Last updated: 13 July 2026
Table of contents
- Controller
- Overview of processing activities
- Relevant legal bases
- Security measures
- Transfer of personal data
- International data transfers
- Rights of data subjects
- Use of cookies
- Business services
- Payment procedures
- Provision of the online services and web hosting
- Blogs and publication media
- Contact and inquiry management
- Marketing communication via e-mail, post, fax or telephone
- Web analysis, monitoring and optimisation
- Reseller (merchant of record)
Controller
Markus Haberkern
Schronnenäckerstraße 3
74906 Bad Rappenau
Germany
E-mail address: markus(at)weaverpixel.com
Imprint: https://weaverpixel.com/legal/imprint/
Overview of processing activities
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Inventory data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
Categories of data subjects
- Customers.
- Prospective customers.
- Communication partners.
- Users.
- Business and contractual partners.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Contact requests and communication.
- Security measures.
- Direct marketing.
- Web analytics / reach measurement.
- Office and organisational procedures.
- Managing and responding to inquiries.
- Feedback.
- Profiles with user-related information.
- Provision of our online services and user-friendliness.
- Information technology infrastructure.
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission of data and automated individual decision-making, including profiling. Furthermore, the data protection laws of the individual German federal states may apply.
Note on the applicability of the GDPR and the Swiss FADP: This privacy policy serves to provide information pursuant to both the Swiss Federal Act on Data Protection (Swiss FADP) and the General Data Protection Regulation (GDPR). For this reason, please note that the terms of the GDPR are used due to their broader territorial application and comprehensibility. In particular, instead of the terms used in the Swiss FADP – "processing" of "personal data", "overriding interest" and "particularly sensitive personal data" – the terms used in the GDPR, namely "processing" of "personal data", "legitimate interest" and "special categories of data", are used. However, within the scope of the Swiss FADP, the legal meaning of these terms continues to be determined by the Swiss FADP.
Security measures
In accordance with the legal requirements and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access to, entry of, disclosure of, availability of and separation of the data. We have also established procedures to ensure the exercise of data subjects' rights, the erasure of data and responses to data threats. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principles of data protection by design and by default.
Transfer of personal data
In the course of our processing of personal data, the data may be transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Data processing in third countries: If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if processing takes place in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies, this only takes place in accordance with the legal requirements. If the level of data protection in the third country has been recognised by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is otherwise ensured, in particular through standard contractual clauses (Art. 46(2)(c) GDPR), explicit consent or in the case of contractually or legally required transfers (Art. 49(1) GDPR). Furthermore, we will inform you of the bases of third-country transfers with regard to the individual providers from third countries, with adequacy decisions taking precedence as the basis. Information on third-country transfers and existing adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
EU-US Trans-Atlantic Data Privacy Framework: Within the framework of the so-called "Data Privacy Framework" (DPF), the EU Commission has also recognised the level of data protection of certain companies from the USA as adequate in its adequacy decision of 10 July 2023. The list of certified companies and further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/. As part of this privacy policy, we will inform you which of the service providers we use are certified under the Data Privacy Framework.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR, including profiling based on those provisions. Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you are being processed, and to obtain access to this data as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without undue delay or, alternatively, to request restriction of the processing of the data in accordance with the legal requirements.
- Right to data portability: You have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the requirements of the GDPR.
Use of cookies
Cookies are small text files or other storage records that store information on end devices and read information from them – for example, to store the login status of a user account, the contents of a shopping cart in an e-shop, or the content accessed or functions used in an online service. Cookies can also be used for various purposes, e.g. for the functionality, security and convenience of online services and for the analysis of visitor flows.
Information on consent: We use cookies in accordance with the legal requirements. Therefore, we obtain prior consent from users, except where this is not required by law. Consent is not required, in particular, if the storage and reading of information, including cookies, is strictly necessary in order to provide users with a digital service they have expressly requested (i.e. our online services). Strictly necessary cookies generally include cookies with functions relating to the display and operability of the online services, load balancing, security, storage of users' preferences and choices, or similar purposes related to the provision of the main and secondary functions of the online services requested by users. The revocable consent is clearly communicated to users and contains information on the respective cookie usage.
