and its content. It applies regardless of the domains, systems, platforms, and devices (e.g., desktop or mobile) on which the website is accessed.
The data controller is Westernacher Solutions GmbH (hereinafter referred to as “we” or “us”). For more information about the data controller and the data protection officer, please see Section 1.1, “Data Controller,” and Section 1.2, “Data Protection Officer.”
2.2 Transmission Security
By default, our websites use transport encryption (SSL/TLS) during data transmission to protect the transmitted data from tampering, loss, destruction, or unauthorized access. The security measures we employ are continuously updated in line with technological developments.
You can usually tell if a connection is encrypted by a padlock icon or a corresponding indicator in your browser’s address bar.
2.3 Collection of Usage Data When Visiting This Website
When you visit our websites, certain technical information is automatically processed; this information—which includes your IP address, browser or system settings, and the cookies used—can, at least in theory, be linked to a specific user.
The primary purpose of processing this data is to ensure the website displays correctly, to maintain the stability and security of the system, and to conduct statistical analysis to optimize our websites. However, the data may also be used to display information or entries that the user has already provided after a session has been terminated.
The legal basis for this is our legitimate interest in providing and optimizing our websites (Art. 6(1)(f) of the GDPR).
2.4 Transmission of Browser Data and Settings
The following section describes what usage data is collected on this site and what services are used on this site.
If you use the website solely for informational purposes—that is, if you do not register, order any paid services, or otherwise provide us with information—we collect only the personal data that your browser transmits to our hosting provider. Our websites are hosted by our data processor, Raidboxes (RAIDBOXES GmbH, Hafenstraße 32, 48153 Münster, Germany). Connection data is processed for the purpose of providing and delivering the website. This data is used exclusively for the operation of the site and is not stored beyond the duration of your visit. The legal basis for data processing is legitimate interest (an absolute technical necessity for providing and delivering the “website” service you have expressly requested by visiting the site), Art. 6(1)(f) GDPR.
We record and store log files on the server, particularly when errors occur, such as during logins. IP addresses may be stored for up to 365 days. The legal basis for this processing is Article 6(1)(f) of the GDPR, namely our legitimate interest in analyzing and resolving errors.
As part of the logging process mentioned above and for display purposes, the following data is collected, which is technically necessary to display our website to you and to ensure its stability and security:
- IP address
- Date and time of the request
- Content of the request (specific page)
- Access status / https status code
- Amount of data transferred in each case
- Website from which the request originates (referrer)
- Browser Used
- Operating system
- Language and version of the browser software
- Other technical parameters, e.g.
- JavaScript support
- Number and type of installed plug-ins
- Size of the browser window
- Resolution of the screen
- Supported Languages
- Installed fonts
In order to operate the website, connection data and other personal data are also processed in connection with specific features or services used. We provide detailed information about this in the relevant sections of this Privacy Policy.
2.5 General Information on Data Processing
We process your personal data as a user of our website in compliance with the applicable data protection regulations and the principles of data minimization and data avoidance. This means that we process your data only if there is a legal basis for doing so, if it is required by law, or if you have given us your consent. This applies in particular when the data is necessary for the provision of our contractual services and online services.
We implement state-of-the-art organizational, contractual, and technical security measures to ensure compliance with data protection laws and to protect the data we process against accidental or intentional manipulation, loss, destruction, or unauthorized access.
2.6 International Data Transfers
When using our website and certain integrated services (see Section 5.2.2 “Note on Possible International Data Transfers”), it may be necessary to transfer personal data to recipients in countries outside the European Union or the European Economic Area (so-called third countries).
Any transfer is carried out exclusively in accordance with the requirements of Articles 44 et seq. of the GDPR. This means that either an adequacy decision by the European Commission (Article 45 of the GDPR) is in place, appropriate safeguards have been established through the conclusion of standard contractual clauses (Article 46(2)(c) of the GDPR), or you have expressly consented to the transfer (Article 49(1)(a) of the GDPR).
