Data protection
We are very pleased that you are interested in our organization. The protection of your personal data is of particular importance to our management.
You can use our websites without disclosing any personal data to us. However, if you wish to use more specific services offered through our websites, other websites, applications, and social media pages operated by us, we may need to process your personal data.
If we wish to process data about you and cannot rely on any other legal basis, we will always ask for your consent first (e.g., via a cookie banner).
We always comply with applicable data protection laws when handling your personal data (such as your name, address, email address, or phone number). This data protection statement informs you about the data we process. It also explains the rights you have as a data subject.
We have implemented various technical and organizational measures to protect your data on our websites as effectively as possible. Nevertheless, there are always risks associated with the Internet, and complete protection is not possible. Therefore, if you prefer, you can also provide us with your personal data through other channels, such as by phone.
This data protection is not only intended to fulfill the obligations under the GDPR and to comply with the laws of the member states of the European Union (EU) and the European Economic Area (EEA). This data protection is also intended to ensure compliance with legal requirements such as those of the United Kingdom (UK-GDPR), the Swiss Federal Act on Data Protection and the Swiss Data Protection Ordinance (DSG, DSV), the California Consumer Privacy Act (CCPA/CPRA), China’s Personal Information Protection Law (PIPL), the Delaware Personal Data Privacy Act (DPDPA), the Tennessee Information Protection Act (TIPA), the Minnesota Consumer Data Privacy Act (MCDPA), the Iowa Act Relating to Consumer Data Protection (ICDPA), the Maryland Online Data Privacy Act (MODPA), the Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696), and other global data protection regulations, and shall be interpreted accordingly. The following data protection shall be interpreted for each country, state, or province such that the terms and legal bases used correspond to the terms and legal bases used in the respective state or province.
To improve readability, we do not use gender-specific terms (male, female, diverse, and other gender identities) on our website, in our publications, in our communications, or in our Privacy Policy. All wording used applies equally to all genders.
If you have any suggestions for improving the text in this Privacy Policy, or if you need an external data protection officer, please contact the author of the text: Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E..
1. Definitions
In our data protection, we use specific terms from various data protection laws. We want our policy to be easy to understand, so we’ll explain these terms first.
The following definitions are based, where applicable, on the case law of the General Court of the European Union (GCEU), the Court of Justice of the European Union (CJEU), the Swiss Federal Supreme Court (BGE), the Supreme Court of the United Kingdom (UKSC), or in light of national data protection laws or national case law of a state or federal state, including but not limited to California, including judicial precedent, including under common law, if this is necessary for the application of the law in a specific case.
In this data protection, we use the following terms, among others:
a) personal data
Personal data refers to any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject” where applicable). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person, or who must be regarded as such under national data protection laws or the national case law of a state or federal state, including judicial precedent, even under common law.
b) data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the controller, a processor, an international organization, or another data recipient, as well as persons who must be regarded as such under national data protection laws or the national case law of a country or state, including judicial precedents, even under common law.
c) Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of disclosure, the comparison or linking, the restriction, erasure, or destruction.
d) Restriction of processing
Restriction of processing refers to the marking of stored personal data with the aim of limiting its future processing.
e) Profiling
Profiling is any form of automated processing of personal data that involves using such data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning the natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
f) Pseudonymization
Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures that ensure the personal data is not attributed to an identified or identifiable natural person.
g) Data controller
The controller is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for by Union law or the law of the Member States.
h) Data processor
A data processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the data controller.
i) Recipient
A recipient is a natural or legal person, public authority, agency, or other body to whom personal data is disclosed, regardless of whether or not that entity is a third party. However, public authorities that may receive personal data in the course of a specific investigative mandate under Union law or the law of the Member States are not considered recipients.
j) Third party
Third party means a natural or legal person, public authority, agency, or other body other than the data subject, the controller, the processor, and the persons authorized to process the personal data under the direct responsibility of the controller or the processor.
k) Consent
Consent means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.
2. Name and address of the data controller
The data controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the member states of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), California data protection laws (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and other provisions relating to data protection, is:
Training Base Weeze GmbH & Co. KG
Flughafen-Ring 16
47652 Weeze
Germany
Phone: 0160 975354039
Email: datenschutzbeauftragter@tb-weeze.de
Website: https://www.tb-weeze.com
3. Name and contact information of the data protection officer
Mr. Thorsten Damm
c/o Holz+ Kunststoff Association
Bierstadter Straße 39
65189 Wiesbaden
Germany
Phone: 0611 17360
Email: datenschutzbeauftragter@vhk.de
Collection of General Data and Information
Our websites collect a range of general data and information each time a data subject or an automated system accesses the websites. This general data and information is stored in the log files of the respective server. The data collected may include, among other things, (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our websites (known as the referrer), (4) the subpages of our websites accessed via an accessing system, (5) the date and time of access to the website, (6) an Internet Protocol (IP) address, (7) the Internet service provider of the accessing system, and (8) other similar data and information used to prevent threats in the event of attacks on our information technology systems.
We do not use this general data and information to draw any conclusions about the data subject. Rather, this information is needed to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising on them, (3) ensure the ongoing functionality of our information technology systems and the technology of our websites, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack. We therefore evaluate this anonymously collected data and information both for statistical purposes and with the aim of enhancing data protection and data security within our company, ultimately to ensure an optimal level of protection for the personal data we process. The data from the server log files is stored separately from any personal data provided by a data subject.
The purpose of the processing is to prevent threats and ensure IT security, as well as the purposes mentioned above. The legal basis is Article 6 (1) (f) of the GDPR. Our legitimate interest is, in particular, the protection of our information technology systems. The log files are deleted once the specified purposes have been achieved.
4. Contact options via the website and other data transmissions, and your consent
Our websites contain information that enables users to quickly contact our company electronically and communicate directly with us, including a general electronic mail (email) address and, where applicable, a phone number. If a data subject contacts us via email, a contact form, an input form, or by other means, the personal data transmitted by the data subject is automatically stored. Such personal data, which is provided to us by a data subject on a voluntary basis, is processed for the purposes of handling the request or contacting the data subject.
We obtain your consent for the transmission, storage, and processing of your contact information and inquiries, as well as for contacting you, in accordance with Article 6 (1) (a) of the GDPR and Article 49 (1) (1) (a) of the GDPR, as follows:
By submitting your personal data, you voluntarily consent to the processing of the personal data you have entered or submitted for the purposes of handling your inquiry and establishing contact. By submitting your data to us, you also voluntarily grant your explicit consent pursuant to Art. 49 (1) (1) (a) of the GDPR for data transfers to third countries to and by the companies and for the purposes specified in this Privacy Policy, in particular for such transfers to third countries for which an EU/EEA adequacy decision may or may not exist, as well as to companies or other entities that are not covered by an existing adequacy decision based on self-certification or other eligibility criteria, and in or for which there are significant risks and no suitable safeguards for the protection of your personal data (e.g., due to Section 702 of the FISA, Executive Order EO 12333, and the Cloud Act in the United States). When you provided your voluntary and explicit consent, you were aware that third countries may not provide an adequate level of data protection and that your rights as a data subject may not be enforceable in such cases. You may revoke your consent under data protection law at any time with future effect. Revoking your consent does not affect the lawfulness of processing carried out on the basis of your consent prior to revocation. With a single action (entering and submitting your information), you are providing multiple consents. These include consents under EU/EEA data protection law as well as those under the CCPA/CPRA, the ePrivacy Directive, the German Telemedia Act, and other international legal provisions that are required, among other things, as the legal basis for any planned further processing of your personal data. By taking this action, you also confirm that you have read and understood this data protection policy.
5. Routine deletion and restriction of personal data
We process and store personal data for the period necessary to achieve the purpose of the processing, or to the extent provided for by the European legislative bodies or other legislative bodies in laws or regulations to which we are subject, or for as long as a legal basis for the processing exists.
If the purpose of the processing no longer applies, if a retention period prescribed by European legislative bodies or other competent legislative bodies expires, or if the legal basis for the processing no longer applies, the personal data will be restricted or deleted routinely and in accordance with legal requirements.
6. Rights of the data subject under the GDPR
A) Right of confirmation
Every data subject has the right to request confirmation from the controller as to whether personal data concerning them is being processed.
