1. Intro
Protecting your personal data is our top priority. This privacy policy explains the type, scope and purpose of processing personal data ("data") in connection with our online offering. This includes the associated website, functions and content, as well as external online presences such as social media profiles (together, the "online offering"). Your personal data is treated confidentially and processed strictly in line with statutory data protection law and this privacy policy.
General Notes
This privacy policy gives you a full overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to identify you personally. For detailed information, please refer to this full privacy policy.
Controller
Data processing on this website is carried out by the website operator. You can find the controller's contact details in the "Controller" section of this privacy policy.
Collecting Your Data
Personal data is collected in part when you actively provide it, e.g. by filling out a contact form. Other data is collected automatically, or after your consent, by the controller's IT systems when you visit the website. This is mainly technical data (e.g. browser, operating system or time of the page visit). This data is collected automatically as soon as you enter the website.
Use of Your Data
Some data is collected to ensure the website is provided without errors. Other data may be used to analyse your user behaviour, to optimise our offering and adapt it to your needs.
Disclosing Data to Third Parties
In the course of the controller's business activity, it may be necessary to disclose personal data to external parties. This only happens under certain conditions: where disclosure is necessary to perform a contract, where a legal obligation exists, e.g. to tax authorities, where a legitimate interest under Art. 6(1)(f) GDPR exists, or where another legal basis permits the disclosure. Where external service providers process data on our behalf, this is done solely under a valid data processing agreement under Art. 28 GDPR. Where data is jointly processed with other parties, a joint-controller agreement under Art. 26 GDPR is concluded.
Withdrawing Consent to Data Processing
Certain data processing can only take place with your express consent. This consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Right to Object to Specific Processing and Advertising (Art. 21 GDPR)
Where your personal data is processed under Art. 6(1)(e) or (f) GDPR, you have the right to object at any time, for reasons arising from your particular situation. This also applies to profiling based on these provisions. The specific legal basis for processing can be found in this privacy policy. If you object, the controller will no longer process your personal data, unless compelling legitimate grounds can be
shown that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims (objection under Art. 21(1) GDPR).
Where your personal data is used for direct marketing, you have the right to object to such processing at any time. This also applies to profiling connected with direct marketing. Once you object, the controller will no longer use your personal data for these marketing purposes (objection under Art. 21(2) GDPR).
Rights Under the GDPR
You have the right to lodge a complaint with a competent supervisory authority for breaches of the GDPR. This right may in particular be exercised in the member state of your habitual residence, place of work, or place of the alleged breach. Other administrative or judicial remedies remain unaffected.
Personal data processed automatically on the basis of consent or to perform a contract may be requested in a structured, common and machine-readable format. On request, this data can also be transferred directly to another controller, where technically feasible.
Every data subject has the right to obtain, free of charge, information about their stored personal data, its origin, recipients and the purpose of processing. There is also a right to rectification or erasure of this data, where legally permitted. For further questions on personal data, you may contact the controller at any time.
You have the right to request restriction of the processing of your personal data where you contest its accuracy, pending verification. In cases of unlawful processing, you may request restriction instead of erasure. Restriction may also be requested where the data is no longer needed but is required to assert, exercise or defend legal claims, or while it is being determined whose interests prevail following an objection under Art. 21(1) GDPR.
Where processing of personal data is restricted, it may, apart from being stored, only be processed with the data subject's consent, to assert, exercise or defend legal claims, to protect the rights of another person, or for important public-interest reasons of the EU or a member state.
2. Controller
The controller for data processing on this website within the meaning of the GDPR is:
Firm: woerle peaks foundation gGmbH
Represented by: Mr Philipp Burger
Address: 6610 Wängle, Höfener Straße 1/2
Website: www.woerlepeaks.com
Email: contact@woerlepeaks.com
Phone: +436606773495
3. Data Protection Officer
The data protection officer is available as your contact for all questions on data protection:
Name: Philipp Burger
Address: 6610 Wängle, Höfener Straße 1/2
Email: contact@woerlepeaks.com
4. Processors
We work with various processors who process data on our behalf. These service providers are contractually bound to treat the data confidentially and to use it only for the relevant service. In some cases, responsibility for processing is shared with other parties. In such cases, responsibilities are set out transparently and documented to ensure compliance with data protection requirements.
5. Definitions
To keep this privacy policy transparent and understandable, it mainly uses terms also defined in the GDPR. Full legal definitions can be found in Art. 4 GDPR. The key terms used in this policy are explained below:
Personal data:
Any information relating to an identified or identifiable natural person ("data subject"). A person is identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an ID number, location data, an online identifier (e.g. a cookie), or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity.
Processing:
Any operation or set of operations performed on personal data, whether or not by automated means. This may include collecting, recording, organising, structuring, storing, adapting, altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning, combining, restricting, erasing or destroying data.
Controller:
The natural or legal person, authority, agency or other body which, alone or jointly with others, decides on the purposes and means of processing personal data.
Processor:
A natural or legal person, authority, agency or other body that processes personal data on behalf of the controller.
Consent:
Any freely given, specific, informed and unambiguous indication of the data subject's wishes, given by a statement or a clear affirmative action, signifying agreement to the processing of their personal data.
Website:
The website means the entire online offering provided by the controller under a specific URL. This includes all content, information, functions and services published by the controller and made accessible to users via this URL. The website serves as a digital platform for providing information and services, and for interaction between the controller and users.
Device:
A device is any electronic device able to access the internet and load web pages. This includes, among others, computers, laptops, tablets and smartphones.
These definitions help you better understand this privacy policy and the meaning of the terms used.
6. Hosting
This website is hosted on the servers of an external service provider, to give you reliable and secure use of this online offering.
Processing by the hosting provider is based on Art. 6(1)(f) GDPR, as the controller has a legitimate interest in providing a stable and secure website. Where user consent is required (e.g. for certain cookies or tracking technologies), processing is based on the user's consent under Art. 6(1)(a) GDPR and Sec. 25(1) TTDSG. You may withdraw your consent at any time with effect for the future.
The hosting provider is: Wix.com Ltd., 40 Namal Tel Aviv Street, Tel Aviv, 6350671 Israel
Details on data processing and data protection can be found in the hosting provider's privacy policy, available here: https://de.wix.com/about/privacy
To ensure your data is processed in line with applicable data protection law, a data processing agreement (DPA) has been concluded with the hosting provider. This agreement obliges the hosting provider to process visitors' personal data solely on the controller's instructions and in accordance with the GDPR. The hosting provider guarantees comprehensive protection of your data through technical and organisational measures.
7. Legal Bases for Data Processing
Your personal data is processed on the basis of the GDPR and other relevant statutory provisions. Depending on the purpose of processing, different legal bases apply.
Where you have consented to processing of your personal data, this is based on your consent under Art. 6(1)(a) GDPR. This applies in particular to processing special categories of personal data under Art. 9(2)(a) GDPR and to transfers of personal data to third countries under Art. 49(1)(a) GDPR. You may withdraw your consent at any time.
Processing your data may be necessary to perform a contract or carry out pre-contractual steps, in which case it is based on Art. 6(1)(b) GDPR. Processing may also be required to comply with a legal obligation, based on Art. 6(1)(c) GDPR.
In certain cases, processing serves the legitimate interests of the controller or a third party, unless your interests or fundamental rights and freedoms prevail. This processing is based on Art. 6(1)(f) GDPR.
Certain processing may also be subject to national rules, such as Sec. 25 TTDSG for storing cookies or accessing information on your device. The applicable legal bases are explained in detail in the specific sections of this privacy policy.
Where your data is required to perform a contract or carry out pre-contractual steps, processing is based on Art. 6(1)(b) GDPR. For compliance with a legal obligation, processing is based on Art. 6(1)(c) GDPR. Processing may also be based on legitimate interests under Art. 6(1)(f) GDPR. The specific legal basis in each case is explained in the following sections of this privacy policy.
8. Disclosure to Unsafe Third Countries and Non-DPF-Certified US Companies
Where tools from companies based in third countries considered unsafe for data protection are used on this website, or US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF), your personal data may be transferred to and processed in those countries. Please note that unsafe third countries cannot guarantee a level of data protection equivalent to the EU. The US, as an unsafe third country, is generally not guaranteed to offer a comparable level of protection. A transfer to the US is therefore only permitted where the recipient is either certified under the DPF or has suitable additional safeguards in place. Detailed
information on possible transfers to third countries, including recipients, is set out in this privacy policy.
9. Retention
Unless a more specific storage period is stated in this privacy policy, personal data remains with the controller until the purpose of processing no longer applies. Where a valid erasure request is made or consent is withdrawn, the data is erased unless other legally permitted grounds for storage exist (e.g. tax or commercial retention periods). In such cases, erasure follows once those grounds cease to apply.
The controller only stores personal data for as long as necessary to fulfil the purposes for which it was collected. This includes in particular performing contractual obligations, complying with statutory retention periods, and safeguarding the controller's legitimate interests, such as IT security and protection against misuse. Where processing is based on consent, storage continues until the data subject withdraws that consent. Such withdrawal is possible at any time with effect for the future. The data is then erased without delay, unless statutory retention duties or other overriding legal grounds require further storage.
In summary, personal data is erased once its purpose has been fulfilled or the legal basis for storage no longer applies, unless legal obligations or legitimate interests continue to justify further storage.
10. Security Measures and Data Minimisation
Comprehensive technical and organisational measures are taken to effectively protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access. Only the data strictly necessary for the relevant purpose is collected and processed. This data-minimisation approach significantly reduces the risk of misuse and unauthorised access. Security measures are continuously adapted to the state of the art to keep protection of your data at a consistently high level.
11. SSL/TLS Encryption
To protect your data during transmission, state-of-the-art encryption methods (e.g. SSL or TLS) are used via HTTPS. SSL (Secure Socket Layer) and TLS (Transport Layer Security) are protocols for encrypting data transfers on the internet. This ensures that data exchanged between your browser and the server is protected from unauthorised access. You can recognise an encrypted connection by the browser address bar switching from "http://" to "https://" and by the padlock icon in your browser bar.
12. Encrypted Payment Transactions via the Website
Where a paid contract requires you to provide payment data (e.g. an account number for direct debit) to the controller, this data is transmitted in encrypted form. This encryption technology provides strong protection for payment data and prevents third-party access. An encrypted connection can be recognised by the browser address bar switching from "http://" to "https://" and by the padlock icon in the browser bar. The use of SSL/TLS ensures that payment data is handled securely and confidentially.
13. Storing User Information in Log Files
Each time the website is accessed, general information transmitted by your browser to the server is automatically recorded. This information is stored in what are known as log files and typically includes:
IP address of the requesting computer
date and time of access
name and URL of the file accessed
website from which access occurred (referrer URL)
browser used and user agent string
operating system
name of your access provider
HTTP status code
This data is stored for security reasons, to ensure a smooth connection to the website, for the website's convenient use, to evaluate system security and stability, and for further administrative purposes.
The legal basis for this processing is Art. 6(1)(f) GDPR. The legitimate interest arises from the stated purposes of data collection. The collected data is never used to draw conclusions about you personally. Stored data is anonymised or erased, unless statutory retention obligations apply.
14. Cookies
This website uses cookies. These are small files your browser automatically creates and stores on your device (laptop, tablet, smartphone, etc.) when you visit the site. Cookies cause no damage to your device and contain no viruses, trojans or other malware.
Information is stored in the cookie that relates to the specific device used. This does not mean the controller thereby gains direct knowledge of your identity.
Cookies are used, in part, to make using the site more pleasant for you. The controller uses session cookies to recognise that you have already visited certain pages of the website. These are automatically deleted when you leave the site.
The controller also uses temporary cookies, stored on your device for a set period, to improve usability. When you revisit the site to use its services, it is automatically recognised that you have been there before, along with any entries and settings you made, so you do not have to enter them again.
The controller also uses cookies to statistically record use of the website and to evaluate it for the purpose of optimising the offering for you. These cookies let the controller automatically recognise, on a repeat visit, that you have been there before. They are automatically deleted after a defined period.
Data processed via cookies is necessary for the stated purposes to safeguard the legitimate interests of the controller and third parties under Art. 6(1) sentence 1(f) GDPR.
Most browsers accept cookies automatically. You can configure your browser so that no cookies are stored on your computer, or so that a notice always appears before a new cookie is created. Fully disabling cookies may mean you cannot use all functions of the website.
15. Cookie Consent Banner
This website uses a cookie consent banner to manage your consent to the use of cookies. The provider of this service is:
Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany
Further information on data processing is available at: https://usercentrics.com/de/datenschutzerklaerung/
Function and Purpose
The cookie consent banner sets a technically necessary cookie to store your cookie consents. This cookie does not process personal data. It only stores the choices you made when entering the website, including:
Consent to or rejection of certain cookies
the time consent was given
how long the settings are stored
the legal basis for the processing
Processing by the cookie consent banner is based on Art. 6(1)(f) GDPR. The controller's legitimate interest is ensuring lawful consent to the use of cookies. Where consent was requested, processing is based on Art. 6(1)(a) GDPR.
Storage Period and Deletion
The stored data remains until you delete the cookies in your browser yourself or withdraw your consent. You can change your settings at any time in this website's cookie settings.
16. Use of the Contact Form
For any questions, you can contact the controller via a form provided on this website. To know who the enquiry is from and to reply to it, the following data is required: email
Processing for the purpose of contacting the controller is based on Art. 6(1) sentence 1(a) GDPR, on the basis of consent freely given.
Personal data collected through use of the contact form is routinely erased once the enquiry has been dealt with.
17. Enquiries by Email or Phone
You may direct enquiries to the controller by email or phone. Any personal data submitted this way (e.g. name, email address, phone number and the enquiry itself) is processed and stored by the controller solely to handle the enquiry and any follow-up questions.
The legal basis for this processing is Art. 6(1)(b) GDPR, as it is necessary to perform a contract or carry out pre-contractual steps. Where processing is not related to a contract, it is based on Art. 6(1)(f) GDPR, as the controller has a legitimate interest in handling and answering enquiries.
Sending to Existing Customers Without Consent
Newsletters are sent to existing customers even without their express consent under certain conditions. This is permitted under Art. 6(1)(f) GDPR where the following conditions are met:
Existing-customer status: the customer provided their email address in connection with the purchase of goods or services. Direct marketing for similar products or services: the newsletter only advertises the controller's own similar products or services. Notice of the right to object: the customer was clearly informed, both when the email address was collected and in every newsletter, that they may object to its use at any time at no cost beyond basic transmission fees. No objection raised: the customer has not objected to the use of their email address.
This type of newsletter is sent on the basis of the controller's legitimate interest in informing existing customers about similar products or services and maintaining the business relationship. Processing is based on Art. 6(1)(f) GDPR. Customers may of course object to this use of their email address at any time. An informal email to the controller, or the "unsubscribe" link in the newsletter, is sufficient.
18. Use of Analytics and Tracking Tools
Analytics and tracking tools are used to ensure this website is designed to meet demand and continuously optimised. These measures help record use of the website statistically, so the offering can be optimised for you. Storage and analysis of the data is based on Art. 6(1) sentence 1(f) GDPR, as the provider has a legitimate interest in offering an appealing, functional website.
Where relevant consent has been obtained, processing is additionally based on Art. 6(1) sentence 1(a) GDPR and Sec. 25(1) TTDSG, where consent covers storing cookies or accessing information on the user's device (e.g. device fingerprinting). This consent may be withdrawn at any time.
19. Form Tools
Here you will find information on the use of form tools on this website, including details on the processing of personal data and your rights in connection with using these forms.
These tools are used on the basis of the legitimate interest under Art. 6(1)(f) GDPR in efficient data collection and management. Where required, processing is based on your consent under Art. 6(1)(a) GDPR and Sec. 25(1) TTDSG. Consent may be withdrawn at any time with effect for the future.
Payment
You can pay for your purchases using the following payment service: _________
20. Google Fonts
This website uses Google Fonts, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This service provides fonts supplied by Google to improve the visual design of this website.
To protect your data, Google Fonts are hosted locally on our own server. This means no connection is made to Google's servers, and your IP address is not transmitted to Google. Your data stays entirely on the controller's server and is not shared with third parties.
21. Captcha
This website uses a captcha service to secure the online forms and ensure they are filled in by real users, not bots. This is provided by a third party, which may process personal data when you use its service.
Your data is processed under Art. 6(1)(b) GDPR to perform the contract, in particular to secure the online forms, and in the legitimate interest of a safe user experience under Art. 6(1)(f) GDPR. Where your consent is required for certain actions, processing is based on Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.
Detailed information on the captcha service follows below:
Google reCAPTCHA
Google reCAPTCHA is used to ensure form submissions come from real users. Google reCAPTCHA is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Visiting a page with embedded Google reCAPTCHA establishes a connection to Google's servers. Personal data such as your IP address and your interactions with the captcha may be transmitted to Google.
Google is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for transfers of personal data from the EU to the US. More on the EU-US DPF is available at: https://www.dataprivacyframework.gov. More on how Google reCAPTCHA processes your personal data can be found in Google's privacy policy: https://policies.google.com/privacy.