In July 2023, the European Commission issued an adequacy decision for the United States under the EU-U.S. Data Privacy Framework (DPF). Companies that have joined this framework and obtained certification from the U.S. Department of Commerce ensure an adequate level of data protection. You can find a current list of participants here : Data Privacy Framework.
Please note that transferring data to certain third countries may involve risks, such as government agencies accessing your data without you having adequate legal recourse. As a result, profiles about you may be created without your knowledge and used for further reviews or restrictions.
In some cases, services are provided by a subsidiary based in the EU, while certain processing operations are carried out by a parent company in a third country. In these cases, additional contractual arrangements, such as standard contractual clauses, ensure compliance with an adequate level of protection. The specific security guarantees in place are described for each service we use.
You can obtain further information at any time by using the contact information provided for our data protection officer.
3. Your Rights
As a data subject, you have the following rights under the GDPR:
3.1 Information
You may at any time contact Westernacher Solutions GmbH or the Data Protection Officer using the contact information provided above to request information regarding whether we process personal data about you and, if so, what data we process (Art. 15 GDPR). This includes, in particular, information regarding the purposes of processing, the categories of data processed, the recipients to whom data is disclosed, and the planned retention period.
3.2 Correction, Restriction, and Deletion
You have the right to have inaccurate personal data corrected without delay (Art. 16 of the GDPR).
Subject to the legal requirements, you may also request the restriction of processing (Art. 18 of the GDPR) or the erasure of your personal data (Art. 17 of the GDPR).
3.3 Objection
You may object at any time, without having to provide a specific reason, to the processing of your data for the purposes of direct marketing, market research, or the customized design of telemedia (Art. 21 GDPR).
This also applies to the processing of your data based on a legitimate interest (Art. 6(1)(f) of the GDPR), provided that there are grounds arising from your particular situation (Art. 21(1) of the GDPR).
You may also object to the use of web analytics tools, tracking services, retargeting services, and, in general, the collection of your usage data. To do so, you can use the links and settings options provided in this Privacy Policy for the respective services.
3.4 Withdrawal of Consent
You may withdraw any consent you have given at any time, effective for the future (Art. 7(3) of the GDPR).
This applies in particular to consents you have provided on this website, for example:
- Contact Form: You may informally revoke the storage of your data when using the contact form by contacting us using the contact information provided above. In this case, we will no longer process your data, unless there are compelling legitimate grounds for continued storage or the processing is necessary to assert, exercise, or defend legal claims.
The lawfulness of the processing carried out on the basis of consent until such consent is revoked remains unaffected by this.
3.5 Data Portability
Upon request, we will provide you with the data we have stored about you in a structured, commonly used, and machine-readable format that you can use for further processing (Art. 20 GDPR).
Please direct any inquiries regarding this matter to the Data Protection Officer’s email address (westernacher@krisp.services) or to datenschutz@westernacher.com.
Any transmission requires your unambiguous authentication as the data subject or can only be sent to an address already on file in your records.
3.6 Right to File a Complaint
You also have the right at any time to file a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR).
3.7 Exercising Your Rights
To exercise your rights or for any other questions or complaints regarding data protection, you may contact our Data Protection Officer at any time using the contact information provided.
4. Local Services
4.1 Contact Form
On our website, you can contact us directly using a contact form. All required fields are marked accordingly (*). Data is transmitted via a secure SSL/TLS connection. We then process the personal data you provide solely for the purpose of handling your inquiry. The legal basis for this is the consent you provided before submitting the form, in accordance with Article 6(1)(a) of the GDPR.
To secure our contact form, we use the Turnstile feature provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Turnstile is used to detect and prevent automated submissions, thereby ensuring the security and functionality of the contact form. In doing so, technical information is processed, including, in particular, the time of the request, the IP address in truncated form, and details about the browser and system environment used. This data is processed exclusively for the purpose of spam prevention. No user profiles are created, nor is the data used for analytical or advertising purposes.
Data processing related to turnstiles is based on our legitimate interest under Article 6(1)(f) of the GDPR to protect our systems from misuse and to ensure the security of our website.
The recipient of the data is Cloudflare, Inc. It cannot be ruled out that personal data may be transferred to servers in third countries, particularly the United States. Cloudflare bases such data transfers on appropriate safeguards in accordance with Article 46 of the GDPR, in particular on standard contractual clauses approved by the European Commission. For further information on international data transfers and the associated risks, please refer to Section 2.6, “International Data Transfers.”
The information you provide will be forwarded to the department you selected and will be used solely to process your request.
For audit purposes and for customer service, the data is stored as a transaction and retained for three months after the transaction is completed, after which it is deleted. You may revoke your consent to the processing of your personal data at any time by contacting the Data Protection Officer using the contact information provided. The lawfulness of the processing carried out on the basis of your consent up until its revocation remains unaffected.
If your contact with us results in a contractual relationship or if your inquiry is intended to lead to the conclusion of a contract, we will also process your data pursuant to Article 6(1)(b) of the GDPR for the purpose of taking steps prior to entering into a contract or for the performance of the contract.
4.2 Friendly Captcha
To prevent spam messages and bot activity, we use the Friendly Captcha service in connection with our contact form.
A JavaScript element is integrated into the source code of our website, which loads the software in the background. For this service, your end device calculates the solution to a crypto puzzle in order to be able to understand whether the user or visitor to our website is a human being or whether the use is made by automated, machine processing (e.g. bots).
The service helps us prevent automated attacks that could pose risks to our infrastructure. In this way, it helps us prevent fraudulent activities.
By using the service, the following data is processed:
- Browser, operating system, referrer (previous websites)
- Date and time of the request
- Version of the Friendly Captcha service used
- Hash value (one-way encryption) of the incoming IP address (the IP address is discarded, only the hash value is saved)
- Number of requests from the (hashed) IP address per time period
- Answer to the math problem solved by the visitor’s computer
No cookies are used.
The legal basis for this processing is our legitimate interest under Article 6(1)(f) of the GDPR, namely to protect our systems against misuse and to ensure the availability of our website.
The service is provided by Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee.
For more information about data protection at Friendly Captcha, please visit: https://friendlycaptcha.com/de/legal/privacy-end-users/.
5. External Services and Technical Tools
5.1 Cookies
5.1.1 General Functioning of
Cookies are small text files that are stored by your browser and thus saved on your device. They contain various pieces of information, such as the duration of your visit to the website or user input, and in some cases may also include identification codes for recognition purposes. They may originate from us as the website provider (so-called first-party cookies) or, in the case of collaboration with third parties, from those third parties (so-called third-party cookies). The storage duration may vary (e.g., for the duration of your visit to the site, up to several weeks or years).
You can configure your browser to notify you when cookies are sent. You can also delete cookies from your computer’s hard drive at any time. You can also prevent your browser from storing cookies. However, if you do so, you will no longer be able to use the website’s full functionality.
5.1.2 First-Party Cookies
Our website uses first-party cookies, known as “session cookies.” They are used to store data relevant to your visit to the website or to recognize your computer during your visit (e.g., to make entering your password easier). These cookies are technically necessary, ensure the full functionality of the website, and therefore do not require consent. The legal basis for their storage is Section 25(2)(2) of the Telecommunications, Digital Services, and Data Protection Act (TDDDG). The legal basis for the subsequent processing of the data is Article 6(1)(f) of the GDPR (legitimate interest).
5.1.3 Third-Party Cookies
When we collaborate with third parties, you will be informed individually and separately about the use of such cookies and the scope of the information collected in each case in the paragraphs below regarding the respective third-party service providers. The legal basis for storing these cookies is your consent, Section 25(1) of the Austrian Telemedia Act (TDDDG). The legal basis for the subsequent processing of the data is your consent, Article 6(1)(a) of the General Data Protection Regulation (GDPR).
5.1.4 Use of the Borlabs Cookie Consent Tool
This website uses the “Borlabs Cookie” tool to obtain the consent required for the use of certain cookies or similar technologies (e.g., pixels). When you first start using the website, a banner with relevant information appears. There, you can consent to the use of all cookies, customize your settings by category, or decline to give consent. In this case, only technically necessary cookies that do not require consent (first-party cookies) will be set.
The selected setting is stored on your computer for one year via a cookie from the provider Borlabs GmbH, Managing Director: Benjamin A. Bornschein, Hamburger Str. 11, 22083 Hamburg, provided that you do not clear the cache of the browser you are using. This cookie is necessary for the operation of the website and does not require your consent.
The legal basis for storage is Section 25(2)(2) of the TDDDG. The legal basis for processing is Article 6(1)(f) of the GDPR (legitimate interest) to operate the website in compliance with the law and to automatically apply selected settings during subsequent visits to the website.
Further information on the use of the data transmitted during use is available at https://de.borlabs.io/datenschutz/. In addition to this consent specific to our website, many service providers offer their own links for cross-website privacy objections, which we mention in our privacy policy for the sake of completeness. Consent given on our site via the Borlabs tool does not revoke any such objections—whether already made or to be made in the future—against individual providers.
To the extent that the use of individual services involves the transfer of data to third countries, your consent is generally required for this, pursuant to Article 49(1)(a) of the GDPR. The risks associated with such transfers are described in Section 2.6, “International Data Transfers.”
You can adjust and/or revoke your existing cookie settings at any time here.
5.2 General Provisions for Third-Party Services
5.2.1 Allocation of Responsibility for Third-Party Services
All third-party services involve the transfer of personal data to the respective provider and, where applicable, processing by that provider. Therefore, we must clarify how responsibility for processing is allocated between us, as the website operator, and the service providers. This applies to the services and technical tools described below.
We enter into the necessary contractual agreements with third-party service providers for this purpose. If services are operated under joint responsibility in accordance with Article 26 of the GDPR, both we and the relevant service provider are jointly responsible for the purposes and means of data processing.
In these cases, the contract specifies which processing activities are to be carried out and by whom. The service provider (joint controller) is generally responsible for the personalized analysis of usage data, as well as for identifying and justifying the legal basis for its own processing activities. As a joint controller, we are specifically responsible for setting the respective cookies and for transmitting usage data from our website.
However, you can assert your data subject rights against both jointly responsible parties irrespective of this allocation.
In many cases, service providers offer only limited or outdated contracts that do not fully meet the current requirements of data protection supervisory authorities. Nevertheless, such contracts are regularly entered into automatically when the service is used. It is reasonable to assume that providers will adapt their terms and conditions in the future. Regardless, we base the current data transfers entirely on the consents obtained via the privacy settings banner (see Section 5.1.4 above, “Use of the Borlabs Tool for Cookie Consent”).
5.2.2 Notice Regarding Potential International Data Transfers
Some of the service providers listed in Section 5.3, “Specific Services,” are based outside the European Union or the European Economic Area, or process data on servers located in such countries. In such cases, personal data—such as IP addresses or usage data—may be transferred to a third country.
The applicable principles, as well as information on security measures and potential risks, are described in Section 2.6, “International Data Transfers.”
5.3 Individual Services
Below, we provide information about the various services used on our website. Some of these are social media services or other third-party providers. While social media services may appear to non-members as conventional marketing services, they differ in that data collected through this website can be linked to a member’s existing account.
In general, a distinction must be made between different services and functions:
On the one hand, service providers offer the option to display personalized ads on their platforms or to show ads on linked sites based on their users’ profiles. In addition, they can be used via social media providers through social plugins (e.g., “Like” or “Share” buttons) to enable users to share and promote page content. In addition to this website, we may also maintain our own pages on social media platforms to showcase our company.