If a data subject wishes to exercise this right, they may contact us at any time.
b) Right of access
Every data subject has the right to obtain, at any time and free of charge, information from the controller regarding the personal data stored about them, as well as a copy of that data. Furthermore, European legislation (directives and regulations) grants data subjects the right to receive the following information:
- the purposes of processing,
- the categories of personal data that are processed,
- the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations,
- if possible, the planned period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period,
- the existence of a right to have personal data concerning them rectified or erased, or to have the processing restricted by the controller, or a right to object to such processing,
- the existence of a right to file a complaint with a supervisory authority,
- if the personal data is not collected from the data subject: All available information regarding the origin of the data,
- the existence of automated decision-making, including profiling, pursuant to Article 22 (1) and (4) of the GDPR; and—at least in such cases—meaningful information about the logic involved, as well as the scope and intended effects of such processing on the data subject.
Furthermore, the data subject has the right to be informed whether personal data has been transferred to a third country or to an international organization. If this is the case, the data subject also has the right to be informed of the appropriate safeguards in connection with the transfer.
If a data subject wishes to exercise this right, they may contact us at any time.
c) Right of correction
Every data subject has the right to request the immediate rectification of inaccurate personal data concerning him or her. Furthermore, the data subject has the right to request that incomplete personal data be completed—including by means of a supplementary statement—taking into account the purposes of the processing.
If a data subject wishes to exercise this right, they may contact us at any time.
d) Right to erasure (right to be forgotten)
Every data subject has the right to request that the controller erase personal data concerning him or her without delay, provided that one of the following grounds applies and the processing is not necessary:
- The personal data was collected or otherwise processed for purposes for which it is no longer necessary.
- The data subject withdraws their consent on which the processing was based pursuant to Article 6 (1) (a) of the GDPR or Article 9 (2) (a) of the GDPR, and there is no other legal basis for the processing.
- The data subject objects to the processing pursuant to Article 21 (1) of the GDPR, and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21 (2) of the GDPR.
- The personal data was processed unlawfully.
- The erasure of personal data is necessary to comply with a legal obligation under Union law or the law of the Member States to which the controller is subject.
- The personal data was collected in connection with the information society services offered, in accordance with Article 8 (1) of the GDPR.
If any of the reasons listed above apply and a data subject wishes to request the deletion of personal data stored by us, they may contact us at any time.
If we have made the personal data public and our organization, as the controller, is obligated under Article 17 (1) of the GDPR to erase the personal data, we will take appropriate measures, including technical measures, taking into account the available technology and the costs of implementation, to inform other controllers who process the published personal data that the data subject has requested that these other controllers delete all links to such personal data or copies or replicas of such personal data, provided that the processing is not necessary.
e) Right of restriction of processing
Every data subject has the right to request that the controller restrict processing if any of the following conditions are met:
- The data subject disputes the accuracy of the personal data for a period that allows the controller to verify the accuracy of the personal data.
- The processing is unlawful; the data subject objects to the erasure of the personal data and instead requests that the use of the personal data be restricted.
- The controller no longer needs the personal data for the purposes of processing, but the data subject needs it to assert, exercise, or defend legal claims.
- The data subject has objected to the processing pursuant to Article 21 (1) of the GDPR, and it has not yet been determined whether the controller’s legitimate interests outweigh those of the data subject.
If any of the above conditions are met and a data subject wishes to request the restriction of personal data stored by us, they may contact us at any time.
f) Right of data portability
Every data subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format. The data subject also has the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that the processing is based on consent pursuant to Art. 6 (1) (a) of the GDPR or Art. 9 (2) (a) of the GDPR or on a contract pursuant to Article 6 (1) (b) of the GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Furthermore, when exercising their right to data portability under Article 20 (1) of the GDPR, the data subject has the right to have their personal data transmitted directly from one controller to another, provided that this is technically feasible and does not infringe upon the rights and freedoms of others.
If a data subject wishes to exercise this right, they may contact us at any time.
g) Right of objection
Every data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them that is carried out pursuant to Article 6 (1) (e) or (f) of the GDPR. This also applies to profiling based on these provisions.
We will no longer process personal data in the event of an objection, unless we can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or the processing is necessary for the establishment, exercise, or defense of legal claims.
If we process personal data for the purpose of direct marketing, the data subject has the right to object at any time to the processing of personal data for such marketing purposes. This also applies to profiling to the extent that it is related to such direct marketing. If the data subject objects to the processing for direct marketing purposes, we will no longer process the personal data for these purposes.
In addition, the data subject has the right to object, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her that we carry out for scientific or historical research purposes or for statistical purposes in accordance with Article 89 (1) of the GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.
