GDPR-Report

Results found by automated analysis

All information provided without guarantee, as it is determined fully automatically. No liability for data protection texts.

http://www.demo-only.com
↪️
Redirect to: https://www.demo-only.com
⚠️️

Findings: Clear violation of the General Data Protection Regulation

Indicators

Cookies
Tracking
Critical tools
External files
SSL
🔍
For Your Website

Get Your Own Website Checked

This is a sample report. Get the same comprehensive privacy check for your own website and protect yourself from costly warnings.

  • Automatic analysis of your website
  • privacy texts for your tools
  • Concrete action recommendations
  • Cookie analysis & SSL check included
🚀 Check My Website Now
Over 50,000 websites checked
One-time only €15 plus VAT
✓ Start immediately ✓ Report in no time ✓ No recurring costs

Screenshots of the website

The screenshots show a snapshot of the website after it has loaded. For websites that display content with a time delay, the screenshots may not show all of the content.

PDF

Privacy report: Read view

Download full report as PDF

Table Of Contents

Action Instructions

Overview of recommended measures. Further details on the recommendations can be found below.

1

Tracker: Ask for consent

Consent must be requested for trackers before they are loaded. Likewise, an opt-out option must be provided.

🔍 Found Tracking tools:
YouTube VideoGoogle Tag ManagerFacebook ConnectGoogle SchriftartenFacebook PixelGoogle Ads Remarketing für Google AnalyticsGoogle Safeframe (Google Ad Services)
To the action recommendations →
2

Check the cookies

Please check whether the cookies that have been set are technically necessary. A review is justified for at least8 cookies. Consent must be obtained for all non-necessary cookies.

To the list of cookies →
3

Privacy Texts / Privacy Notices

Please ensure that all necessary privacy texts, including tool-specific texts, are present in the privacy notices.

To the privacy notices →
4

Review Contact Forms

Please review the contact forms on the website: They should only request the most necessary data as required fields (data minimization). In addition, a reference to your privacy notice should be present at each form and consent should be requested for the receipt and processing of the form data.

Found Contact Forms →
5

Review Videos

Please check whether the embedded videos are compliant with data protection regulations. Further information can be found in this report.

To the action recommendations →
6

External files

Please check whether the loaded external files are compliant with data protection regulations.

To the list of external files →
7

Review Specific Issues

Please review the issues identified during our expert review.

To the notice →

Important pages

Identified tools

⚠️️

Important

The following tools are loaded without consent! In case a consent tool is in place and the following overview shows critical tools, the consent tool does not work properly.

🔌 YouTube Video [3] Reference Critical
Knowledge article on YouTube Video
🔌 Google Tag Manager [3] Reference Critical ℹ️ Assigning recognized data transfers to the tool fraught with uncertainty
Knowledge article on Google Tag Manager Assigning recognized data transfers to the tool fraught with uncertainty
🔌 Facebook Connect [3] Reference Critical
Knowledge article on Facebook Connect
🔌 Google Schriftarten [3] Reference Critical
Knowledge article on Google Schriftarten
🔌 Facebook Pixel [2] Reference Critical
Knowledge article on Facebook Pixel
🔌 Google Ads Remarketing für Google Analytics [3] Reference Critical
classified as tracker
🔌 Google Safeframe (Google Ad Services) [3] Reference Critical
classified as tracker

Tool recognition legend:

  • [1]Detection via source code analysis, subject to uncertainty; tool may only be loaded after consent has been given.
  • [2]Recognition via cookie, subject to minor uncertainties
  • [3]Detection via evaluation of network traffic (certain loading processes may not be visible in your browser's developer console, but are still taking place)
  • [4]Detection via evaluation of the consent query. The tool will probably only be loaded after consent has been given.
  • [5]Detection via manual inspection

Found Cookies

The following tools are loaded without explicit user consent. In case a cookie consent tool is used, it might not work properly

Printed in red: critical cookies that need to be analyzed manually.
Print in green: are Cookies, which are probably uncritical.

Name
Value
Domain
Lifetime
Presumed Purpose
demo-only.com
Session
Session management
CheckForPermission
demo-only.com
15 minutes
Google Ads Remarketing for Google Analytics
fb.1.1655989552714.1337055417
demo-only.com
3 months
Facebook Pixel
1.1.1820909660.1655989552
demo-only.com
3 months
Google Ads Remarketing for Google Analytics
PENDING+206
demo-only.com
2 years
Q2Dt7WR8qBc
demo-only.com
6 months
YouTube Video
lD0pH50XEnw
demo-only.com
Session
YouTube Video , Session management
AHWqTUm6KeHlbAvEO6gaHm11-O-6sA…
demo-only.com
1 year
Google Ads Remarketing for Google Analytics
WP%20Cookie%20check
demo-only.com
Session
Technically necessary for WordPress Session management

The cookie information must be specified in the privacy policy together with the purpose and type of data collection if critical cookies are involved.

Common findings

🔒

Good: The website uses an SSL certificate.

The SSL certificate ensures that the data of your users is transfered securely.

Information about certificate

  • Issuer: COMODO CA Limited Nr. 3issuer worldwide
  • The issuer of your certificate is seen as trustworthy

  • The certificate is encrypted with a key length of 2048 bits. This is considered sufficient.

SSL-forward works

The website is configured so that accessing the http version redirects to the https version (good).

This was tested by calling up the URL http://www.demo-only.com.

ℹ️

Please click on this URL and see if your browser reports a certificate problem. This can happen even if the basic SSL check was positive. The reason: Modern browsers are constantly tightening the requirements for trustworthy SSL certificates.

📋

Data protection texts found

The following privacy policy texts could be recognized automatically. The recognition works well, but it should never replace a more detailed review.

Server log files
Right to data portability
Legal basis for processing
Right to information
Right of appeal
Lawfulness of processing
Rights of concerned persons
Correction of data
Right of objection
Transfer of data to third parties
Tool: Google Safeframe (Google Ad Services)
Tool: Facebook Connect
Tool: YouTube Video
Tool: Google Fonts
⚠️️

Important privacy policy text may be missing

The check for missing German texts was automated and works quite reliably. Nevertheless, false alarms can occur.

This means that at least one important data protection text is probably missing from the data protection information. This message appears if information about a tool used, an externally loaded resource, or a general, legally required, or recommended data protection text is missing.

You will find sample texts for the privacy notices in this report.

Please check the following texts in particular to ensure that they are correct:

  • Tool: Google Safeframe (Google Ad Services)
  • Tool: Google Ads Remarketing for Google Analytics
  • Tool: Google Tag Manager
⚠️️

Privacy declaration not in website domain

The privacy policy and the website are located in the same main domain, but with and without "www.":

  • Domain of the privacy policy: demo-only.com
  • Website domain: www.demo-only-2.com
This is not ideal, as it means that the online availability of the website and the privacy policy may be disconnected.
We recommend that you keep the privacy policy exactly where your website is located.

Typo3: General recommendations

The website uses Typo3 as its content management system. Typo3 includes special pages for logging in as an administrator or other user and for requesting a new password, among other things.
We recommend linking to the legal notice and privacy policy on these special pages as well.
We also recommend displaying a notice about the use of cookies, as a cookie popup plugin is not executed on these special pages.
These special pages are in particular:

Tip for professionals: Alternatively, you can password-protect these pages at the server level (for example, using .htaccess).

⚠️️

Harmful disclaimer present

Not a privacy issue, but maybe relevant: On the following pages a problematic disclamer is used. You are attempting to exclude liability where this is not permissible. This can lead to legal problems, particularly in the presence of Terms and Conditions (T&C).

⚠️️

Einwilligung notwendig wegen Verwendung von Tracking Tools: Consent required due to use of tracking tools

Consent required due to use of tracking tools

Your website uses tracking cookies or other tracking methods (see the section Cookies found in this report or the section Components found). For this reason, you must display a pop-up query on your website (§ 25 TDDDG or GDPR or Google policy).
Please ensure that the consent prompt does NOT cover the links to your legal notice and privacy policy, as these must be accessible at all times.
The strict interpretation of the GDPR requires that the user's prior consent be obtained before using tracking tools such as Google Analytics or the Facebook Pixel.

