General information
- We process your personal data within the meaning of Article 4(1) GDPR, such as your name, email address and IP address, only in accordance with German data protection law and the European General Data Protection Regulation (GDPR). The following provisions explain the nature, scope and purposes of collecting, processing and using personal data.
- Processing within the meaning of Article 4(2) GDPR is lawful under Article 6 GDPR where one of the following conditions applies:
- The data subject has consented to processing for one or more specific purposes;
- processing is necessary to perform a contract with the data subject or take steps at their request before entering into a contract;
- processing is necessary to comply with a legal obligation binding on the controller;
- processing is necessary to protect the vital interests of the data subject or another natural person;
- processing is necessary to perform a task in the public interest or exercise official authority vested in the controller;
- processing is necessary for the legitimate interests of the controller or a third party, unless those interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring protection of personal data, in particular where the data subject is a child.
- Processing special categories of personal data, such as health data, biometric data, sexual orientation, religion or trade union membership, within Article 9(1) GDPR is lawful in particular under Article 9(2) GDPR where:
- the person has given explicit consent; or
- processing is necessary to establish, exercise or defend legal claims, or whenever courts act in their judicial capacity.
- No automated decision-making or profiling of personal data within Article 22 GDPR takes place.
- The operator ensures data security through appropriate technical measures under Article 32 GDPR, taking proportionality into account.
- In the unexpected event of a personal data breach, the competent supervisory authority will be notified under Article 33 GDPR and the affected person under Article 34 GDPR.
Scope
This privacy policy applies only to our websites. If links on our pages take you to other websites, please consult those websites for information about how they handle your data.
Data retention period
The retention period for data you transmit is determined by statutory retention requirements. Under commercial and tax laws, invoice data must be retained for up to 10 years.
Disclosure of data to third parties
Data provided when contacting us is disclosed to third parties within Article 4(10) GDPR only where:
- you have given your express consent under Article 6(1)(a) GDPR;
- disclosure is necessary under Article 6(1)(f) GDPR to establish, exercise or defend legal claims and there is no reason to assume you have an overriding legitimate interest in non-disclosure;
- there is a legal obligation to disclose under Article 6(1)(c) GDPR; or
- disclosure is legally permissible and necessary to perform contractual relationships with you under Article 6(1)(b) GDPR.
Controller under the GDPR
The controller within the meaning of the GDPR, other data protection laws applicable in the European Union and other provisions concerning data protection is:
path digital PD GmbH & Co. KG
Lindenstraße 3D
55595 Hargesheim
Germany
Phone: +49 (0)151 64413169
Email: datenschutz@pathdigital.de
Cookies
We use necessary browser storage to remember your privacy choices (pd_consent_v2, valid for 180 days) and your explicitly selected language (pd_language, 180 days). Automatic browser-language routing does not set this language cookie.
Optional statistics and marketing technologies are loaded only after you choose the corresponding categories. Scrolling, continuing to browse or opening the details does not constitute consent. You may reject optional services without restricting the website.
You can change or withdraw your consent at any time using Privacy settings in the footer. Withdrawal stops future loading and removes accessible tracking storage on our domain. Cookies set by third parties on their own domains can be removed in your browser settings. Withdrawal does not affect processing that took place before it.
The legal basis for optional tracking is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Necessary storage is used under Section 25(2) TDDDG. The cookie and storage details in the privacy settings list providers, purposes, identifiers and retention periods.
Hosting
We host our website with Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA (Vercel). When you visit our website, Vercel records various log files, including your IP address, to deliver the website reliably and securely.
Vercel stores cookies or other recognition technologies necessary to display the website, provide certain website functions and ensure security (necessary cookies).
For details, see Vercel’s privacy policy: Privacy Policy | Vercel.
Vercel is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in displaying our website reliably and securely.
Transfers of data to the USA rely on the EU-U.S. Data Privacy Framework and the European Commission’s standard contractual clauses. For details, see: Privacy Policy | Vercel.
Data processing agreement
Where required by data protection law, we have entered into data processing agreements with the providers named in this privacy policy. These agreements ensure that providers process our website visitors’ personal data only on our instructions and in compliance with the GDPR.
PostHog
Where you have given consent, we use PostHog, a web analytics service with EU hosting (eu.posthog.com), on our website. The provider is PostHog Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA (PostHog).
After statistics consent, PostHog uses a randomly generated identifier in Local Storage and Session Storage to record page views, CTA clicks and booking steps. Our PostHog integration does not use analytics cookies or session recordings and does not record form field values. The local identifiers are removed when consent is withdrawn or detected as expired. Session Storage lasts for the tab session.
Processing is based exclusively on your consent under Article 6(1)(a) GDPR in conjunction with section 25(1) TTDSG. You can withdraw your consent at any time with effect for the future by clicking “Privacy settings” in our website’s footer and changing your choice.
Transfers of data to the USA rely on the EU-U.S. Data Privacy Framework and the European Commission’s standard contractual clauses.
For more information, see PostHog’s privacy policy.
Google Tag Manager
We use Google Tag Manager (Google Ireland Limited, Ireland) to load the following services only after the required consent. Defaults remain denied. GTM does not replace PostHog. No optional GTM service starts before a choice or after rejection.
Google Analytics and Google Ads
Google Ireland Limited, Ireland, provides visit measurement and advertising attribution. Our linked Google tags and server-side configuration require both statistics and marketing consent. Events may be forwarded through gcp.pathdigital.de. Cookies include _ga and _ga_* (up to two years), and _gcl_* (up to 90 days). The conversion linker is enabled with marketing consent. Details: https://business.safety.google/adscookies/
Meta Pixel
With marketing consent, we use Meta Pixel (Meta Platforms Ireland Limited, Ireland) for advertising attribution, remarketing and confirmed booking conversions. _fbp and _fbc cookies may persist for up to 90 days. Automatic form matching is disabled in this integration. Details: https://www.facebook.com/privacy/policies/cookies/
LinkedIn Insight
With marketing consent, LinkedIn Insight (LinkedIn Ireland Unlimited Company, Ireland) provides advertising attribution, audience analysis and remarketing. Cookies may include li_gc (six months), bcookie (one year), lidc (one day), UserMatchHistory and AnalyticsSyncHistory (30 days). Details: https://www.linkedin.com/legal/l/cookie-table
Leadinfo
With marketing consent, Leadinfo B.V., Netherlands, identifies visiting companies and analyses their visits. _li_id.* cookies last up to two years; _li_ses.* cookies associate pages in the current session. Browser storage may queue unsent events. Details: https://help.leadinfo.com/en/what-cookies-are-created-by-leadinfo
OpenAI Pixel
With marketing consent, OpenAI Pixel associates clicks on ChatGPT ads with visits and confirmed bookings. It may use __obref (browser identifier, up to one year) and __oppref (ad click reference, lifetime determined by pixel configuration). Details: https://help.openai.com/en/articles/20001409-conversion-measurement
Processing by external providers
The providers above may process data in the USA or other countries outside the EU/EEA. Processing of optional measurement data is based on consent. Provider policies describe recipients and applicable transfer mechanisms. Current storage details and withdrawal controls are available in Privacy settings in the footer.
Contact form
When you use the contact form offered on these pages, the information you enter and files you attach are transmitted and stored to respond to your enquiry. Data provided when contacting us is disclosed to third parties only with your express consent.
Booking via Cal.com
We use the scheduling service Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA (Cal.com) to let you book consultation calls. The embedded calendar only loads after you have filled in the booking form and actively requested a time slot.
Cal.com processes the data you enter (e.g. name, email address, phone number, answers to booking questions) along with your chosen time slot to enable the booking and send reminders.
Processing is based on Article 6(1)(b) GDPR, as it is necessary to carry out pre-contractual measures taken at your request. Cal.com has appointed an EU representative under Article 27 GDPR (Felix Kolodziej, felix@cal.com).
For details, see Cal.com’s privacy policy: Privacy Policy | Cal.com.
Job applications
During the application process, personal data such as your name, address, telephone number and email address is stored in the applicant database. Application documents, including letters, CVs and certificates, are also collected and stored. Your data is evaluated, processed or forwarded internally exclusively for the application process. Applicant data may be viewed only by HR staff and the people responsible for selection. Data is not disclosed to third parties.
If your application is successful, your application data is transferred to your personnel file. Other applicant data is retained for a maximum of 3 months after the application process ends.
You may withdraw your consent and request deletion of your applicant data at any time by sending us an informal email.
SSL connection and data security
In accordance with section 13(7) TMG, this website uses SSL encryption, indicated by a padlock symbol in your browser’s address bar. When SSL encryption is enabled, third parties cannot read the transmitted data.
As a rule, this uses 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can recognise an encrypted connection to a page of our website by the closed key or padlock symbol in the lower status bar of your browser.
We also use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction and unauthorised third-party access. We continuously improve our security measures in line with technological developments.
Your rights
You may request information about your stored personal data at any time, free of charge. Your rights also include confirmation, rectification, restriction, blocking and erasure of such data, provision of a copy in a portable format, withdrawal of consent and objection. Statutory retention obligations remain unaffected.
Your rights arise in particular from the following provisions of the GDPR:
- Article 7(3) – Right to withdraw consent to data processing
- Article 12 – Transparent information, communication and arrangements for exercising data subject rights
- Article 13 – Information to be provided when personal data is collected from the data subject
- Article 14 – Information to be provided when personal data has not been obtained from the data subject
- Article 15 – Right of access, confirmation and a copy of personal data
- Article 16 – Right to rectification
- Article 17 – Right to erasure (right to be forgotten)
- Article 18 – Right to restriction of processing
- Article 19 – Notification obligation regarding rectification, erasure or restriction of processing
- Article 20 – Right to data portability
- Article 21 – Right to object
- Article 22 – Right not to be subject to a decision based solely on automated processing, including profiling
- Article 77 – Right to lodge a complaint with a supervisory authority
To exercise your rights, except under Article 77, please contact the controller identified above.
Competent supervisory authority:
The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate
Hintere Bleiche 34
55116 Mainz
Germany
Phone: +49 (0) 6131 208-2449
Fax: +49 (0) 6131 208-2497
Website: https://www.datenschutz.rlp.de/
Email: poststelle(at)datenschutz.rlp.de
(Please check the authority’s website to confirm that these contact details are current.)
