Privacy statement

This privacy policy informs you about the collection of personal data when using this website.

1.

General notes and information

We take the protection of your data very seriously.

With this privacy policy, we inform you what information we collect and how and for what purposes it is processed. We will also inform you of your rights.

NOTE: If you send us personal data by e-mail, i.e. away from our website, we cannot guarantee secure transmission and therefore no protection of your data. We therefore recommend that you never send personal data unencrypted by e-mail. For this reason, you are also free to provide us with personal data in alternative ways, such as by telephone.

We have implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed via this website. Nevertheless, Internet-based data transmissions can generally have security gaps, so that absolute protection cannot be guaranteed.

We always handle your personal data in accordance with the General Data Protection Regulation (EU) 2016/679.

2nd

Responsible body

If you have any questions or other concerns, you can contact our responsible body at any time, as long as we have not appointed a data protection officer. In this case, please contact them directly.

The person responsible is: top.legal GmbH (hereinafter: “top.legal”), Trogerst 19, 81675 Munich represented by the managing director Mr. Alexander Baron, e-mail: support@top.legal

3rd

legal basis

The legal basis for the use of personal data is based on Article 6 Paragraph 1 of the GDPR. This shows that the processing of personal data is lawful if:

a) The consent of the person concerned has been obtained,
b) it to fulfill a contract or to carry out pre-contractual measures, or
c) to fulfill a legal obligation, or
d) to protect vital interests, or
e) to perform a task that is in the public interest or in the exercise of official authority, or
f) is necessary due to a balance of interests

The legal basis under Article 6 Paragraph 1 f) GDPR is therefore to enable the error-free and secure operation of our website by collecting web server log files.

NOTE: The web server is the computer on which the website is stored. Log files (i.e. log files) are text files that automatically log your Internet history and save it on your web server.

4th

What data is collected and why

4.1

Information collected

Our website collects and stores a range of general data and information with each visit. This general data and information is stored on our web server in web server log files.

The following can be recorded:
(1) browser types and versions used,
(2) the operating system used by the accessing system,
(3) the website from which an accessing system accesses our website (so-called referrer),
(4) the sub-websites, which are accessed via an accessing system on our website,
(5) the date and time of access to the website,
(6) an Internet protocol address (IP address),
(7) the Internet service provider of the accessing system and
(8) other similar data and information used to avert risks in the event of attacks on our information technology systems.

4.2

Why is the data collected

When using this general data and information, we do not draw any conclusions about the person concerned. The information is much more needed to

(1) to correctly deliver the content of our website,
(2) to optimize the content of our website and the advertising for it,
(3) to ensure the long-term functionality of our information technology systems and the technology of our website, and
(4) to provide law enforcement authorities with the information necessary for law enforcement in the event of a cyber attack

This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our company in order to ultimately ensure an optimal level of protection for the personal data we process. The anonymous data in the server log files is stored separately from the personal data you provide.

5th

Definitions

In our privacy policy, we use the following terms, among others:

5.1

Affected people

Data subject is any identified or identifiable natural person whose personal data is processed by the controller.

5.2

Personal data

Personal data is any information that allows conclusions to be drawn about the personal or factual circumstances of a specific or identifiable natural person (hereinafter “data subject”). Information about personal or factual circumstances includes: name, date of birth, address, telephone number, e-mail address. The person can be identified if you can be identified directly or indirectly (e.g. via identification numbers or location data) on the basis of the information.

5.3

workmanship

Processing is any process carried out with or without the aid of automated processes or any such series of processes in connection with personal data, such as collection, collection, organization, organization, organization, organization, ordering, storage, adjustment or modification, reading, querying, use, disclosure through transmission, dissemination or any other form of provision, reconciliation or linking, restriction, deletion or destruction.

5.4

Profiling

Profiling is any type of automated processing of personal data that consists of using this personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to the work performance, economic situation, health, personal preferences, interests, reliability, behavior, whereabouts or changes of location of that natural person.

6th

Duration of storage and deletion of data

We process and store your personal data only for the period necessary to achieve the storage purpose or if this has been provided for by the European legislator of directives and regulations or another legislator in laws or regulations to which the person responsible for processing is subject.

If the storage purpose or the consent given for processing ceases to apply, or if a storage period prescribed by the European legislator of directives and regulations or another competent legislator expires, the personal data is routinely blocked or deleted in accordance with legal regulations.

7th

Withdrawal of your consent to data processing

You have the right to withdraw your consent at any time. To do this, it is sufficient to send an informal message by e-mail to the data protection officer or to the responsible body of our company (see § 2). The legality of the data processing carried out up to the time of revocation remains unaffected by the revocation.

8th

Your rights

8.1

Right to confirmation

You have the right to request confirmation from us as to whether personal data relating to you is being processed. If you wish to exercise this right of confirmation, you can contact our data protection officer or another employee of the controller at any time.

8.2

Right to information, correction and deletion

You have the right to receive free information about your stored personal data, its origin and recipient and the purpose of data processing and a copy of this information, as well as the right to correct, block or delete your data.

8.3

Right to restrict processing

You also have the right to restrict processing and to object to processing.

8.4

Right to surrender

You also have the right to have your data, which we process automatically, handed over to you or to a third party in a common, machine-readable format. To assert your rights, please contact us using the contact details given above for the responsible body.

8.5

Right to lodge a complaint with the competent supervisory authority

You also have the right to lodge a complaint with the competent data protection supervisory authority. The competent supervisory authority for data protection issues is the Bavarian State Office for Data Protection Supervision (https://www.lda.bayern.de/).

8.6

Right to object

You have the right to object to the processing of personal data concerning you at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions.

In the event of an objection, we will no longer process the personal data unless we can demonstrate compelling legitimate reasons for processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

To exercise the right to object, you can contact our data protection officer or another employee directly. In connection with the use of information society services, notwithstanding Directive 2002/58/EC, you are also free to exercise your right of objection by means of automated procedures using technical specifications.

8.7

Automated individual decisions, including profiling

You have the right not to be subject to a decision based exclusively on automated processing — including profiling — which has legal effect against you or significantly affects you in a similar way, provided that the decision.

(1) is not necessary for the conclusion or performance of a contract between the data subject and the person responsible, or

(2) is permitted by Union or Member State legislation to which the person responsible is subject and that legislation contains appropriate measures to protect the rights and freedoms and legitimate interests of the data subject, or

(3) is carried out with the express consent of the person concerned.

Is the decision

(1) required for the conclusion or performance of a contract between the data subject and the person responsible, or

(2) If it is carried out with the express consent of the data subject, we take appropriate measures to protect the rights and freedoms as well as the legitimate interests of the data subject, which includes at least the right to obtain a person's intervention on the part of the person responsible, to state his own point of view and to challenge the decision.

If the data subject wishes to assert rights with regard to automated decisions, he or she can contact our data protection officer or another employee of the controller at any time.

8.8

Right to data portability

You have the right to receive the data concerning you, which you have provided to us, in a structured, common and machine-readable format.

Furthermore, when exercising your right to data portability in accordance with Article 20 (1) GDPR, you have the right to have the personal data transferred directly from one person responsible to another person responsible, as far as this is technically feasible and provided that this does not affect the rights and freedoms of other persons.

9.

cookies

Our website uses cookies. Cookies are information that is transferred from our web server or third-party web servers to your browser and stored there for later retrieval. Cookies can be small files or other types of information storage. Cookies store information that is generated in connection with the specific device used. Cookies contain a characteristic string of characters that enables the browser to be uniquely identified when the website is accessed again. A cookie also contains information about its origin and the storage period. However, this does not mean that we are immediately aware of your identity.

On the one hand, we use so-called session cookies, which are only stored for the duration of the respective visit to our website. A randomly generated unique identification number, a so-called session ID, is stored in a session cookie. Session cookies are automatically deleted after you leave our website.

We also use temporary cookies, which we store on your device for a specific period of time (so-called first-party cookies). If you visit our site again, it will automatically recognize that you have already visited us and which entries and settings you have made so that you do not have to enter them again.

We also use cookies for other purposes, such as web analysis. These cookies are also automatically deleted after a defined period of time. This use is explained in more detail below.

You can prevent cookies from being set by making appropriate settings in your browser. If you deactivate the setting of cookies in the Internet browser you are using, you may not be able to use all functions of our website to their full extent.

You can object to the use of cookies, which are used for audience measurement and advertising purposes, via the deactivation page of the Network Advertising Initiative (http://optout.networkadvertising.org/) and in addition the US website (http://www.aboutads.info/choices) or the European website (http://www.youronlinechoices.com/uk/your-ad-choices/).

10th

registry

It is possible to register on our website.

The personal data you enter will be collected and stored exclusively for internal use and for your own purposes. The person responsible for processing can arrange for the transfer to one or more contract processors, who also use the personal data exclusively for internal use.

By registering on the website, your Internet service provider (ISP) also stores your IP address, the date and time of registration. This data is stored on the basis that this is the only way to prevent misuse of our services and, if necessary, make it possible to investigate committed crimes. In this respect, it is necessary to store this data for security purposes. In principle, this data will not be passed on to third parties unless there is a legal obligation to transfer it or the transfer is for law enforcement purposes.

Registration with voluntary provision of personal data enables us to offer you content or services which, due to the nature of the matter, can only be offered to registered users. Registered persons are free to amend the personal data provided during registration at any time or to have them completely deleted from the database of the person responsible for processing.

You can obtain information about your personal data from the responsible body at any time. Furthermore, the responsible body will correct or delete your personal data at the request or notice of the person concerned, provided that there are no legal storage obligations to the contrary. A data protection officer named in this data protection declaration and all of the employees of the controller are available to the data subject as contact persons in this context.

11th

Use of web analysis tools

We use web analysis tools on our website.
If you want
As part of the web analysis, data about the behavior of visitors (such as age or gender) is collected, which is then calculated as key performance indicators (KPIs). On the basis of these key figures, information (such as interests or demographic trends) of visitors is analyzed in order to filter weak points on the website and to be able to sustainably improve the efficiency of the website. Web analysis is therefore primarily used to monitor the long-term success of a website.

In most cases, cookies or similar processes are used to collect such information. The data collected includes, for example, the browser used, the duration of the visit or the content viewed. The collected and stored data also includes your IP address. However, this is shortened for your protection and is therefore pseudonomized. This means that the actual identity of us or the respective web analysis provider cannot be traced, but only the pseudonomized data provided.

As already described above, you can prevent the setting of cookies by our website at any time by setting the Internet browser you are using and thus permanently object to the setting of cookies. Such a setting of the Internet browser used would also prevent a cookie from being set on your information technology system. In addition, cookies that have already been set can be deleted at any time via an Internet browser or other software programs.

We use the following web analysis tools:

service provider Google Analytics: Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA; privacy policy: https://www.google.de/intl/de/policies/privacy/ and http://www.google.com/analytics/terms/de.html

12th

Use of online marketing tools

We store and process personal data for online marketing purposes. This data is primarily used to create user profiles, which can be used to display interest-specific advertising or other content. For these purposes, data such as: name, age, gender, duration of visit to a website, online networks used, usage times and other content are stored. Cookies or similar processes are used to collect such information. The data collected includes, for example, the browser used, the duration of the visit or the content viewed. The collected and stored data also includes your IP address. However, this is shortened for your protection and is therefore pseudonomized. This means that the actual identity of us or the respective web analysis provider cannot be traced, but only the pseudonomized data provided.

We use the following online marketing tools:

Service provider of Double Click: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; privacy policy: https://policies.google.com/privacy; Privacy Shield (ensuring a level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active; Opt-out option: Opt-out plugin: http://tools.google.com/dlpage/gaoptout?hl=de, settings for displaying advertisements: https://adssettings.google.com/authenticated.

Service provider of Google Ad Words: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; privacy policy: https://policies.google.com/privacy; Privacy Shield (ensuring a level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active; Opt-out option: Opt-out plugin: http://tools.google.com/dlpage/gaoptout?hl=de, settings for displaying advertisements: https://adssettings.google.com/authenticated.

service provider Google Remarketing Tags: Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy Policy: http://www.google.com/policies/

Service provider of Google AdSense: Alphabet Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA; Privacy Policy: https://www.google.com/policies/

13th

web hosting

We use services from one or more web hosting providers for our online offering. For example, web hosting provides us with storage space, computing capacity or security services, which enables us to provide our website securely and efficiently. As part of web hosting, all data of users who visit our website is forwarded to the web host's server. These include: address and name of the accessed websites and files, date and time of retrieval and amounts of data transferred. Web hosts are also often used to send emails.

We use the following web hosting providers:

service provider AWS (Amazon Web Service): Amazon Web Services, Inc. P.O. Box 81226 Seattle, WA 98108-1226; Web site: https://aws.amazon.com; Privacy Policy: https://aws.amazon.com/de/compliance/data-privacy/

Service provider of Webflow: Webflow, Inc. 208 Utah, Suite 210, San Francisco, CA 94103, USA; Web Site: https://webflow.com; Privacy Policy: https://webflow.com/legal/eu-privacy-policy; Privacy Shield (ensuring a level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt0000000TT9jAAG&status=Active

14th

Using external payment service providers

As part of our services and products, we offer effective and secure payment options via third-party providers.