Our recommendation:
Check whether you really need the tools you are using and whether externally integrated resources (such as fonts) can be stored locally (this report contains relevant information on this subject). For Google Analytics, use alternatives such as WP Statistics (for WordPress). If you need or want to continue using the tools you have been using, ask your IT service provider to integrate a consent request into your website and only load tracking tools on your website after the user has given their consent.
Furthermore, tools and plugins from corporations such as Google and Facebook should ideally not be integrated, or only after prior consent has been given. This applies in particular to Google Maps, Google fonts, social media plugins, and YouTube videos.
Since the ECJ ruling of July 16, 2020, data transfers to unsafe third countries such as the US have also become very problematic. At present, these data transfers may be legitimate for certified companies. We assume that the agreement between the EU and the US will not be upheld. You would also need to check whether the providers of the plugins you use are certified. Therefore, all tools, fonts, maps, videos, etc. from non-European providers should only be loaded after legally valid user consent has been obtained.

⚠️️

Dynamically loaded resources

Your website loads third party resource by a third party script. This might be a problem as the script is not under your control, but you can be made responsible for what the script does. This is often done via the integrated Google Tag Manager (GTM). We recommend that you no longer use tools like this, partly because they can use cookies (see Investigation into Google Tag Manager)!

📄

Information about the legal notice (according to German law

Please ensure that the following mandatory information about the responsible party in accordance with §5 DDG (Digital Services Act) is included in the legal notice:

  • Company name
  • Address (no P.O. box)
  • Email address
  • VAT ID (if available), but never the tax number
  • If applicable, telephone and fax (e.g., for stock corporations)
  • Information specific to the legal form, such as the managing director and commercial register reference for limited liability companies (GmbHs)

Make sure that this information is NOT interrupted by a section (such as Contact or Service).

🍪

Information on consent requests

Consent requests are often implemented using so-called consent tools. Only use consent tools if you are aware of the risks and know what to do!

Privacy policy texts

⚠️️

Below you will find sample texts without guarantee.

Please insert the texts into your privacy policy in a modified form so that they correspond to the data collection that takes place on and via your website. In the case of analysis products in particular, please check that the links to the opt-out functions correspond to yours.

Be sure to retain your existing individual texts (introduction, information on the DPO, etc.) and eliminate duplicate texts. The automated analysis of the website is only a working aid. Further review by a data protection expert is highly recommended.

Introduction

Introductory text
Thank you for visiting our website. Dealing with your data securely is particularly important for us. That is why we want to provide you with detailed information on how your data is used when you visit our website.

Introduction

Legal basis for processing
Our company uses Article 6 (S. 1) letter a of the GDPR as the legal basis for processing data for which we received permission for a specific processing purpose. If personal data has to be processed in order to comply with a contract for which the contractual partner is the affected person, as is the case, for example, when processing the data required to deliver goods or provide a service for compensation, this processing is based on Article 6 (S. 1) letter b of the GDPR. This also applies for processing that is needed to perform pre-contractual activities, such as enquiries concerning our products or services. If our company is subject to a legal obligation which makes processing personal data necessary, for example to fulfil fiscal obligations, processing is based on Article 6 (S. 1) letter c of the GDPR. In rare cases, processing personal data may be required in order to protect vital interests of the affected person or another private individual, Article 6 (S. 1) letter d of the GDPR. Finally, processing can also be based on Article 6 (S. 1) letter f of the GDPR. This legal basis is used for processing which is not covered by any of the other legal bases if processing is required to uphold a justified interest of our company or a third party to the extent that the affected party’s interests, basic rights and basic freedoms are not more important.

Introduction

Passing on data
Your personal data is not passed on to third parties for any purposes other than those listed below. We only pass on your personal data to third parties if:
  • You have provided your express permission for this according to Article 6 (1) Sentence 1 letter a of the GDPR,
  • Passing this data on according to Article 6 (1) Sentence 1 letter f of the GDPR is required to assert, exercise or defend legal entitlements and there is no reason to assume that you have a more important interest that requires protection for your data not to be passed on,
  • In the event that there is a legal obligation for passing data on according to Article 6 (1) Sentence 1 letter c of the GDPR, as well as
  • this being legally permissible and required for processing contractual relationships with you according to Article 6 (1) Sentence 1 letter b of the GDPR.