Information on legal bases under data protection law: The legal basis on which we process users' personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is their declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g. in the commercial operation of our online services and the improvement of their usability) or, if this takes place in the context of fulfilling our contractual obligations, if the use of cookies is necessary to fulfil our contractual obligations. We will clarify the purposes for which we process cookies in the course of this privacy policy or as part of our consent and processing procedures.
Storage period: With regard to the storage period, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online service and closed their end device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be saved, or preferred content can be displayed directly when the user visits a website again. Likewise, user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information about the type and storage period of cookies (e.g. as part of obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.
General information on withdrawal and objection (opt-out): Users can withdraw the consent they have given at any time and object to processing in accordance with the legal requirements. Among other things, users can restrict the use of cookies in their browser settings (although this may also limit the functionality of our online services). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Consent (Art. 6(1)(a) GDPR).
Further information on processing procedures and services:
- Processing of cookie data on the basis of consent: We use a cookie consent management procedure, in the context of which users' consent to the use of cookies, or to the processing operations and providers named in the cookie consent management procedure, is obtained and can be managed and withdrawn by users. The declaration of consent is stored so that it does not have to be requested again and so that consent can be proven in accordance with the legal obligation. Storage can take place server-side and/or in a cookie (a so-called opt-in cookie, or with the aid of comparable technologies) in order to be able to attribute the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following applies: consent may be stored for up to two years. A pseudonymous user identifier is created and stored together with the time of consent, information on the scope of the consent (e.g. which categories of cookies and/or service providers) as well as the browser, system and end device used; Legal bases: Consent (Art. 6(1)(a) GDPR).
Business services
We process data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as "contractual partners"), in the context of contractual and comparable legal relationships and associated measures, and in the context of communication with contractual partners (or pre-contractually), e.g. to answer inquiries.
We process this data to fulfil our contractual obligations. These include, in particular, the obligations to provide the agreed services, any update obligations, and remedies in the event of warranty claims and other service disruptions. In addition, we process the data to safeguard our rights and for the purposes of the administrative tasks associated with these obligations and the organisation of our business. Furthermore, we process the data on the basis of our legitimate interests in proper and efficient business management as well as in security measures to protect our contractual partners and our business operations from misuse and from threats to their data, secrets, information and rights (e.g. involving telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the scope of applicable law, we only disclose the data of contractual partners to third parties to the extent necessary for the aforementioned purposes or to fulfil legal obligations. Contractual partners will be informed about further forms of processing, e.g. for marketing purposes, within the scope of this privacy policy.
We inform contractual partners which data are required for the aforementioned purposes before or in the course of data collection, e.g. in online forms, by means of special markings (e.g. colours) or symbols (e.g. asterisks or similar), or in person.
We delete the data after the expiry of statutory warranty and comparable obligations, i.e. generally after four years, unless the data are stored in a customer account, e.g. for as long as they must be retained for legal archiving reasons. The statutory retention period is ten years for documents relevant under tax law as well as for commercial books, inventories, opening balance sheets, annual financial statements, the work instructions required to understand these documents and other organisational documents and accounting records, and six years for received commercial and business letters and copies of dispatched commercial and business letters. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, the opening balance sheet, the annual financial statements or the management report was prepared, the commercial or business letter was received or dispatched, or the accounting record was created, or the record was made or the other documents were created.
Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between the users and the providers.
- Types of data processed: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. e-mail, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Customers; prospective customers. Business and contractual partners.
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; security measures; contact requests and communication; office and organisational procedures. Managing and responding to inquiries.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing procedures and services:
- Shop and e-commerce: We process our customers' data to enable them to select, purchase or order the chosen products, goods and associated services, as well as their payment and delivery or performance. If required for the fulfilment of an order, we use service providers, in particular postal, freight and shipping companies, to carry out the delivery or performance for our customers. For the processing of payment transactions, we use the services of banks and payment service providers. The required information is marked as such in the context of the order or comparable purchase process and includes the information required for delivery or provision and invoicing as well as contact information in order to be able to make any necessary contact; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Payment procedures
In the context of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and use banks, credit institutions and other service providers for this purpose (collectively, "payment service providers").
The data processed by the payment service providers includes inventory data such as name and address, bank data such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, amount and recipient-related information. This information is required to carry out the transactions. However, the data entered is only processed by the payment service providers and stored with them. This means that we do not receive any account- or credit card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers may transmit the data to credit agencies. The purpose of this transmission is to check identity and creditworthiness. In this regard, we refer to the terms and conditions and privacy notices of the payment service providers.