If a data subject wishes to exercise this right, they may contact us at any time. The data subject is also free, in connection with the use of information society services, notwithstanding Directive 2002/58/EC, to exercise their right to object through automated means using technical specifications.
h) Automated decisions in individual cases, including profiling
Every data subject has the right not to be subject to a decision based solely on automated processing—including profiling—that produces legal effects concerning the data subject or similarly significantly affects the data subject, unless the decision (1) is necessary for entering into or performing a contract between the data subject and the controller, or (2) is authorized by Union or Member State law to which the controller is subject, and that law provides for appropriate measures to safeguard the data subject’s rights and freedoms as well as legitimate interests; or (3) is based on the data subject’s explicit consent.
If the decision (1) is necessary for the conclusion or performance of a contract between the data subject and the controller, or (2) is it made with the data subject’s explicit consent, we will take appropriate measures to safeguard the data subject’s rights and freedoms as well as their legitimate interests, including, at a minimum, the right to request human intervention by the controller, to present their point of view, and to challenge the decision.
If a data subject wishes to exercise this right, they may contact us at any time.
i) Right to withdraw consent under data protection law
Every data subject has the right to withdraw consent to the processing of personal data at any time.
If a data subject wishes to exercise this right, they may contact us at any time.
7. General purpose of the processing, categories of data processed, and categories of recipients
The general purpose of processing personal data is to handle all matters relating to the data controller, customers, prospective customers, business partners, or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense), or the data controller’s legal obligations. This general purpose applies unless more specific purposes are stated for a particular processing activity.
The categories of personal data we process are customer data, prospect data, employee data (including applicant data), and supplier data. The categories of recipients of personal data are public authorities, external entities, internal processing, intra-group processing, and other entities.
A list of our data processors and data recipients in third countries, as well as any international organizations, is either published on our website or can be requested from us free of charge.
8. Legal basis for data processing
Article 6 (1) (a) of the GDPR serves as the legal basis for processing operations in which we obtain consent for a specific purpose of processing. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party—as is the case, for example, with processing operations required for the delivery of goods or the provision of other services or consideration—the processing is based on Article 6 (1) (b) of the GDPR. The same applies to processing operations necessary for the implementation of pre-contractual measures, such as in cases of inquiries regarding our products or services. If we are subject to a legal obligation that requires the processing of personal data—such as to fulfill tax obligations—the processing is based on Article 6 (1) (c) of the GDPR.
In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were injured on our premises and, as a result, their name, age, health insurance information, or other vital information had to be disclosed to a doctor, a hospital, or other third parties. In such cases, the processing would be based on Article 6 (1) (d) of the GDPR.
If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, the legal basis is Article 6 (1) (e) of the GDPR.
Ultimately, processing operations may be based on Article 6 (1) (f) of the GDPR. This legal basis applies to processing operations not covered by any of the aforementioned legal bases, provided that the processing is necessary to safeguard a legitimate interest of our company or a third party, unless the interests, fundamental rights, and fundamental freedoms of the data subject override those interests. We are permitted to carry out such processing operations in particular because they were specifically mentioned by the European legislator. In this regard, the legislator took the view that a legitimate interest could be presumed, for example, if the data subject is a customer of the controller (Recital 47, sentence 2 of the GDPR).
9. Legitimate interests in processing pursued by the controller or a third party, and direct marketing
If the processing of personal data is based on Article 6 (1) (f) of the GDPR, and no more specific legitimate interests are specified, our legitimate interest is the conduct of our business operations for the benefit of our employees and shareholders.
We may send you direct marketing messages regarding our own products or services that are similar to the products or services you have inquired about, ordered, or purchased. You may opt out of direct marketing at any time (e.g., by email). You will not incur any costs other than the transmission costs charged at standard rates. The processing of personal data for direct marketing purposes is based on Article 6 (1) (f) of the GDPR. The legitimate interest is direct marketing.
Our news updates and newsletters may also constitute communications for direct marketing purposes within the meaning of Article 13(2) of EU Directive 2002/58 (Electronic Communications Privacy Directive) and the national law resulting from that directive, provided that we have received your electronic and other contact information in connection with the sale of a service or product—including the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we use direct marketing to promote similar products or services, so that direct marketing is permitted even without consent (see ECJ, judgment of Nov. 13, 2025, Case C-654/23). In such cases, you may object to the use of your contact information at any time, free of charge.