Introduction

Rights of affected parties
You have the right:
  • to demand information on your personal data which I process according to Article 15 of the GDPR. In particular, you can demand information on the processing purpose, the category of the personal data, the categories of recipients to whom your data is or will be disclosed, the planned storage period, the existence of a right to correction, deletion, restriction of processing or objection, the existence of a right to complain, the origin of your data to the extent that this was not collected by me, and the existence of automated decision making including profiling and, as the case may be, meaningful information on the details;
  • to demand the immediate correction of incorrect personal data stored by me or the completion of this data according to Article 16 of the GDPR;
  • to demand that your personal data that I have stored be deleted according to Article 17 of the GDPR to the extent that processing is not required to exercise the right to freely express an opinion and the freedom of information, to fulfil a legal obligation, for reasons of public interest, or to assert, exercise or defend against legal claims;
  • to demand that processing of your personal data is restricted according to Article 18 of the GDPR to the extent that you dispute that your data is correct, processing is illegal, you reject the deletion of this data and we no longer require the data, however you need this data to assert, exercise or defend against legal claims or you have filed an objection to processing according to Article 21 of the GDPR;
  • to demand that your personal data which you have provided me with are maintained in a structured, accessible and machine-readable format or that this is passed on to another responsible party according to Article 20 of the GDPR;
  • to revoke any permission you may have granted me with at any time according to Article 7 (3) of the GDPR. This means that we may not continue to process the data that is based on this permission in future, and
  • to file a complaint with a supervisory authority irrespective of any other appeal under administrative law or a judicial remedy according to Article 77 of the GDPR. As a rule, in this regard, you can consult the supervisory body at your usual address or place of work, or the place at which the purported violation took place if the affected person is of the opinion that processing their personal data violates the EU’s general data protection regulation (GDPR).

Introduction

Cookies
Our website uses cookies. A cookie is a dataset which is created when a website is visited and stored on the hard drive of the website user. If the website user calls up our website’s server again, the user’s browser sends the cookie previously received from the website back to the server. This allows the server to evaluate information thus received. Cookies control, for example, certain advertising being shown or can make it easier to navigate a website. In addition, cookies are required to make it possible to operate our website (the legal basis for this is Article 6 (1) letter f of the the GDPR, upholding the website operator’s justified interests - we only use cookies in agreement with Article 5 (1) letter a of the GDPR, that means in line with the principles of “Legality, processing in good faith, transparency”).
If you want to prevent cookies from being used, you can do this by changing the local settings in your Internet browser (for example Internet Explorer, Mozilla Firefox, Opera or Safari).

Introduction

General data collection
If you access our website or call up a file, data concerning this action is stored in a log file on our web server. The following individual items of data can be stored:
  • IP address (if possible this is saved in a disguised version)
  • Domain name of the website from which you came
  • Name of the files called up
  • Date and time these were called up
  • Name of your Internet service provider
  • as well as, as the case may be, the operating system and browser version on your end device
We only save IP addresses for reasons of data security in order to ensure the stability and security of our system (legal basis: Article 6 (1) letter f of the the GDPR). We reserve the right to analyse statistics for disguised data records.

Introduction

Contact forms
If you send us enquiries using our contact form, your information on the contact form including the contact data you state therein are saved and processed by us to process your enquiry and for any subsequent questions. Your data is exclusively used to reply to and process your question. In this case, data is processed according to Article 6 section 1 (S. 1) letter a of the GDPR based on permission voluntarily issued. You can object to this at any time (right of revocation).

Introduction

YouTube videos
We included YouTube videos on our website. These are stored on servers of the provider YouTube and can be played on our website using an embedded version. The videos are embedded with an activated option for extended data protection settings. If you play these videos, YouTube cookies and double-click cookies are stored on your computer, and data may be transferred to Google Inc., Amphitheater Parkway, Mountain View, CA 94043, USA, as the YouTube operator.

When playing videos stored on YouTube, according to the current situation at least the following data is sent to Google Inc. as the YouTube operator and the operator of the Double-Click network: IP Address and cookie, the specific address of the page called up on our website, system date and time this is called up, call sign for your browser.

This data is transferred depending on whether you have a Google user account with which you are logged in, or if you do not have a user account. If you are logged in this manner, Google may allocate this data directly to your account. If you do not want this to be allocated to your profile, you must log out prior to activating the play button for the video.

YouTube and Google Inc. save this data as use profiles and may use this for advertising, market research and/or the need-related design of their websites. Any such evaluation is performed in particular (including for non-registered users) to provide need-related advertising and in order to inform other users about your activities on our website. You can reject the creation of these user profiles, however to do so you must contact Google as the YouTube operator.

