Angelschein Spanien
Privacy policy
Introduction
This privacy policy explains which types of your personal data (also referred to below as “data”) we process, for what purposes and to what extent. It applies to all processing of personal data carried out by us, both in providing our services and particularly on our websites, in mobile applications and within external online presences such as our social-media profiles (collectively referred to below as our “online services”).
The terms used are not gender-specific.
Date of the imported general information: 5 December 2025. Cookie and visitor-statistics sections updated on 6 September 2026.
Contents
- Introduction
- Controller
- Overview of processing
- Applicable legal bases
- Security measures
- Transfer of personal data
- General information on data retention and deletion
- Rights of data subjects
- Business services
- Payment procedures
- Provision of online services and web hosting
- Registration, sign-in and user accounts
- Contact and enquiry management
- Communication via messengers
- Newsletters and electronic notifications
- Changes and updates
- Definitions
Controller
Angelschein-Spanien.de
Jörg Horstmann
Avenida de Miramar 106
07639 Sa Rapita
Spain
Legal notice: www.angelschein-spanien.de/impressum
Overview of processing
The following overview summarises the types of data processed, the purposes of processing and the people concerned.
Types of data processed
- Master data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Metadata, communication and procedural data.
- Log data.
Categories of data subjects
- Service recipients and clients.
- Prospective customers.
- Communication partners.
- Users.
- Business and contractual partners.
Purposes of processing
- Providing contractual services and fulfilling contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Office and organisational procedures.
- Organisational and administrative procedures.
- Feedback.
- Marketing.
- Providing our online services and making them user-friendly.
- Information-technology infrastructure.
- Business processes and commercial procedures.
Applicable legal bases
Applicable legal bases under the GDPR: Below is an overview of the GDPR legal bases on which we process personal data. Please note that national data-protection requirements in your or our country of residence or establishment may apply alongside the GDPR. Where more specific legal bases apply in individual cases, we identify them in this privacy policy.
- Consent (Article 6(1), first sentence, point (a) GDPR) — The data subject has consented to processing their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) GDPR) — Processing is necessary to perform a contract to which the data subject is a party or to take steps at the data subject’s request before entering into a contract.
- Legal obligation (Article 6(1), first sentence, point (c) GDPR) — Processing is necessary to comply with a legal obligation to which the controller is subject.
- Legitimate interests (Article 6(1), first sentence, point (f) GDPR) — Processing is necessary for the legitimate interests of the controller or a third party, provided these are not overridden by the interests or fundamental rights and freedoms of the data subject requiring protection of personal data.
National data-protection provisions in Germany: In addition to the GDPR, national data-protection provisions apply in Germany, particularly the German Federal Data Protection Act (Bundesdatenschutzgesetz — BDSG), which protects against misuse of personal data during processing. The BDSG contains specific provisions concerning the rights of access, erasure and objection, processing of special categories of personal data, processing for other purposes, transfers, and automated individual decision-making including profiling. The data-protection laws of individual German federal states may also apply.
Security measures
In accordance with legal requirements, taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include protecting the confidentiality, integrity and availability of data by controlling physical and electronic access, access rights, input, disclosure, availability and separation of data. We have also established procedures to enable the exercise of data-subject rights, deletion of data and responses to threats to data. We consider personal-data protection when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and by default.
IP-address truncation: where we, our service providers or technologies process IP addresses and processing the full IP address is unnecessary, the address is shortened (“IP masking”). The last two digits, or the final part of the IP address after a dot, are removed or replaced by placeholders. Truncation is intended to prevent or substantially hinder identification of a person through their IP address.
Securing online connections using TLS/SSL encryption technology (HTTPS): we use TLS/SSL encryption to protect user data transmitted through our online services from unauthorised access. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are foundations of secure internet transmission. They encrypt information exchanged between a website or app and a user’s browser, or between two servers, protecting it from unauthorised access. TLS, the more advanced and secure successor to SSL, ensures that all data transfers meet the highest security standards. A website secured with an SSL/TLS certificate displays HTTPS in its URL, indicating that users’ data is transmitted securely and in encrypted form.
Transfer of personal data
When processing personal data, we may transfer or disclose it to other bodies, companies, legally independent organisational units or individuals. Recipients may include providers commissioned to perform IT tasks or providers of services and content embedded in a website. We comply with legal requirements in such cases and, in particular, enter into appropriate contracts or agreements with recipients to protect your data.
General information on data retention and deletion
We delete personal data we process in accordance with statutory requirements when the underlying consent is withdrawn or no other legal basis for processing remains. This includes cases where the original purpose ceases to apply or the data is no longer required. Exceptions apply where statutory duties or particular interests require longer retention or archiving.
In particular, data that must be retained for commercial or tax-law reasons, or whose storage is necessary to pursue legal claims or protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional retention and deletion information for particular processing operations.
If several retention periods or deletion deadlines apply to an item of data, the longest period is decisive. Where data is retained because of statutory requirements or other reasons rather than for its original purpose, we process it exclusively for the reasons justifying retention.
Data retention and deletion: the following general retention and archiving periods apply under German law:
- 10 years — Books and records, annual financial statements, inventories, management reports, opening balance sheets, and the working instructions and other organisational documents necessary to understand them (section 147(1) no. 1 in conjunction with (3) AO, section 14b(1) UStG, section 257(1) no. 1 in conjunction with (4) HGB).
- 8 years — Accounting vouchers, such as invoices and expense receipts (section 147(1) nos. 4 and 4a in conjunction with (3), first sentence, AO, and section 257(1) no. 4 in conjunction with (4) HGB).
- 6 years — Other business documents: received commercial or business correspondence, copies of sent commercial or business correspondence, and other documents relevant to taxation, such as hourly wage records, cost-allocation sheets, calculation documents and price labels, as well as payroll documents that are not already accounting vouchers, and cash-register strips (section 147(1) nos. 2, 3 and 5 in conjunction with (3) AO; section 257(1) nos. 2 and 3 in conjunction with (4) HGB).
- 3 years — Data necessary to consider potential warranty claims, damages claims or similar contractual claims and rights, and to handle related enquiries, based on previous business experience and customary industry practice, is stored for the ordinary statutory limitation period of three years (sections 195 and 199 BGB).
Periods beginning at the end of the year: if a period does not expressly begin on a particular date and is at least one year long, it automatically starts at the end of the calendar year in which the triggering event occurred. For ongoing contractual relationships involving stored data, the triggering event is the date on which notice of termination takes effect or the legal relationship otherwise ends.
Rights of data subjects
Data-subject rights under the GDPR: you have various rights, particularly those arising from Articles 15–21 GDPR:
- Right to object: you have the right, on grounds relating to your particular situation, to object at any time to processing of your personal data based on Article 6(1)(e) or (f) GDPR, including profiling based on those provisions. Where personal data is processed for direct marketing, you have the right to object at any time to processing for that purpose, including profiling insofar as it relates to direct marketing.
- Right to withdraw consent: you may withdraw consent at any time.
- Right of access: you may request confirmation of whether relevant data is processed, access to it, further information and a copy in accordance with statutory requirements.
- Right to rectification: in accordance with statutory requirements, you may request completion of your data or correction of inaccurate data.
- Right to erasure and restriction of processing: subject to statutory requirements, you may request deletion of your data without delay or, alternatively, restriction of its processing.
- Right to data portability: in accordance with statutory requirements, you may receive data concerning you that you supplied to us in a structured, commonly used, machine-readable format, or request its transmission to another controller.
- Complaint to a supervisory authority: without prejudice to another administrative or judicial remedy, you may complain to a supervisory authority, particularly in the Member State of your habitual residence, place of work or the alleged infringement, if you consider that processing of your personal data infringes the GDPR.
Business services
We process data of our contractual and business partners, such as customers and prospective customers (collectively “contractual partners”), within contractual and comparable legal relationships, associated measures and communication with contractual partners or pre-contractual communication, for example to answer enquiries.
We use this data to fulfil our contractual obligations, particularly providing agreed services, meeting any update obligations and remedying warranty issues or other performance problems. We also use data to protect our rights and carry out administrative tasks and business organisation associated with those obligations. Furthermore, we process data on the basis of our legitimate interests in sound commercial management and security measures protecting our contractual partners and business operations against misuse and threats to their data, secrets, information and rights. This may involve telecommunications, transport and other support providers, subcontractors, banks, tax and legal advisers, payment providers or tax authorities. Within applicable law, we disclose contractual partners’ data to third parties only where necessary for those purposes or statutory obligations. This privacy policy informs contractual partners about other processing, such as for marketing.
We explain which data is necessary before or during collection, for example in online forms through special markings such as colours or symbols such as asterisks, or personally.
We delete data after statutory warranty and comparable obligations expire, generally after four years, unless it is stored in a customer account, for example for as long as statutory archiving requirements apply (usually ten years for tax purposes). We delete data disclosed by a contractual partner during an assignment according to applicable requirements and generally after the assignment ends.
- Types of data processed: master data (for example full name, residential address, contact information and customer number); payment data (for example bank details, invoices and payment history); contact data (postal and email addresses or telephone numbers); contract data (subject matter, term and customer category); usage data (page views and time spent, click paths, intensity and frequency of use, device types and operating systems, interactions with content and functions); metadata, communication and procedural data (IP addresses, times, identification numbers and people involved).
- Data subjects: service recipients and clients; prospective customers; business and contractual partners.
- Purposes of processing: providing contractual services and fulfilling obligations; security measures; communication; office and organisational procedures; organisational and administrative procedures; business processes and commercial procedures.
- Retention and deletion: deletion according to “General information on data retention and deletion”.
- Legal bases: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legal obligation (Article 6(1)(c) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Online shop, order forms, e-commerce and fulfilment: we process customer data to enable selection, purchase or ordering of products, goods and associated services, as well as payment, provision, delivery or performance. Where needed to fulfil an order, we use service providers, particularly postal, freight and shipping companies, to deliver or perform for our customers. We use banks and payment providers to process payments. Required information is marked during ordering or comparable purchasing processes and includes information needed for delivery, provision and billing, plus contact details for any follow-up questions. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
Payment procedures
Within contractual and other legal relationships, to meet statutory obligations or on the basis of our legitimate interests, we offer efficient and secure payment methods. In addition to banks and credit institutions, we use other providers (collectively “payment providers”). Payments use encrypted connections in accordance with the state of the art, protecting entered data against unauthorised access during transmission.
Payment providers process master data such as name and address; banking data such as account or card numbers; passwords, transaction authentication numbers and checksums; and contract, amount and recipient information. This information is required to carry out transactions. However, entered data is processed and stored only by the payment providers. We do not receive account or card information, only confirmation that payment succeeded or failed. Payment providers may transmit data to credit-reference agencies for identity and creditworthiness checks. Please refer to their terms and privacy notices.
Payment transactions are governed by the terms and privacy notices of the relevant payment providers, available on their websites or transaction applications. Please also consult them for further information and to exercise withdrawal, access and other data-subject rights.
- Types of data processed: master data (full name, residential address, contact information and customer number); payment data (bank details, invoices and payment history); contract data (subject matter, term and customer category); usage data (page views and time spent, click paths, intensity and frequency of use, device types and operating systems, interactions with content and functions); metadata, communication and procedural data (IP addresses, times, identification numbers and people involved); contact data (postal and email addresses or telephone numbers).
- Data subjects: service recipients and clients; business and contractual partners; prospective customers.
- Purposes of processing: providing contractual services and fulfilling contractual obligations; business processes and commercial procedures.
- Retention and deletion: deletion according to “General information on data retention and deletion”.
- Legal bases: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Apple Pay: payment services (technical integration of online payment methods). Provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR). Website: https://www.apple.com/de/apple-pay/. Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
- Google Pay: payment services (technical integration of online payment methods). Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR). Website: https://pay.google.com/intl/de_de/about/. Privacy policy: https://policies.google.com/privacy.
- PayPal: payment services (technical integration of online payment methods), for example PayPal, PayPal Plus and Braintree. Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR). Website: https://www.paypal.com/de. Privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full.
- Stripe: payment services (technical integration of online payment methods). Provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR). Website: https://stripe.com. Privacy policy: https://stripe.com/de/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
Provision of online services and web hosting
We process users’ data to provide our online services. For this purpose, we process users’ IP addresses, which are required to transmit content and functions to their browsers or devices.
- Types of data processed: usage data (page views and time spent, click paths, intensity and frequency of use, device types and operating systems, interactions with content and functions); metadata, communication and procedural data (IP addresses, times, identification numbers and people involved); log data (for example logs of sign-ins, data retrieval or access times); content data (text or image messages and posts, plus related information such as authorship or creation time).
- Data subjects: users, such as website visitors and online-service users.
- Purposes of processing: providing our online services and making them user-friendly; information-technology infrastructure (operating and providing information systems and technical equipment such as computers and servers); security measures.
- Retention and deletion: deletion according to “General information on data retention and deletion”.
- Legal basis: legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Providing online services on rented storage: to provide our online services, we use storage, computing capacity and software rented or otherwise obtained from an appropriate server provider, also known as a web host. Legal basis: legitimate interests (Article 6(1)(f) GDPR).
- Collection of access data and log files: access to our online services is recorded in server log files. These may include the addresses and names of pages and files retrieved, retrieval date and time, transferred data volumes, successful-retrieval messages, browser type and version, operating system, referrer URL (previous page), and generally IP addresses and the requesting provider. Logs may be used for security, for example to prevent server overload, particularly during abusive attacks known as DDoS attacks, and to ensure server capacity and stability. Legal basis: legitimate interests (Article 6(1)(f) GDPR). Deletion: log-file information is retained for a maximum of 30 days and then deleted or anonymised. Data requiring further retention as evidence is exempt from deletion until the relevant incident is finally resolved.
- Email sending and hosting: the web-hosting services we use also include sending, receiving and storing emails. Recipient and sender addresses, further transmission information such as providers involved, and email contents are processed for these purposes. This data may also be processed to detect spam. Please note that email on the internet is generally not sent with end-to-end encryption. Although usually encrypted during transport, it is not encrypted on sending and receiving servers unless an end-to-end encryption method is used. We therefore cannot assume responsibility for the email transmission path between the sender and receipt on our server. Legal basis: legitimate interests (Article 6(1)(f) GDPR).
- Hetzner: information-technology infrastructure and related services, for example storage or computing capacity. Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Legal basis: legitimate interests (Article 6(1)(f) GDPR). Website: https://www.hetzner.com. Privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz. Data-processing agreement: https://docs.hetzner.com/de/general/general-terms-and-conditions/data-privacy-faq/.
Registration, sign-in and user accounts
Users can create an account. During registration, required information is identified and processed to provide the account on the basis of contractual performance. Data processed particularly includes login information: username, password and email address.
When users use registration, sign-in functions or their account, we store their IP address and the time of the relevant action. Storage is based on our legitimate interests and users’ interests in protection against misuse and other unauthorised use. This data is generally not disclosed to third parties unless necessary to pursue our claims or required by law.
Users may be informed by email about events relevant to their account, such as technical changes.
- Types of data processed: master data (full name, residential address, contact information and customer number); contact data (postal and email addresses or telephone numbers); content data (text or image messages and posts and related information, such as authorship or creation time); usage data (page views and time spent, click paths, intensity and frequency of use, device types and operating systems, interactions with content and functions); log data (sign-ins, data retrieval or access times).
- Data subjects: users, such as website visitors and online-service users.
- Purposes of processing: providing contractual services and fulfilling contractual obligations; security measures; organisational and administrative procedures; providing our online services and making them user-friendly.
- Retention and deletion: deletion according to “General information on data retention and deletion”; deletion after termination.
- Legal bases: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Registration using real names: due to the nature of our community, we ask users to use our services only under their real names; pseudonyms are not permitted. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
- User profiles are not public: user profiles are not publicly visible or accessible.
- Deletion after termination: when users terminate their account, account-related data is deleted subject to statutory permission, obligations or user consent. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
- No obligation to retain data: users are responsible for backing up their data after giving notice and before the contract ends. We are entitled to irretrievably delete all user data stored during the contract. Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
Contact and enquiry management
When you contact us, for example by post, contact form, email, telephone or social media, and within existing user and business relationships, we process the enquirer’s information insofar as necessary to answer the enquiry and carry out requested measures.
- Types of data processed: master data (full name, residential address, contact information and customer number); contact data (postal and email addresses or telephone numbers); content data (text or image messages and posts, with related information such as authorship or creation time); usage data (page views and time spent, click paths, intensity and frequency of use, device types and operating systems, interactions with content and functions); metadata, communication and procedural data (IP addresses, times, identification numbers and people involved).
- Data subjects: communication partners.
- Purposes of processing: communication; organisational and administrative procedures; feedback, for example collected through online forms; providing our online services and making them user-friendly.
- Retention and deletion: deletion according to “General information on data retention and deletion”.
- Legal bases: legitimate interests (Article 6(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
Further information on processing operations, procedures and services:
- Contact form: when contacted through our form, email or other channels, we process personal data supplied to answer and handle the enquiry. This generally includes name, contact details and any further information provided that is necessary for appropriate handling. We use this data exclusively for the stated purpose of contact and communication. Legal bases: performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Communication via messengers
We use messengers for communication. Please note the following information about their operation, encryption, use of communication metadata and your opportunities to object.
You can also contact us through alternative channels such as telephone or email. Please use the contact details supplied to you or provided within our online services.
Where contents are end-to-end encrypted, meaning your message and attachments, communication contents such as messages and attached images are encrypted from end to end. This means their contents cannot be viewed, even by the messenger providers. Always use an up-to-date messenger version with encryption enabled to ensure message contents are encrypted.
However, messenger providers may still learn that and when communication partners communicate with us. They may also process technical information about the communication partner’s device and, depending on device settings, location information. This is known as metadata.
Legal bases: if we ask communication partners for permission before communicating through a messenger, consent is the basis for processing their data. Otherwise, for example where they contact us themselves, we use messengers with contractual partners and when establishing contracts as a contractual measure. For other prospective customers and communication partners, use is based on our legitimate interests in fast, efficient communication and meeting their wish to communicate through messengers. We do not initially transmit contact details supplied to us to messenger providers without consent.
Withdrawal, objection and deletion: you may withdraw consent at any time and contact us to exercise your rights. See the terms and conditions linked in the footer.
- Types of data processed: contact data, such as postal and email addresses or telephone numbers; content data, such as text or image messages and posts and related information, including authorship and creation time.
- Data subjects: communication partners.
- Purpose of processing: communication.
- Retention and deletion: deletion according to “General information on data retention and deletion”.
- Legal bases: consent (Article 6(1)(a) GDPR); performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).
Newsletters and electronic notifications
We send newsletters, emails and other electronic notifications (“newsletters”) only with recipients’ consent or on a statutory basis. If newsletter contents are described during subscription, those contents determine the scope of consent. Providing an email address is normally sufficient to subscribe. To offer a personalised service, we may also request your name for a personal greeting or further information necessary for the newsletter’s purpose.
Deletion and restriction of processing: based on our legitimate interests, we may retain unsubscribed email addresses for up to three years before deletion to prove prior consent. Processing is restricted to defending potential claims. An individual deletion request is possible at any time if the former existence of consent is simultaneously confirmed. Where objections must be respected permanently, we reserve the right to retain the email address solely for that purpose in a blocklist.
We log the subscription process on the basis of our legitimate interests in demonstrating that it was properly conducted. If we commission a provider to send emails, this is based on our legitimate interests in an efficient and secure sending system.
Contents:Information about us, our services, promotions and offers.
- Types of data processed: master data (full name, residential address, contact information and customer number); contact data (postal and email addresses or telephone numbers); metadata, communication and procedural data (IP addresses, times, identification numbers and people involved).
- Data subjects: communication partners; users, such as website visitors and online-service users.
- Purposes of processing: direct marketing, for example by email or post; providing contractual services and fulfilling contractual obligations.
- Legal basis: consent (Article 6(1)(a) GDPR).
- Opt-out: you may unsubscribe at any time, withdrawing consent or objecting to further receipt. An unsubscribe link is provided at the end of each newsletter; alternatively, use a contact method listed above, preferably email.
Further information on processing operations, procedures and services:
- Condition for using free services: consent to mailings may be made a condition for using free services, such as accessing particular content or taking part in promotions. If you wish to use the free service without subscribing to the newsletter, please contact us.
Changes and updates
Please check the contents of our privacy policy regularly. We adapt it whenever changes in our data processing make this necessary. We will inform you if changes require action by you, such as consent, or another individual notification.
Where this policy lists company or organisation addresses and contact details, please note that these can change over time and check them before making contact.
Definitions
This section explains terms used in this privacy policy. Where terms are defined by law, their statutory definitions apply. The explanations below are primarily intended to aid understanding.