10. Length of time for which personal data is stored
The criterion for the duration of personal data storage is the applicable statutory retention period. If no statutory retention period exists, the criterion is the contractual or internal retention period. Once the period has expired, the relevant data is routinely deleted, provided it is no longer necessary for the performance or initiation of a contract. This applies in particular to all processing operations for which no more specific criteria have been established.
11. Legal or contractual requirements regarding the provision of personal data; necessity for the conclusion of the contract; the data subject’s obligation to provide personal data; possible consequences of failure to provide such data
We would like to inform you that the provision of personal data is, in some cases, required by law (e.g., tax regulations) or may also arise from contractual provisions (e.g., information about the contracting party). In some cases, it may be necessary for a data subject to provide us with personal data in order to conclude a contract, which we must then process. For example, the data subject is obligated to provide us with personal data when our organization enters into a contract with them. Failure to provide the personal data would mean that the contract with the data subject could not be concluded. Before providing personal data, the data subject must contact us. We inform the data subject on a case-by-case basis whether the provision of personal data is required by law or contract, or is necessary for the conclusion of the contract; whether there is an obligation to provide the personal data; and what the consequences of failing to provide the personal data would be.
12. Existence of automated decision-making
As a responsible company, we generally do not use automated decision-making or profiling. If, in exceptional cases, we do use automated decision-making or profiling, we will inform the data subject either separately or through a section in our Privacy Policy (available here on our website). In this case, the following applies:
Automated decision-making, including profiling, may occur if (1) it is necessary for the conclusion or performance of a contract between the data subject and us, or (2) it is permitted under Union or Member State law to which we are subject, and such law provides for appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject, or (3) it is based on the data subject’s explicit consent.
In the cases specified in Article 22 (2) (a) and (c) of the GDPR, we will take appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject. In these cases, you have the right to request that the controller designate a person to intervene, to state your own position, and to challenge the decision.
Where applicable, this data protection statement provides relevant information about the logic involved, as well as the scope and intended effects of such processing on the data subject.
13. Recipients in a third country and appropriate or adequate safeguards, and how to obtain a copy of them or where they are available
Pursuant to Article 46 (1) of the GDPR, the controller or a processor may transfer personal data to a third country only if the controller or processor has provided appropriate safeguards and provided that the data subjects have enforceable rights and effective legal remedies. Appropriate safeguards may be provided through standard data protection clauses without the need for specific authorization from a supervisory authority, Article 46 (2) (c) of the GDPR.
For all recipients in third countries, the EU Standard Data Protection Clauses or other appropriate safeguards are agreed upon prior to the first transfer of personal data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights, and effective remedies are guaranteed for all processing of personal data. Any data subject may obtain a copy of the Standard Data Protection Clauses or adequacy decisions from us. In addition, the Standard Data Protection Clauses and adequacy decisions are available in the Official Journal of the European Union.
Article 45 (3) of the GDPR authorizes the European Commission to adopt an implementing act determining that a non-EU country ensures an adequate level of protection. This means a level of protection for personal data that is essentially equivalent to the level of protection within the EU. Adequacy decisions allow personal data to flow from the EU (as well as from Norway, Liechtenstein, and Iceland) to a third country without further obstacles. Similar provisions apply to the United Kingdom, Switzerland, and several other countries.
In all cases where the European Commission, or a government or competent authority of another country, has determined that a third country ensures an adequate level of protection and/or that a valid framework exists (e.g., EU-U. S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to members of such frameworks (e.g., self-certified entities) are based exclusively on that entity’s membership in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the respective company’s membership in that framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based exclusively on the respective adequacy decisions.
Any data subject may obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union, in published legislative materials, or on the websites of data protection supervisory authorities or other authorities or institutions.
14. Right to complain to a data protection supervisory authority
As the data controller, we are required to inform the data subject of their right to lodge a complaint with a supervisory authority. This right to lodge a complaint is governed by Article 77 (1) of the GDPR. Under this provision, every data subject has the right to lodge a complaint with a supervisory authority—in particular in the Member State of their residence, their workplace, or the place where the alleged infringement occurred—without prejudice to any other administrative or judicial remedy, if the data subject considers that the processing of personal data concerning them infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislature solely in that it may be exercised only with a single supervisory authority (Recital 141, first sentence, of the GDPR). This provision is intended to prevent duplicate complaints regarding the same matter by the same data subject. Therefore, if a data subject wishes to file a complaint against us, we ask that they contact only a single supervisory authority.
15. Data protection in connection with job applications and the application process
As part of the application process, we collect and process the personal data of applicants. This processing may also be carried out electronically. This is particularly the case when an applicant submits the relevant application documents to us electronically, for example via email or through a web form located on our website or on a third-party website.
For applicant data, the purpose of data processing is to review the application as part of the application process. For this purpose, we process all data you provide. Based on the data submitted as part of your application, we determine whether to invite you to an interview (part of the selection process). Subsequently, in the case of generally suitable applicants, we process certain additional personal data you have provided—particularly during the interview—that is essential to our selection decision.
The legal basis for data processing is Article 6 (1) (b) of the GDPR, Article 9 (2) (b) and (h) of the GDPR, Article 88 (1) of the GDPR, and national laws.
If we do not enter into an employment contract with the applicant, the application documents will be deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests of the data controller preclude such deletion. Other legitimate interests in this context include, for example, the presentation of evidence in legal proceedings.
16. Data protection provisions regarding the use of Borlabs Cookie
Borlabs Cookie is a cookie management tool that we use on our website to enable visitors to manage their use of cookies and online tracking technologies in a transparent and consent-based manner. This tool helps us respect our users’ privacy preferences while complying with the requirements of the General Data Protection Regulation (GDPR) and other local data protection laws. With Borlabs Cookie, users can individually manage their consent to various types of cookies and tracking technologies, enabling a personalized and privacy-compliant web experience.
When using Borlabs Cookie, data such as user cookie preferences and IP addresses are processed to document consent history and implement user settings. This information is essential for complying with legal data protection requirements and provides a basis for consent-based tracking and content personalization.
The operator of the service and, therefore, the recipient of the personal data is: Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to manage consent regarding cookies and tracking technologies on our website. The processing is based on Article 6 (1) (c) of the GDPR in order to comply with the legal requirements for documenting user consent.
The criteria for determining the period for which personal data is processed are the statutory or contractual retention periods. The use of personal data is required by law, as it is necessary to fulfill legal obligations related to data protection and consent management. Users are required to specify their cookie preferences or reject cookies, and this information must be stored to properly document their decision.
Further information and Borlabs Cookie's current privacy policy are available at https://borlabs.io.
17. Subscription to our newsletter and your consent
We regularly inform our customers and business partners about special offers and news via a newsletter. Our website therefore offers you the option to subscribe to our newsletter. The personal data provided to us when you subscribe to the newsletter is determined by the form you fill out. You can generally only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.
For legal reasons, a confirmation email is sent via the double-opt-in procedure to the email address initially provided by a data subject to subscribe to the newsletter. This confirmation email serves to verify whether the owner of the email address, as the data subject, has authorized receipt of the newsletter. The legal basis for sending this double-opt-in confirmation email is Article 6 (1) (c) of the GDPR, as there is a legal obligation to send the newsletter only to recipients who have reconfirmed their consent.
When you subscribe to the newsletter, we also store the IP address assigned by the Internet service provider (ISP) to the Internet connection used by the data subject at the time of registration, as well as the date and time of registration. Storing this data is necessary to be able to trace any (potential) misuse of a data subject’s email address at a later date and therefore serves to provide legal protection for the controller. The legal basis for this processing is also Article 6 (1) (c) of the GDPR.
To collect and store your email address for the purpose of subscribing to our newsletter, we obtain your consent in accordance with Article 6 (1) (a) of the GDPR and Article 49 (1) (1) (a) of the GDPR as follows:
By entering and submitting your personal data, you voluntarily consent to the processing of the personal data you have entered for the purpose of sending you our newsletter. By entering your data and submitting it to us, you also voluntarily grant your explicit consent pursuant to Art. 49 (1) (1) (a) of the GDPR for data transfers to third countries to and by the companies and for the purposes specified in this Privacy Policy, in particular for such transfers to third countries for which an EU/EEA adequacy decision may or may not exist, as well as to companies or other entities that are not covered by an existing adequacy decision based on self-certification or other eligibility criteria, and in or for which there are significant risks and no suitable safeguards for the protection of your personal data (e.g., due to Section 702 of the FISA, Executive Order EO 12333, and the Cloud Act in the United States). When you provided your voluntary and explicit consent, you were aware that third countries may not provide an adequate level of data protection and that your rights as a data subject may not be enforceable in such cases. You may revoke your consent under data protection law at any time with future effect. Revoking your consent does not affect the lawfulness of the processing carried out on the basis of your consent up until the time of revocation. With a single action (entering and submitting your information), you are granting multiple consents. These include consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy, and telemedia law, and other international legal provisions that are required, among other things, as the legal basis for any planned further processing of your personal data. By taking this action, you also confirm that you have read and understood this data protection statement.
You may revoke your consent to the processing of personal data—which you provided to us for the purpose of storing your email address to send you the newsletter—at any time. To revoke your consent, you will find a link for this purpose in every newsletter. You may also notify us of your request to unsubscribe by other means (e.g., by phone).
The personal data collected when you subscribe to the newsletter will be used exclusively for sending our newsletter. Furthermore, newsletter subscribers may be notified by email if this is necessary for the operation of the newsletter service or for registration purposes, such as in the event of changes to the newsletter content or technical changes. Personal data collected as part of the newsletter service will not be disclosed to third parties.
By subscribing to our newsletter, you enter into a contract with us for the delivery of the newsletter; therefore, the processing activities related to its distribution are based on Article 6 (1) (b) of the GDPR as the legal basis. The contract may be terminated at any time.
As Newsletter Software Newsletter2Go is used. Your data will be transmitted to Newsletter2Go GmbH. Newsletter2Go is prohibited from selling and using your data for purposes other than sending newsletters. Newsletter2Go is a German, certified provider, which was selected according to the requirements of the General Data Protection Regulation and the Federal Data Protection Act.
Further information can be found here: https://www.newsletter2go.co.uk/information-for-newsletter-recipients/?_ga=2.2629616.1352889904.1527085437-1286840444.1511896030
18. Data protection provisions regarding the use and application of IONOS
IONOS is a company that provides web hosting and domain services. As a provider in this field, IONOS not only provides the technical infrastructure for our online presence but also offers a range of related services, such as email hosting, SSL certificates, and data backup. When using IONOS, various types of data are processed, particularly data collected during domain registration, such as the domain owner’s name, contact information, and technical details about the domain.
In addition, IONOS collects data on website traffic to ensure IT security and defend against attacks, such as DDoS attacks. This information may include IP addresses, timestamps, and pages accessed. This data is processed to provide and optimize hosting services, ensure network and information security, and improve the user experience on our website.
The operator of the service and, therefore, the recipient of the personal data is: IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The representative under UK national law is: IONOS Cloud Limited, 2 Cathedral Walk, The Forum, Gloucester, GL1 1AU, United Kingdom.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is the use of web hosting services and related services. The processing is based on Article 6 (1) (f) of the GDPR. The legitimate interest lies in the reliable and secure provision of our website and the associated services.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
Further information and IONOS SE's current privacy policy are available at https://www.ionos.de.
19. Data protection provisions regarding the use and application of WooCommerce Multilingual & Multicurrency with WPML
WooCommerce Multilingual & Multicurrency with WPML is a WordPress plugin that enables WooCommerce stores to operate in multiple languages and currencies. This plugin allows online merchants to offer their products and services in different languages and currencies, thereby improving their reach and accessibility to an international audience. The plugin does not store any personal data of website visitors; rather, it processes information such as language settings and currency preferences that are necessary for the extended functionality of WooCommerce. However, the language used allows one to infer that a data subject speaks a specific language, which is why personal data is processed.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which the personal data is to be processed, as well as the legal basis for the processing: The purpose of using WooCommerce Multilingual & Multicurrency with WPML is to extend WooCommerce’s functionality with multilingual and multicurrency features in order to reach a broader, international audience. The processing is based on Article 6 (1) (f) of the GDPR, whereby the legitimate interest lies in marketing to an international market and improving user-friendliness.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for entering into a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, features, or the plugin.
More information about WooCommerce Multilingual & Multicurrency with WPML is available at WordPress.org.
20. Data protection provisions regarding the use and application of Facebook
Facebook is a social network that allows people to connect online, share content, and communicate. Users can create profiles, post photos and videos, exchange messages, and organize themselves into groups. Facebook also provides businesses and organizations with a platform for advertising and interacting with their target audience.
When using Facebook, personal data such as names, email addresses, phone numbers, usage data, location information, and information about shared content is processed. This data is necessary to provide the platform, offer personalized content and advertising, ensure user safety, and develop new services.
The operator of the service and, therefore, the recipient of the personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and the EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as the point of contact and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent’s Place, London, NW1 3FG, United Kingdom.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to use and improve social networking features and network services. The processing is based on Article 6 (1) (b) of the GDPR for the performance of a contract to which the data subject is a party, as well as on Article 6 (1) (f) of the GDPR, where the legitimate interest lies in improving the user experience, providing personalized content and advertising, and ensuring the security of the network.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards as specified in Article 46 (2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. For more information, please visit https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
Further information and Facebook's current privacy policy can be found at https://facebook.com.
21. Data protection provisions regarding the use and application of Instagram
Instagram is a widely used social network that allows users to share photos and videos, post Stories, and interact with followers and friends. Instagram offers a variety of features, including direct messages, IGTV for longer videos, Instagram Live for real-time broadcasts, and an Explore page for discovering new content and users.
When using Instagram, personal data such as names, email addresses, phone numbers, user-generated content (photos, videos, comments, etc.), location data, usage information, and, in some cases, payment information is processed. This data helps provide the service, ensure the security of the platform, deliver personalized advertising, and improve the user experience.
The operator of the service and, therefore, the recipient of the personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and the EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as the point of contact and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent’s Place, London, NW1 3FG, United Kingdom.
Purposes for which the personal data is to be processed, as well as the legal basis for the processing: The purpose of the processing is to use and optimize social networking features. The processing is based on Article 6 (1) (b) of the GDPR for the performance of a contract to which the data subject is a party, as well as on Article 6 (1) (f) of the GDPR, whereby the legitimate interest lies in improving and personalizing the user experience, providing customer support, ensuring the security and integrity of the platform, as well as in the use of the platform and marketing.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards as specified in Article 46 (2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. For more information, please visit https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Instagram's current data protection policies, visit https://instagram.com.
22. Data protection provisions regarding the use and application of LinkedIn
LinkedIn is a social network for professional connections and career development. The platform allows users to create a professional profile, connect with colleagues, business partners, and potential employers, share professional experiences and skills, and stay informed about industry news. LinkedIn also offers tools for companies and recruiters to search for talent, post job listings, and build a brand presence.
When using LinkedIn, personal data such as names, email addresses, job titles and work experience, educational background, skills, interests, and platform usage data are processed. This information is necessary to provide and use the service, create networking opportunities, present personalized content and job offers, and ensure the security of user data.
The operator of the service and, therefore, the recipient of the personal data is: LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
Purposes for which the personal data is to be processed, as well as the legal basis for the processing: The purpose of the processing is to use and optimize network and career services. The processing is based on the user’s consent (Art. 6 (1) (a) GDPR), the performance of a contract (Art. 6 (1) (b) the GDPR), to which the data subject is a party, as well as on legitimate interests (Art. 6 (1) (f) of the GDPR), such as marketing and recruitment.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards as specified in Article 46 (2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. For more information, please visit https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view LinkedIn Corporation's current data protection policies, please visit https://www.linkedin.com.
23. Data protection provisions regarding the use and application of YouTube
YouTube is a platform for sharing and watching videos that is used by individuals, artists, businesses, and media companies to publish a wide variety of content, such as music videos, vlogs, educational material, and much more. YouTube offers users the ability to upload, share, and comment on videos, as well as interact with a broad community.
When using YouTube, personal data such as IP addresses, user interactions (e.g., videos watched, comments), location data (if enabled for services), and information from linked Google accounts is processed. This information is necessary to provide personalized content and advertising, enable user interactions, keep the platform secure, and improve the user experience.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the point of contact and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Article 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the personal data is to be processed, as well as the legal basis for the processing: The purpose of the data processing is the use of video-sharing services. The processing is based on the performance of a contract pursuant to Article 6 (1) (b) of the GDPR, to which the data subject is a party, as well as on legitimate interests pursuant to Article 6 (1) (f) of the GDPR, such as the use of an efficient video platform, the improvement of the user experience, the use of personalized advertising, and the use of embedded videos on our website.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards as specified in Article 46 (2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. For more information, please visit https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and YouTube's current data protection policies, please visit https://policies.google.com.
The privacy policy above was created using a generator based on the expertise of legal advisors specializing in contract lawt, certified data protection officers and the ISO 22301 certification authority.
TRAINING BASE WEEZE
The Training Base Weeze stands for a multidisciplinary training campus. With a total area of over 60 hectares, it is the largest BOS training center of its kind in Europe.
FURTHER INFORMATION
FOLLOW US
© Copyright 2026 | All rights are reserved