You can find further information on the purpose and scope of data collection and data processing by Google here.

Introduction

Use of IFRAMES
Your website uses IFrames. These are either loaded directly into the website code or via an embedded script.
If your own pages are embedded via IFrames, there is a risk that the pages in the IFrame will not contain a link to the legal notice or privacy policy.
If, on the other hand, third-party pages are integrated via IFrames, this constitutes a GDPR-relevant data transfer.

Recommendation: Stop using IFrames! Revise your website and eliminate these constructs.

Introduction

References to third-party websites
References to third-party websites are offered in our website as so-called links. Data for the target link is only passed on when you click on such a link. This is a technical pre-requisite. The data transferred include, in particular: Your IP address, the time at which you clicked on the link, the page on which you clicked on the link, information on your Internet browser. If you do not want this data to be passed on to the target link, do not click on the link.

Introduction

SSL encryption
This website uses SSL encryption (Secure Socket Layer) for transferring data from your browser to our servers and to servers which provide information and we include in our website.
Data is transfer with encryption using SSL. This data cannot be changed and the sender can be identified.
You can recognise the presence of SSL encryption by the "https" prefix before IP addresses for websites you call up using your browser.

Introduction

Links to other websites
Our website/app can sometimes include links to third-party websites or other of our websites. If you follow a link to one of these websites, please note that these websites have their own data protection policies and that we do not accept any responsibility or liability for these policies. Please check these data protection policies before you pass on personal data to these websites.

Introduction

Separate page for the privacy policy
Your website does not contain a direct link to the privacy policy. This could lead to problems. We recommend providing a link labeled “Privacy Policy” or “Privacy Notice” and linking to the page with the privacy policy from there (if necessary, create a new page with the policy if you do not already have two separate pages for the legal notice and privacy policy). Further information on this topic.

Introduction

Consent required due to use of tracking tools

Your website uses tracking cookies or other tracking methods (see the section Cookies found in this report or the section Components found). For this reason, you must display a pop-up query on your website (§ 25 TDDDG or GDPR or Google policy).
Please ensure that the consent prompt does NOT cover the links to your legal notice and privacy policy, as these must be accessible at all times.
The strict interpretation of the GDPR requires that the user's prior consent be obtained before using tracking tools such as Google Analytics or the Facebook Pixel.

Our recommendation:
Check whether you really need the tools you are using and whether externally integrated resources (such as fonts) can be stored locally (this report contains relevant information on this subject). For Google Analytics, use alternatives such as WP Statistics (for WordPress). If you need or want to continue using the tools you have been using, ask your IT service provider to integrate a consent request into your website and only load tracking tools on your website after the user has given their consent.
Furthermore, tools and plugins from corporations such as Google and Facebook should ideally not be integrated, or only after prior consent has been given. This applies in particular to Google Maps, Google fonts, social media plugins, and YouTube videos.
Since the ECJ ruling of July 16, 2020, data transfers to unsafe third countries such as the US have also become very problematic. At present, these data transfers may be legitimate for certified companies. We assume that the agreement between the EU and the US will not be upheld. You would also need to check whether the providers of the plugins you use are certified. Therefore, all tools, fonts, maps, videos, etc. from non-European providers should only be loaded after legally valid user consent has been obtained.

Introduction

Comments function
There are voluntary comment functions on some pages or for some contributions, which allow you to communicate your opinion on the respective page or contribution. The comment is released after receiving a positive review and becomes publicly visible on the page to which you sent your comment. There is no entitlement to have a comment released. The commenting party must state their name - this can also be a pseudonym. In addition the commenting party must also state their e-mail address. This is used to inform this party of the status of their comment, in particular if a question is included in the comment for which a response is expected. The e-mail address is not publicly displayed and not passed on to third parties and not manually evaluated. The commenting party’s IP address is only saved in a disguised form. The comment is permanently saved until it is deleted again by you (or an administrator). The e-mail address you provide with the comment is only saved for the purpose of sending you a message in the event that there is a response to your comment. Other data which you pass on with your comment will be published with your comment if this data is provided. If a name is requested you can use a pseudonym.