If you select either “purchase on account” or “installment purchase” as a payment option during the ordering process, your data will be automatically transmitted to the respective payment service provider. By choosing one of these payment options, you consent to this transfer of personal data, which is required to process the invoice or installment purchase or for identity and credit checks.
If you want
The personal data transmitted is usually first name, last name, address, date of birth, gender, email address, IP address, telephone number, mobile phone number and other data that is necessary to process an invoice or installment purchase. Personal data related to the respective order is also necessary to process the corresponding contract.

The transmission of data is aimed in particular at identity verification, payment administration and fraud prevention.

Payment transactions are subject to the terms and conditions and data protection information of the respective payment service providers, which can be accessed within the respective websites or transaction applications. We also refer to the terms and conditions of the individual payment providers insofar as they wish to assert their rights. If you have any problems, you are still welcome to contact us first.

We use the following external payment provider:
If you want
Service provider of Stripe: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, United States; Web Site: https://stripe.com/de; Privacy Policy: https://stripe.com/de/privacy

15th

Newsletters, online forms and chat

If we have your consent or legal permission, we will send you our newsletters or other electronic notifications with content about us and our offers.

We inform our customers and business partners regularly by means of a newsletter about company offers. In principle, our company's newsletter can only be received by the person concerned if
If you want
(1) the person concerned has a valid e-mail address and
(2) the person concerned registers to receive the newsletter

For legal reasons, a confirmation email will be sent to the e-mail address you have registered for the newsletter for the first time. This confirmation email is used to check whether the owner of the e-mail address as the data subject has authorized the receipt of the newsletter.
The personal data collected as part of a newsletter subscription is used exclusively to send our newsletter. There is no transfer of personal data collected as part of the newsletter service to third parties. You can cancel your subscription to our newsletter at any time. The consent to the storage of personal data that you have given us for sending the newsletter can be withdrawn at any time. For the purpose of withdrawing consent, there is a corresponding link in every newsletter. It is also possible to contact us at any time in another way to unsubscribe from the newsletter.

We use the following newsletter tool provider:

service provider Hubspot: HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141 USA, Attn: Web Site: https://www.hubspot.de/ Privacy statement: https://legal.hubspot.com/de/privacy-policy

16th

Application tools

We offer you the opportunity to apply to us via our website.

The application process requires that you provide us with the data required for an application, which will then be processed automatically by us.
If an employment contract is concluded as a result of your application, your data will be stored by us in your personnel file for organizational and administrative purposes. This is done in compliance with legal regulations.

In the event of rejection of an application, your data will be automatically deleted by us two months after notification. It will not be deleted if, due to legal provisions, the data requires longer storage of up to four months or following court proceedings.
We use the following web hosting providers:

We use the following provider for applications:

service provider Smartrecruiters: SmartRecruiters Inc., 225 Bush Street, Suite #300, San Francisco CA 94104; Web Site: https://www.smartrecruiters.com/de/home/; Privacy Policy: https://www.smartrecruiters.com/legal/general-privacy-policy/

17th

Other third-party services

We have integrated further content from third-party providers on our website, through which personal data is processed.
This includes, for example, videos or graphics. By integrating the respective third-party providers, your IP address is retrieved, which is necessary to send the respective content to your browser. In addition, third-party providers may use so-called pixel tags. Pixel tags are small graphics that are automatically loaded when a website is accessed and allow statistical evaluation and analysis of user behavior. These pixels are usually not visible to visitors to a website. We have integrated components from the following third-party providers on our website:

We use the following providers:

service provider Google Suite: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; privacy policy: https://policies.google.com/privacy; Privacy Shield (ensuring a level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active; Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for displaying advertisements: https://adssettings.google.com/authenticated.

service provider Google Fonts: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; privacy policy: https://policies.google.com/privacy; Privacy Shield (ensuring a level of data protection when processing data in the USA): https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active; Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for displaying advertisements: https://adssettings.google.com/authenticated.

If you want
service provider Typeform: TYPEFORM SL C/Bac de Roda, 163 (Local), 08018 — Barcelona (Spain); email: gdpr@typeform.com; privacy policy: https://admin.typeform.com/to/dwk6gt/

service provider Productboard: Attn: Legal Department, 392 Staten Ave, Oakland, CA 94610 USA; Privacy Policy: https://legal.productboard.com/terms, https://www.productboard.com/msa/2022-08-18/If you want

18th

Subject to change

This data protection policy complies with the currently applicable legal regulations on data protection. We reserve the right to adjust and change them as required.

If you want