We have entered into the necessary data protection agreements with the respective service providers. For information on the purpose and scope of data collection, the further processing and use of data by the social networks, as well as your rights in this regard and the settings available to protect your privacy, please refer to the privacy policies of the respective social networks, which are described in detail below.
First, we provide links to the relevant pages on our website. In addition, we offer the option to share our content on the aforementioned social media platforms via share buttons in certain areas. These are links to websites that do not require consent under Article 6(1)(a) of the GDPR. We use these linking options to improve the company’s reach and visibility, relying on our legitimate interest under Article 6(1)(f) of the GDPR.
5.3.1 Google Ads
We use Google Ads on our website, an online advertising service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads allows us to display ads on the Google search engine as well as on third-party websites. Ads can be displayed based on specific search terms (known as keyword targeting) or based on general audience characteristics. As the operator of this website, we receive only aggregated and statistical reports that allow us to determine how successful individual advertising campaigns are (e.g., the number of clicks on an ad). We are unable to directly identify individual users through this process.
In addition, we use the Google Dynamic Remarketing feature within Google Ads . This feature may use cookies and similar technologies that enable the device to be recognized in order to display personalized ads to interested users based on their previous activity on our website (e.g., products or services they have viewed).
In all cases, the processing of personal data is carried out exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. To the extent that information is stored on or retrieved from your device in connection with Google Ads, this is also done on the basis of your consent in accordance with Section 25(1) of the TDDDG.
The recipient of the data is Google Ireland Limited. It cannot be ruled out that personal data may be transferred to servers operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. Google is certified under the EU-U.S. Data Privacy Framework, which ensures an adequate level of data protection in accordance with Article 45 of the GDPR. In addition, Google bases data transfers—where necessary—on further appropriate safeguards in accordance with Article 44 et seq. of the GDPR.
You can revoke your consent at any time, effective for the future, through the settings of the consent manager used on this website.
For more information on international data transfers and the associated risks, see Section 2.6, “International Data Transfers.”
For more information about data processing by Google Ads and Google Dynamic Remarketing, please see Google’s Privacy Policy at: https://ads.google.com/intl/de_DE/home/privacy/
5.3.1 etracker
We use services provided by etracker GmbH, based in Hamburg, Germany, to analyze usage data. By default, we do not use cookies for web analytics. etracker operates without cookies in its default configuration. To the extent that we use analytics and optimization cookies, we will obtain your explicit consent separately in advance (Section 25(1) TDDDG; Article 6(1)(a) GDPR). If this is the case and you consent, cookies will be used to enable statistical reach analysis of this website, performance measurement of our online marketing activities, and testing procedures—for example, to test and optimize different versions of our online offering or its components. In the rare instances where cookies are used, etracker cookies do not contain any information that would allow a user to be identified.
The data generated by etracker is processed and stored exclusively in Germany by etracker on our behalf and is therefore subject to strict German and European data protection laws and standards. etracker has been independently audited and certified in this regard and has been awarded the Data Protection Seal of Approval Awarded the ePrivacyseal.
Data is not transferred to third countries. Should this change in the future, the information in Section 2.6, “International Data Transfers,” will apply.
Data processing is carried out in accordance with the legal provisions of Article 6(1)(f) (legitimate interest) of the General Data Protection Regulation (GDPR). Our legitimate interest under the GDPR is to optimize our online services and our website. Since the privacy of our visitors is important to us, any data that could potentially be linked to an individual—such as IP addresses, login IDs, or device identifiers—is anonymized or pseudonymized as soon as possible. This data is not used for any other purpose, combined with other data, or disclosed to third parties.
You may object to this data processing or opt out at any time.
If we use the opt-out slider provided by etracker, you can also opt out directly there.
Objecting will not result in any adverse consequences. If no opt-out option appears on your ad, data collection has already been prevented by other blocking measures (e.g., browser settings, add-ons).
You can find more information about etracker’s privacy policy here.
5.3.3 Content Delivery Networks (CDN): Reducing loading times
Our website uses Content Delivery Networks (CDN) to reduce the loading times of common JavaScript libraries and fonts.