Introduction

Embedded YouTube video
You should only load YouTube videos after requesting consent, but at the very least, embed them in such a way that they do not transmit data to the YouTube platform without permission. By default, the DoubleClick advertising network is loaded dynamically and cookies are set when you embed YouTube videos without special privacy settings.
Please retrieve the embed code for your video on YouTube again. Make sure that the checkbox for “Advanced privacy settings” is selected when retrieving the embed code. You can access the settings by clicking on Share:

Alternatively, you can adjust the address of the video wherever YouTube is embedded:
Change the text youtube.com in the video URL to youtube-nocookie.com.
However, our recommendation is: Do not embed YouTube videos at all, but only show a static preview image that links to the YouTube video. Or store the video locally on your web space and embed it from there. Or choose a 2-click solution so that the user must first agree to the privacy policy for YouTube videos before a YouTube video is even loaded.
The same applies to Vimeo videos, by the way.

Introduction

Google Remarketing with Double Click
Google’s Remarketing with DoubleClick ("DoubleClick" or "DOubleClick Remarketing") is a service offered by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). DoubleClick Remarketing uses cookies in order to blend in the most relevant possible advertising according to the users behaviours. In so doing Google notes which adverts are shown and which ones you call up. The use of DoubleClick cookies allows Google and its advertising network to add adverts based on your previous website visits (or from apps). The information created by the cookies is transferred by Google for evaluation to a Google server, where it is saved. You can prevent cookies being saved with corresponding settings in your browser software. In addition you can prevent the data created by cookies and relating to your website use being collected by Google and the processing of this data by Google. To do so please use the following link: Data protection information for DoubleClick and Google. You can also adjust the settings of the remarketing functionality.

Introduction

Google-Tag-Manager
We use the Google Tag Manager from Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Irland (hereinafter: Google). Google Tag Manager is a cookie-free domain and does not record any personal data. The tool ensures that other components are triggered which, in turn, may record data. Google Tag Manager does not access this data. If deactivation is performed at a domain or cookie level, this remains in place for all tracking tags which are implemented with Google Tag Manager.

Introduction

The privacy policy for a service (tool) used is missing.
You use a service (tool) but do not explain this. This is problematic because it involves the transfer of your website visitor's IP address. This is considered personal data. Therefore, according to Art. 13 GDPR, visitors must be informed about what happens to their data. In the case of scripts and plugins, this is particularly important because they potentially perform additional data processing. If possible, you should store the tool locally on your server or remove the tool.

Introduction

The privacy policy for a service (tool) used is missing.
You use a service (tool) but do not explain this. This is problematic because it involves the transfer of your website visitor's IP address. This is considered personal data. Therefore, according to Art. 13 GDPR, visitors must be informed about what happens to their data. In the case of scripts and plugins, this is particularly important because they potentially perform additional data processing. If possible, you should store the tool locally on your server or remove the tool.

Introduction

Google Fonts
This site uses certain fonts provided by Google. Your browser will load these fonts when you call up the page. In so doing, your IP address and the page (Internet address) that you have visited will be sent to one of Google’s servers. You can find further information on these Google fonts at https://developers.google.com/fonts/faq and in Google’s privacy policy at https://www.google.com/policies/privacy/

Introduction

Facebook Connect/social plugin/pixel used: critical
In particular, you are using a social plugin from Facebook in the form offered by Facebook on the above-mentioned pages. According to current opinion, this is illegal. Please remove the social plugin (widget or Facebook pixel) from all pages either without replacement or replace it with a permitted variant (such as Shariff) or with a static link to your Facebook page.
The Facebook pixel can only be used safely if consent is requested in advance and an opt-out option is offered in the privacy policy.
If, on the other hand, you were to simply link to your Facebook page, this would not be a problem for your website.

Introduction

Use of Facebook’s visitor access statistics
We use the visitor access statistics (remarketing function) “Custom Audiences” from Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”), also known as Facebook Pixel. Thanks to this function we can approach website visitors with advertising in a target-oriented manner by adding advertising content to Facebook that is personalised to the visitor’s interests when they visit the Facebook social network. The function is only activated when you have given us your permission for this. If this function is activated, a direct connection to a Facebook server is created when you visit this website. Information is passed on to the Facebook server about which of our websites you visited. Facebook allocates this information to your personal Facebook user account. Further information on the collection and use of data by Facebook, your rights in this regard and opportunities to protect your privacy can be found in Facebook’s privacy policy here: https://www.facebook.com/about/privacy. If you do not want Facebook to allocate the information collected directly to your Facebook user account, you can deactivate the remarketing function “Custom Audiences” here. To do so you have to be logged in to Facebook.
Facebook this subject to the privacy shield agreement between the European Union and the USA and has had itself certified accordingly. In so doing, Facebook undertakes to comply with the standards and provisions of European data protection law. You can find information in this regard on this website.