The terms and conditions and privacy notices of the respective payment service providers apply to payment transactions and can be accessed on their respective websites or transaction applications. We also refer to these for further information and for asserting rights of withdrawal, access and other data subject rights.
- Types of data processed: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Customers. Prospective customers.
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Provision of the online services and web hosting
We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or end device.
- Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing procedures and services:
- Collection of access data and log files: Access to our online services is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to avoid server overload (particularly in the case of abusive attacks, so-called DDoS attacks) and, on the other hand, to ensure server utilisation and stability; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Erasure of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes are exempt from erasure until the respective incident has been finally resolved.
Blogs and publication media
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data are processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. For the rest, we refer to the information on the processing of visitors to our publication medium within the scope of this privacy policy.
- Types of data processed: Inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; feedback (e.g. collecting feedback via online form). Provision of our online services and user-friendliness.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Contact and inquiry management
When contacting us (e.g. by post, contact form, e-mail, telephone or via social media) and in the context of existing user and business relationships, the details of the inquiring persons are processed insofar as this is necessary to answer the contact inquiries and any requested measures.
- Types of data processed: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Communication partners.
- Purposes of processing: Contact requests and communication; managing and responding to inquiries; feedback (e.g. collecting feedback via online form). Provision of our online services and user-friendliness.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Further information on processing procedures and services:
- Contact form: If users contact us via our contact form, e-mail or other communication channels, we process the data communicated to us in this context in order to deal with the communicated matter; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
Marketing communication via e-mail, post, fax or telephone
We process personal data for the purposes of marketing communication, which may take place via various channels, such as e-mail, telephone, post or fax, in accordance with the legal requirements.
Recipients have the right to withdraw any consent given at any time or to object to marketing communication at any time.
After withdrawal or objection, we store the data required to prove the previous authorisation to contact or send communications for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is limited to the purpose of a possible defence against claims. On the basis of our legitimate interest in permanently observing the withdrawal or objection of users, we also store the data required to avoid renewed contact (e.g. depending on the communication channel, the e-mail address, telephone number, name).
- Types of data processed: Inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (e.g. by e-mail or post).
- Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Web analysis, monitoring and optimisation
Web analysis (also referred to as "reach measurement") is used to evaluate the visitor flows of our online services and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognise at what time our online services or their functions or content are most frequently used or invite repeat use. We can also understand which areas require optimisation.
In addition to web analysis, we may also use testing procedures, e.g. to test and optimise different versions of our online services or their components.
Unless otherwise stated below, profiles, i.e. data aggregated for a usage process, may be created for these purposes, and information may be stored in a browser or end device and read from it. The information collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data by us or by the providers of the services we use, location data may also be processed.
Users' IP addresses are also stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear user data (such as e-mail addresses or names) are stored in the context of web analysis, A/B testing and optimisation, but pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
- Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors). Profiles with user-related information (creation of user profiles).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: Consent (Art. 6(1)(a) GDPR).
Further information on processing procedures and services:
- Matomo (self-hosted): Matomo is software used for the purposes of web analysis and reach measurement. We operate Matomo on our own server (self-hosted); the data collected are therefore processed exclusively by us and are not shared with third parties. When Matomo is used, cookies are created and stored on the user's end device. The cookies are stored for a maximum period of 13 months: https://matomo.org/faq/general/faq_146/; Legal bases: Consent (Art. 6(1)(a) GDPR). Erasure of data: The cookies have a storage period of a maximum of 13 months.
Reseller (merchant of record)
Our ordering process is handled by our online reseller Elements Platform Ltd, acting as merchant of record for all orders placed through our website. The reseller carries out the ordering process, payment processing and invoicing as an independent controller and handles all related customer inquiries and returns. In this context, the reseller processes, in particular, inventory data (e.g. names, addresses), payment data and contract data. We are offering a 30-day money-back guarantee. The refund is limited to these 30 days and cannot be extended.
For more information about privacy at Elements Platform Ltd, please see their privacy policy at: [LINK TO ELEMENTS PLATFORM LTD PRIVACY POLICY].
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke