Privacy Policy

This privacy policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) within our online offering and the associated websites, functions, and content, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). With regard to the terms used, such as “processing” or “controller,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Person Responsible

LA2 GmbH
Allee am Röthelheimpark 15
91052 Erlangen
Germany

Tel: +49 – (9131) – 6149201
Fax: +49 – (9131) – 6149209
Email: la2@la2.de
Internet: www.LA2.de

Managing Directors: Jürgen Dallner, Oliver Hoff, Marc Holfelder, Christian Matiack

District Court of Fürth HRB 7456
Tax No.: 9 216/183/60040
Sales ID: DE 202 435 485
DUNS No.: 31 32 79 270

Imprint:  https://doq-digital.de/doq-imprint/

Data Protection Officer:
ask Datenschutz
Sascha Kuhrau
Schulstrasse 16a
91245 Simmelsdorf
info@ask-datenschutz.de
Landline 09155-263 99 70

Types of Data Processed:

  • Inventory data (e.g. names, addresses)
  • Contact details (e.g. email, telephone numbers)
  • Content data (e.g. text entries, photographs, videos)
  • Usage data (e.g. websites visited, interest in content, access times)
  • Meta/communication data (e.g. device information, IP addresses)

Categories of Data Subjects

Visitors and users of the online offer (hereinafter we refer to the data subjects collectively as “users”).

Purposes of Processing

  • Provision of the online offering, its functions and contents
  • Answering contact requests and communicating with users
  • Security measures
  • Reach measurement / marketing (only on the basis of consent)

Definitions

“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and covers virtually all data handling.

“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

The “controller” is the natural or legal person, public authority, agency or other body which alone or jointly with others decides on the purposes and means of the processing of personal data.

“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Relevant Legal Bases

In accordance with Art. 13 GDPR, we inform you of the legal basis for our data processing. If the legal basis is not mentioned in this privacy policy, the following applies:

  • The legal basis for obtaining consent is Art. 6 (1) (a) and Art. 7 GDPR.
  • The legal basis for processing to fulfil our services and implement contractual measures as well as to answer inquiries is Art. 6 (1) (b) GDPR.
  • The legal basis for processing to fulfil our legal obligations is Art. 6 (1) (c) GDPR.
  • The legal basis for processing to protect our legitimate interests is Art. 6 (1) (f) GDPR.
  • In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR serves as the legal basis.

Security Measures

In accordance with Art. 32 GDPR, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as the access, input, and transfer of data, ensuring its availability, and segregation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the deletion of data, and response to data threats. Furthermore, we consider the protection of personal data right from the development and selection of hardware, software, and processes, in accordance with the principle of data protection by design and through data protection-friendly default settings (Article 25 GDPR).

Cooperation with Processors and Third Parties

If, as part of our processing, we disclose data to other persons and companies (contract processors or third parties), transmit it to them or otherwise grant them access to the data, this will only be done on the basis of legal permission (e.g. if transmission of the data to third parties, such as payment service providers, is necessary to fulfil the contract in accordance with Art. 6 (1) (b) GDPR), you have consented, a legal obligation provides for this or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).

If we commission third parties to process data on the basis of a so-called “order processing agreement”, this is done on the basis of Art. 28 GDPR.

Transfers to Third Countries

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs as part of the use of third-party services or the disclosure or transmission of data to third parties, this will only occur if it is necessary to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests.

Subject to legal or contractual permissions, we will only process or have data processed in a third country if the special requirements of Art. 44 et seq. GDPR are met. This means that processing is carried out on the basis of appropriate safeguards, such as:

  • An adequacy decision of the European Commission (e.g. for the USA on the basis of the EU-U.S. Data Privacy Framework (DPF), adopted on 10 July 2023), provided the respective recipient is certified accordingly; or
  • EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR.

ℹ️ Note: The former EU-U.S. Privacy Shield was invalidated by the Court of Justice of the European Union on 16 July 2020 (Case C-311/18, “Schrems II”) and is no longer a valid transfer mechanism.

Rights of Data Subjects

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether data concerning you is being processed and to receive information about this data as well as a copy thereof.
  • Right to rectification (Art. 16 GDPR): You have the right to request the completion or correction of inaccurate data concerning you.
  • Right to erasure (Art. 17 GDPR): You have the right to request that data concerning you be deleted immediately.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request that the processing of data concerning you be restricted.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, and to request its transmission to another controller.
  • Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with the competent supervisory authority. The supervisory authority responsible for LA2 GmbH is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, lda.bayern.de.

Right of Withdrawal

You have the right to revoke consent given in accordance with Art. 7 (3) GDPR with effect for the future.

Right of Objection

You may object to the future processing of your data at any time in accordance with Art. 21 GDPR. In particular, you may object to processing for direct marketing purposes.

Cookies and Consent Management

What are cookies? “Cookies” are small files that are stored on users’ computers. Different types of information can be stored within cookies. A cookie is primarily used to save information about a user (or the device on which the cookie is stored) during or after their visit to an online service.

We distinguish between:

  • Strictly necessary cookies: Required for the basic functioning of the website. These are set without consent on the basis of Art. 6 (1) (f) GDPR (legitimate interest in operating a functional website) and § 25 (2) No. 2 TTDSG.
  • Functional cookies: Enhance usability (e.g. language preferences). Set only with your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG.
  • Statistics / analytics cookies: Used to analyse website usage (e.g. Google Analytics 4). Set only with your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG.
  • Marketing cookies: Used for targeted advertising. Set only with your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG.

Consent management: When you first visit our website, a consent banner will appear allowing you to accept, decline, or individually configure the use of non-essential cookies. You can change or withdraw your consent at any time via the “Privacy Settings” link in the footer of our website. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

If you do not wish cookies to be stored on your device, you may also deactivate them in your browser settings. Please note that this may result in functional limitations of this online offering.

Deletion of Data

The data we process will be deleted or restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated in this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and there are no statutory retention periods that prevent deletion.

According to legal requirements in Germany, storage takes place in particular for:

  • 10 years in accordance with §§ 147 Para. 1 AO, 257 Para. 1 Nos. 1 and 4 HGB (books, records, accounting documents, etc.)
  • 6 years in accordance with § 257 Para. 1 Nos. 2 and 3 HGB (commercial letters)

According to legal requirements in Austria, storage takes place in particular for:

  • 7 years in accordance with § 132 Para. 1 BAO (accounting documents, receipts, etc.)
  • 22 years in connection with real estate
  • 10 years for documents in connection with electronically provided services subject to the Mini One Stop Shop (MOSS)

Business-Related Processing

In addition, we process contract data (e.g. subject matter of the contract, term, customer category) and payment data (e.g. bank details, payment history) from our customers, interested parties and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.

Software Development and IT Services

We process our customers’ data within the scope of our contractual services, which include conceptual and strategic consulting, software and design development/consulting or maintenance, server administration, data analysis/consulting services and training services.

We process inventory data, contact data, content data, contract data, payment data, usage and metadata. We generally do not process special categories of personal data unless these are part of a commissioned processing operation. The legal basis for the processing is Art. 6 (1) (b) GDPR (contractual services) and Art. 6 (1) (f) GDPR (analysis, statistics, optimization, security measures). When processing data provided to us within the scope of an order, we act in accordance with the client’s instructions and the legal requirements for data processing pursuant to Art. 28 GDPR.

We delete data after the expiration of statutory warranty and similar obligations. The necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, deletion occurs after their expiration.

Administration, Financial Accounting, Office Organization

We process data as part of administrative tasks and to organize our operations, financial accounting, and to comply with legal obligations, such as archiving. The processing is based on Art. 6 (1) (c) GDPR and Art. 6 (1) (f) GDPR.

We disclose or transmit data to the tax authorities, consultants such as tax consultants or auditors as well as other fee offices and payment service providers.

Business Analyses and Market Research

In order to operate our business economically and to identify market trends, we analyse the data available to us on business transactions, contracts, inquiries, etc. on the basis of Art. 6 (1) (f) GDPR. The analyses serve our sole purpose and will not be disclosed externally unless they are anonymous analyses with summarised values. Personal analyses or profiles will be deleted or anonymised upon termination of the user relationship, otherwise after two years from the conclusion of the contract.

Application Process

We process applicant data only for the purpose and within the scope of the application process in accordance with legal requirements. The legal basis is Art. 6 (1) (b) GDPR and § 26 BDSG (German Federal Data Protection Act). Where data processing is necessary in the context of legal proceedings, Art. 6 (1) (f) GDPR also applies.

The application process requires applicants to provide us with their application data (personal information, postal and contact addresses, cover letter, CV, references). Applicants may also voluntarily provide additional information.

If special categories of personal data within the meaning of Art. 9 (1) GDPR are voluntarily provided during the application process, they will be processed in accordance with Art. 9 (2) (b) GDPR. If such data are requested, processing is based on Art. 9 (2) (a) GDPR.

Applications may be submitted via our online form (encrypted transmission), by email, or by post. Please note that emails are generally not transmitted in encrypted form; we therefore recommend using the online form or postal mail.

If the application is successful, the data provided may be further processed for the purposes of the employment relationship. Otherwise, applicant data will be deleted after a period of six months following the conclusion of the application process, unless a longer retention period is required by law or the applicant has consented to longer storage.

ℹ️ Note: The processing of applicant data is based on Art. 6 (1) (b) GDPR and § 26 BDSG – not on consent. Submitting an application does not constitute consent to data processing within the meaning of Art. 7 GDPR.

Contact

When you contact us (e.g., via contact form, email, telephone, or social media), the user’s information will be processed to process the contact request and its handling in accordance with Art. 6 (1) (b) GDPR. User information may be stored in a customer relationship management system (“CRM system”) or similar request organization.

We delete requests if they are no longer required. We review their necessity every two years; furthermore, statutory archiving obligations apply.

Newsletter

We only send newsletters and other electronic notifications containing promotional information with the recipient’s explicit consent or on the basis of a legal permission.

Double opt-in and logging: Registration for our newsletter is done using a double opt-in process. After registration, you will receive an email asking you to confirm your registration. Newsletter registrations are logged to provide evidence of the registration process in accordance with legal requirements. This includes saving the time of registration and confirmation, as well as the IP address.

Registration data: To subscribe to the newsletter, simply provide your email address. Optionally, we ask you to provide a name so we can address you personally.

Legal basis: The newsletter is sent on the basis of the recipient’s consent pursuant to Art. 6 (1) (a), Art. 7 GDPR in conjunction with § 7 (2) No. 3 UWG. The logging of the registration process is based on Art. 6 (1) (f) GDPR (legitimate interest in demonstrating consent).

Cancellation/Revocation: You can unsubscribe from our newsletter at any time by clicking the unsubscribe link at the end of each newsletter. We may store unsubscribed email addresses for up to three years based on our legitimate interests (Art. 6 (1) (f) GDPR) in order to be able to demonstrate that consent was previously given. An individual request for deletion is possible at any time.

Newsletter Service Provider – CleverReach

The newsletter is sent via CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany. CleverReach’s privacy policy is available at: https://www.cleverreach.com/en/privacy-policy/

CleverReach is used on the basis of our legitimate interests pursuant to Art. 6 (1) (f) GDPR and a data processing agreement pursuant to Art. 28 (3) GDPR. CleverReach may use recipients’ data in pseudonymous form to optimise or improve its own services (e.g. technical optimisation of delivery, statistical purposes). CleverReach does not use the data of our newsletter recipients to contact them directly or to pass the data on to third parties.

Hosting and email sending

The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services and technical maintenance services, which we use for the purpose of operating this online offering.

In doing so, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, interested parties and visitors to this online offer on the basis of our legitimate interests in the efficient and secure provision of this online offer in accordance with Art. 6 (1) (f) GDPR in conjunction with Art. 28 GDPR (conclusion of a contract for data processing).

Collection of access data and log files

Based on our legitimate interests pursuant to Art. 6 (1) (f) GDPR, we, or rather our hosting provider, collect data about every access to the server on which this service is located (so-called server log files). This access data includes the name of the accessed website, the file, the date and time of access, the amount of data transferred, the notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address, and the requesting provider.

Log file information is stored for security reasons (e.g., to investigate misuse or fraud) for a maximum of 7 days and then deleted. Data that needs to be retained for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.

Google Analytics 4

We use Google Analytics 4, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”), on the basis of your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Google Analytics 4 is only loaded after you have given your consent via our cookie consent banner.

Google Analytics uses cookies to analyse how users use our website. The information generated by the cookie about your use of this website is generally transmitted to a Google server in the USA and stored there.

Transfer to the USA: Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF). Transfers to the USA are therefore based on the adequacy decision of the European Commission of 10 July 2023 pursuant to Art. 45 GDPR. Additionally, we have concluded Standard Contractual Clauses (SCCs) with Google pursuant to Art. 46 (2) (c) GDPR.

IP anonymisation: We have activated IP anonymisation in Google Analytics 4. Your IP address will be truncated by Google within the EU/EEA before transmission to the USA.

Data retention: We have set the data retention period in Google Analytics to a maximum of 14 months.

Opt-out: You can withdraw your consent at any time via the “Privacy Settings” link in the footer of our website. You can also prevent Google from collecting and processing data generated by the cookie by downloading and installing the browser plugin available at: https://tools.google.com/dlpage/gaoptout

For more information on Google’s data processing, please refer to Google’s privacy policy: https://policies.google.com/privacy

GTranslate

We use GTranslate, a translation service provided by GTranslate LLC, to offer our website content in multiple languages. GTranslate is only loaded after you have given your consent via our cookie consent banner, pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG.

When you use the translation function, your IP address and usage data may be transmitted to GTranslate LLC and to Google (for the underlying Google Translate service). Translations are only activated after your consent to the optional GTranslate service. Without consent, the website remains available in English.

For more information, please refer to GTranslate’s privacy policy: https://gtranslate.io/privacy-policy

LinkedIn

Our website contains a link to our LinkedIn company page (linkedin.com/company/la2-gmbh). This is a simple hyperlink only – no LinkedIn plugins, tracking pixels or social media buttons are embedded on this website. Clicking the link will take you to LinkedIn’s website, which is subject to LinkedIn’s own privacy policy: https://www.linkedin.com/legal/privacy-policy

YouTube

We embed videos from the “YouTube” platform, provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). YouTube videos are only loaded after you have given your consent via our cookie consent banner, pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TTDSG. Where technically possible, we use YouTube’s enhanced privacy mode (youtube-nocookie.com), which prevents YouTube from storing cookies on your device until you actively interact with the video player.
When a YouTube video is played, Google may collect data about your usage behaviour and link it to your Google account if you are logged in.
Transfer to the USA: Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF). Transfers to the USA are therefore based on the adequacy decision of the European Commission of 10 July 2023 pursuant to Art. 45 GDPR. Additionally, we have concluded Standard Contractual Clauses (SCCs) with Google pursuant to Art. 46 (2) (c) GDPR.
Opt-out: You can withdraw your consent at any time via the “Privacy Settings” link in the footer of our website.
For more information on Google’s data processing, please refer to Google’s privacy policy: https://policies.google.com/privacy

Changes to This Privacy Policy

We reserve the right to update this privacy policy from time to time to reflect changes in legal requirements or our data processing practices. The current version is always available at https://doq-digital.de/privacy-policy/. We recommend that you review this privacy policy regularly.