Introduction

The privacy policy for a service (tool) used is missing.
You use a service (tool) but do not explain this. This is problematic because it involves the transfer of your website visitor's IP address. This is considered personal data. Therefore, according to Art. 13 GDPR, visitors must be informed about what happens to their data. In the case of scripts and plugins, this is particularly important because they potentially perform additional data processing. If possible, you should store the tool locally on your server or remove the tool.

Introduction

Use of Facebook’s visitor access statistics
We use the visitor access statistics (remarketing function) “Custom Audiences” from Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”), also known as Facebook Pixel. Thanks to this function we can approach website visitors with advertising in a target-oriented manner by adding advertising content to Facebook that is personalised to the visitor’s interests when they visit the Facebook social network. The function is only activated when you have given us your permission for this. If this function is activated, a direct connection to a Facebook server is created when you visit this website. Information is passed on to the Facebook server about which of our websites you visited. Facebook allocates this information to your personal Facebook user account. Further information on the collection and use of data by Facebook, your rights in this regard and opportunities to protect your privacy can be found in Facebook’s privacy policy here: https://www.facebook.com/about/privacy. If you do not want Facebook to allocate the information collected directly to your Facebook user account, you can deactivate the remarketing function “Custom Audiences” here. To do so you have to be logged in to Facebook.
Facebook this subject to the privacy shield agreement between the European Union and the USA and has had itself certified accordingly. In so doing, Facebook undertakes to comply with the standards and provisions of European data protection law. You can find information in this regard on this website.

Introduction

Security notice
We secure our website and other IT systems using suitable technical and organisational activities to prevent loss, destruction, unauthorised access, unauthorised changes and the unauthorised processing of your data. However, it is practically impossible to fully protect your data from all risks in all cases despite the greatest of care. Because we cannot guarantee full data security for email communication, we recommend that confidential information is sent by post.

Introduction

WordPress
The websites utilizes WordPress as content management system. WordPress itself uses functional cookies, which are necessary to ensure a login process for content managers and webmasters. WordPress uses a cookie named wordpress_test_cookie when a user tries to login to the administrative interface of WordPress. The cookie is solely used for the current session and will be deleted as soon as you close your browser. The beforementioned cookie will not be used to track users or their behaviour.

Introduction

Changes to this data protection declaration
We reserve the right to change this data protection declaration if the legal situation or this online offering or the type of data collection changes. However, this only applies with regard to declarations for data processing. To the extent that the user’s permission is required or if parts of the data protection declaration include regulations for a contractual relationship with users, the data protection declaration has only changed with user’s permission.

As a result, if required, please obtain information on this data protection declaration, in particular if you pass on personal data.

This website was checked and scanned with the privacy protection tool wwwschutz. The privacy declaration was generated with the help of wwwschutz.

Page-specific information

1

Possible contact forms

📝

The following pages were automatically recognized as possible carriers of contact forms. Please check whether contact forms are present and whether they comply with the requirements of the GDPR (in particular data minimization, data protection notices including links to data protection notices, consent).

⚠️️

IFrames Usage

ℹ️ Use of IFRAMES
Your website uses IFrames. These are either loaded directly into the website code or via an embedded script.
If your own pages are embedded via IFrames, there is a risk that the pages in the IFrame will not contain a link to the legal notice or privacy policy.
If, on the other hand, third-party pages are integrated via IFrames, this constitutes a GDPR-relevant data transfer.

Recommendation: Stop using IFrames! Revise your website and eliminate these constructs.
3

Affects the following pages/files in particular

⚠️️

YouTube-Video

ℹ️ Embedded YouTube video
You should only load YouTube videos after requesting consent, but at the very least, embed them in such a way that they do not transmit data to the YouTube platform without permission. By default, the DoubleClick advertising network is loaded dynamically and cookies are set when you embed YouTube videos without special privacy settings.
Please retrieve the embed code for your video on YouTube again. Make sure that the checkbox for “Advanced privacy settings” is selected when retrieving the embed code. You can access the settings by clicking on Share:

Alternatively, you can adjust the address of the video wherever YouTube is embedded:
Change the text youtube.com in the video URL to youtube-nocookie.com.
However, our recommendation is: Do not embed YouTube videos at all, but only show a static preview image that links to the YouTube video. Or store the video locally on your web space and embed it from there. Or choose a 2-click solution so that the user must first agree to the privacy policy for YouTube videos before a YouTube video is even loaded.
The same applies to Vimeo videos, by the way.

4

Generally relevant

⚠️️

Privacy policy incomplete: Google Safeframe (Google Ad Services)

ℹ️ The privacy policy for a service (tool) used is missing.
You use a service (tool) but do not explain this. This is problematic because it involves the transfer of your website visitor's IP address. This is considered personal data. Therefore, according to Art. 13 GDPR, visitors must be informed about what happens to their data. In the case of scripts and plugins, this is particularly important because they potentially perform additional data processing. If possible, you should store the tool locally on your server or remove the tool.
5

Generally relevant

⚠️️

Privacy policy incomplete: Google Ads Remarketing for Google Analytics

ℹ️ The privacy policy for a service (tool) used is missing.
You use a service (tool) but do not explain this. This is problematic because it involves the transfer of your website visitor's IP address. This is considered personal data. Therefore, according to Art. 13 GDPR, visitors must be informed about what happens to their data. In the case of scripts and plugins, this is particularly important because they potentially perform additional data processing. If possible, you should store the tool locally on your server or remove the tool.
6

Affects the following pages/files in particular

⚠️️

Facebook Connect/Social Plugin/Pixel used

ℹ️ Facebook Connect/social plugin/pixel used: critical
In particular, you are using a social plugin from Facebook in the form offered by Facebook on the above-mentioned pages. According to current opinion, this is illegal. Please remove the social plugin (widget or Facebook pixel) from all pages either without replacement or replace it with a permitted variant (such as Shariff) or with a static link to your Facebook page.
The Facebook pixel can only be used safely if consent is requested in advance and an opt-out option is offered in the privacy policy.
If, on the other hand, you were to simply link to your Facebook page, this would not be a problem for your website.
7

Generally relevant

⚠️️

Privacy policy incomplete: Google Tag Manager

ℹ️ The privacy policy for a service (tool) used is missing.
You use a service (tool) but do not explain this. This is problematic because it involves the transfer of your website visitor's IP address. This is considered personal data. Therefore, according to Art. 13 GDPR, visitors must be informed about what happens to their data. In the case of scripts and plugins, this is particularly important because they potentially perform additional data processing. If possible, you should store the tool locally on your server or remove the tool.
8

Generally relevant

⚠️️

WordPress

ℹ️ WordPress
The websites utilizes WordPress as content management system. WordPress itself uses functional cookies, which are necessary to ensure a login process for content managers and webmasters. WordPress uses a cookie named wordpress_test_cookie when a user tries to login to the administrative interface of WordPress. The cookie is solely used for the current session and will be deleted as soon as you close your browser. The beforementioned cookie will not be used to track users or their behaviour.
9

External files

⚠️️

The following files are loaded from your website via external servers and are therefore obtained from third parties. They may belong to already recognized tools.
Please ensure that you are permitted to load these resources without prior consent from your website users and that your privacy policy is designed accordingly. Where possible, the resources mentioned should be stored locally on your server so that the local version of the resource can be used.

Identified pages

📄

Only pages that were accessible at the time of analysis were scanned. Pages that do not display HTML content (such as text files or PDF files) are hidden below, as are pages that were not accessible.

Ready for Your Own Privacy Check?

You've seen how detailed we analyze websites. Use the same service for your own website and gain legal certainty.

How It Works

1

Enter Website

Simply enter your website URL

2

Automatic Check

Our system analyzes all pages automatically

3

Receive Report

You'll receive your report within 24 hours

One-time 29€ plus VAT
✓ Start immediately ✓ Discount option ✓ No recurring costs
Yes, I Want My Website Checked

🔒 Secure Payment • Instant Access • No Subscription Trap

A product from

IT Logic GmbH®
Your partner for secure solutions

The offer is made by IT Logic, which is advised by lawyers. IT Logic does not offer legal advice and will refer you to a lawyer if necessary.