- Master data: essential information needed to identify and manage contractual partners, user accounts, profiles and similar relationships. It may include personal and demographic details such as names, contact information (addresses, telephone numbers and email addresses), dates of birth and specific identifiers such as user IDs. Master data underpins formal interaction between individuals and services, institutions or systems by enabling clear identification and communication.
- Content data: information generated when creating, editing and publishing content of any kind. It may include text, images, videos, audio files and other multimedia published across platforms and media. It is not limited to the content itself, but also includes metadata about it, such as tags, descriptions, author information and publication dates.
- Contact data: essential information enabling communication with individuals or organisations, including telephone numbers, postal and email addresses, and communication identifiers such as social-media handles and instant-messaging IDs.
- Conversion measurement: a method of assessing the effectiveness of marketing activities, also referred to as visitor-action analysis. Usually, a cookie is stored on users’ devices on the websites where marketing takes place and read again on the destination website. This can show, for example, whether advertisements placed on other websites were successful.
- Metadata, communication and procedural data: categories describing how data is processed, transmitted and managed. Metadata, or data about data, describes the context, origin and structure of other data, including file size, creation date, document author and revision histories. Communication data records information exchanged through channels such as email, call logs, social-network messages and chat histories, including participants, timestamps and transmission paths. Procedural data describes processes and workflows within systems or organisations, including workflow documentation, transaction and activity records, and audit logs used to trace and review operations.
- Usage data: information recording how users interact with digital products, services or platforms. It covers how applications are used, preferred functions, time spent on pages and navigation paths. It may also include frequency of use, activity timestamps, IP addresses, device information and location data. It is particularly useful for analysing user behaviour, improving user experience, personalising content and improving products or services. It also helps identify trends, preferences and potential problems within digital services.
- Personal data: any information relating to an identified or identifiable natural person, known as the data subject. A person is identifiable if they can be identified directly or indirectly, particularly by reference to a name, identification number, location data, online identifier such as a cookie, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
- Profiles containing user-related information: processing such profiles, or “profiles” for short, includes any automated personal-data processing used to analyse, evaluate or predict personal aspects of a natural person. Depending on the profiling, these may include demographics, behaviour and interests, such as interaction with websites and content, interest in particular content or products, click behaviour or location. Cookies and web beacons are frequently used for profiling.
- Log data: information about events or activities recorded in a system or network, typically including timestamps, IP addresses, user actions, error messages and other details of use or operation. It is often used to analyse system problems, monitor security or prepare performance reports.
- Audience measurement: also called web analytics, this evaluates visitor traffic to an online service and may include behaviour or interest in particular information, such as website content. It can show operators when people visit and which content interests them, helping adapt pages to visitors’ needs. Pseudonymous cookies and web beacons are often used to recognise returning visitors and improve usage analysis.
- Tracking: following users’ behaviour across multiple online services. Information about behaviour and interests is generally stored in cookies or on tracking providers’ servers, a process known as profiling. This information can then be used, for example, to display advertisements likely to match users’ interests.
- Controller: the natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of processing personal data.
- Processing: any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, including collection, analysis, storage, transmission and deletion.
- Contract data: specific information relating to formalisation of an agreement between two or more parties. It records the conditions under which services or products are provided, exchanged or sold. This category is essential to managing and fulfilling contractual obligations and includes identifying the parties and recording the agreement’s terms. It may include start and end dates, services or products, prices, payment conditions, cancellation rights, renewal options and special clauses. It forms the legal basis of the relationship and is crucial for clarifying rights and duties, enforcing claims and resolving disputes.
- Payment data: all information needed to process payment transactions between buyers and sellers. Essential for e-commerce, online banking and other financial transactions, it includes card numbers, bank details, payment amounts, transaction dates, verification numbers and billing information. It may also include payment status, chargebacks, authorisations and fees.
- Audience creation: identifying audiences for advertising, such as displaying advertisements, is referred to as creating “custom audiences”. A user’s interest in particular online products or topics may suggest interest in advertisements for similar products or for the shop where they viewed products. “Lookalike audiences” are users whose profiles or interests are assumed to resemble those used to create the original audience. Cookies and web beacons are generally used to create custom and lookalike audiences.
Created using the free Datenschutz-Generator.de by Dr Thomas Schwenke