When you visit our website, your IP address, among other things, is transmitted to the servers of the respective CDN providers. These providers operate servers in the EU. However, it cannot be ruled out that your browser may also access servers outside the EU.
In these cases, data may be transferred internationally. For more information on international data transfers and the associated risks, see Section 2.6, “International Data Transfers.”
We use a CDN to ensure a consistent and appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR.
To prevent JavaScript from running altogether, you can install a JavaScript blocker in your browser.
Cloudflare
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (represented in Germany by Cloudflare Germany GmbH, Rosental 7, 80331 Munich).
Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF).
For information on data protection, see Cloudflare’s Privacy Policy | Cloudflare.
5.3.4 Vimeo
Vimeo is used on the website in the form of videos that provide users with information or additional content.
Vimeo, Inc., 330 West 34th Street, 5th Floor, New York 10001, USA, legal@vimeo.com is a video portal that allows users to use the site for free and also offers the option to publish content for a fee. Among other features, the platform also allows users to create personal streams where they can collect videos from other user profiles and rate them with comments.
Using a plug-in, we can display interesting video content from Vimeo directly on our website. In doing so, certain data about you is transmitted to Vimeo. When you visit another webpage on our site that has an embedded Vimeo video, your browser connects to Vimeo’s servers. The data transmitted in this process is stored on these servers. The following data is processed: your IP address, technical information about your browser type and operating system, basic device information, the referring website, and your activities on our website (e.g., session duration).
If you are logged in as a registered member of Vimeo, more data will generally be collected, as more cookies may already be set in your browser. In addition, your activities on our website will be directly linked to your Vimeo account. To prevent this, you must log out of Vimeo before visiting our website.
To the extent that cookies or similar technologies are used to integrate Vimeo, this is done only with your express consent (Section 25(1) of the TDDDG in conjunction with Article 6(1)(a) of the GDPR). You can adjust your consent at any time via the Consent Manager.
The use of Vimeo may involve the transfer of personal data to the United States. Vimeo participates in the EU-U.S. Data Privacy Framework; see https://www.dataprivacyframework.gov/list and https://vimeo.com/legal/privacy/policy#id-13.-location-of-data-and-data-processing
For more information on international data transfers and the associated risks, please see Section 2.6, “International Data Transfers.”
You also have the option to manage cookies in your browser according to your preferences. For example, if you do not want Vimeo to set cookies and collect information about you, you can delete or disable cookies in your browser settings at any time. If you are a registered Vimeo member, you can also manage the cookies used in your Vimeo settings.
The legal basis for the use of Vimeo is, in principle, your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. To the extent that consent is not required for the integration of Vimeo, processing is based on our legitimate interest in presenting content in an attractive manner (Article 6(1)(f) of the GDPR).
For more information on data protection, visit https://vimeo.com/privacy; for information on the use of cookies, visit https://vimeo.com/cookie_policy.
5.3.5 LinkedIn
The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. LinkedIn is a global networking platform for professionals and executives. Registered users can interact with one another to enhance business and career opportunities. On our website, you have the option to be redirected directly to our LinkedIn profile.
When you visit our LinkedIn profile, you are navigating the LinkedIn platform. The analytics data from the site provider is made available to us only in anonymized form (statistical values). The joint responsibility described above under Article 26 of the GDPR applies to the data processing required for this purpose.
Our legal basis for data processing here is the legitimate interest in counting the users of our LinkedIn profile, Art. 6 para. 1 lit. f GDPR. This relates to our interest in measuring and evaluating page effectiveness.
Through pixels and the link to our LinkedIn profile, LinkedIn collects data about the use of our site (browser and device settings, usage times and content, existing identifiers). The purpose is to display personalized advertisements on the LinkedIn platform. The legal basis for this data transfer from our website is the consent you provided when you first used the site, pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.
When using LinkedIn, personal data may be transferred to the United States to the parent company, LinkedIn Corporation, 1000 W Maude Ave, Sunnyvale, California 94085-2810.
To use the European Commission’s standard contractual clauses for LinkedIn: https://www.linkedin.com/help/linkedin/answer/a1343190?lang=de.
LinkedIn is certified under the EU-U.S. Data Privacy Framework: https://www.dataprivacyframework.gov/s/participant-search.
For more information on international data transfers and the associated risks, please see Section 2.6, “International Data Transfers.”
For more information, please see the Privacy Policy at: https://de.linkedin.com/legal/l/dpa? (If necessary, you may need to select your preferred language setting in the footer at the bottom of the LinkedIn page.) The joint controller agreement and the respective responsibilities can be found at: https://legal.linkedin.com/pages-joint-controller-addendum.
5.3.6 XING
We maintain a profile on XING, a social network operated by New Work SE, Baumwall 7, 20459 Hamburg, Germany. XING allows users to create personal profiles as well as company pages where information about our company—such as service descriptions, contact details, or photos—is provided. Users can view this information, create their own posts, and share content. Users are solely responsible for their use of these features.
When you visit our XING profile, you are navigating directly on the XING platform. The analytics data provided by XING is made available to us only in anonymized form as statistical values. We are unable to directly identify individual users.
With regard to data processing in connection with our profile, there is joint responsibility under Article 26 of the GDPR between us, as the website operator, and XING. XING is responsible for the collection, storage, and use of personal data within the platform. We are responsible for the content of our profile as well as for the transfer of data to XING, to the extent necessary.
The processing of personal data is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest lies in measuring and evaluating the reach and effectiveness of our profile.
The recipient of the data is New Work SE. To the extent that personal data is transferred to countries outside the European Union or the European Economic Area, XING relies on the adequacy decisions of the European Commission pursuant to Article 45 of the GDPR or on appropriate safeguards pursuant to Article 46 of the GDPR. For further information on this topic, please refer to Section 2.6, “International Data Transfers,” of this Privacy Policy.
For more information about XING’s processing of personal data and how to manage your privacy settings, please see XING’s Privacy Policy: https://privacy.xing.com/de/datenschutzerklaerung
The agreement on joint liability and the respective responsibilities can be viewed in XING’s Terms of Use: https://www.xing.com/terms/onlyfy-one
5.3.7 YouTube
Videos from YouTube are embedded on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit a page with an embedded YouTube video, a connection is established with Google’s servers. In the process, data such as your IP address, information about the page you visited, the date and time of access, and device and browser information are transmitted to Google. In addition, cookies may be set or similar technologies used that enable recognition.
If you are logged into your Google or YouTube account at the same time, Google can directly associate your visit to our website with your personal profile. You can prevent this by logging out of your account first.
The legal basis for embedding YouTube is your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. To the extent that consent is not required for the purely technical integration, we rely on our legitimate interest in presenting our online offerings in an appealing manner (Article 6(1)(f) of the GDPR).
Personal data may be transferred to the United States, to Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043. Google LLC is certified under the EU-U.S. Data Privacy Framework, which ensures an adequate level of data protection.
For information on using the European Commission’s standard contractual clauses in the event of a potential transfer to a third country, see: https://policies.google.com/privacy/frameworks?hl=de.
For more information on international data transfers and the associated risks, please see Section 2.6, “International Data Transfers.”
Additional information about Google’s privacy policy:
https://policies.google.com/privacy?hl=de&gl=de (Google Privacy Policy)
6. Additional Information
Changes to security and data protection measures may result in an adjustment to this data protection notice. Please refer to the latest version on our website.
If you have any general questions, please feel free to contact us (solutions@westernacher.com). For questions regarding data protection, please contact us at datenschutz@westernacher.com or reach out to our Data Protection Officer at westernacher@krisp.services.
To improve readability, we have chosen not to use the gender-specific terms “male,” “female,” and “diverse” (m/f/d) simultaneously. All references to people in this document apply equally to all genders.

