---
title: "Privacy Policy | DÜS Eckert"
description: "How we handle your data, which services we use, and what rights you have. Our complete privacy policy under GDPR, BDSG, and TDDDG."
url: "https://dues-eckert.com/privacy-policy"
lang: "en"
updated: "2026-08-12"
alternate: "https://dues-eckert.com/de/datenschutz.md"
---

# Privacy Policy

With this privacy policy, we inform you about how we handle your personal data and about your rights under the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG).

## Controller

The controller responsible for data processing is:

**DÜS Eckert Spracheninstitut GmbH**\
Immermannstr. 65C\
40210 Düsseldorf\
Germany

**Phone:** +49 211 2718200\
**Email:** mail@dues-eckert.de

**Managing Director:** Irina Eckert

## Data Protection Enquiries

If you have questions about how we handle your data, or wish to exercise your rights, please address your enquiry to the contact details stated above.

## Legal Bases

The data protection term “personal data” refers to all information relating to an identified or identifiable natural person. We process personal data in compliance with the relevant data protection provisions, in particular the GDPR, the BDSG, and the TDDDG. Processing by us takes place only on the basis of a statutory permission. We process personal data only

- with your consent (Art. 6(1)(a) GDPR; storing information on your device and accessing it are additionally governed by Section 25 TDDDG),
- for the performance of a contract to which you are a party, or at your request in order to take steps prior to entering into a contract (Art. 6(1)(b) GDPR),
- for compliance with a legal obligation (Art. 6(1)(c) GDPR), or
- where processing is necessary for the purposes of our legitimate interests or those of a third party, except where your interests or fundamental rights and freedoms requiring the protection of personal data override those interests (Art. 6(1)(f) GDPR).

## Storage Period

Unless otherwise stated in the following sections, we store data only for as long as is necessary to achieve the purpose of processing or to fulfil our contractual or legal obligations. Such statutory retention obligations may arise in particular from commercial or tax law provisions. From the end of the calendar year in which the last entry was made in the commercial books, the inventory was drawn up, the opening balance sheet or the annual financial statements were established, the commercial or business letter was received or sent, or the accounting voucher was created, we retain commercial books, inventories, opening balance sheets and annual financial statements for ten years, accounting vouchers for eight years, and received and sent commercial and business letters for six years (Section 257(4) and (5) HGB (German Commercial Code), Section 147(3) and (4) AO (German Fiscal Code)). These periods do not expire as long as the documents are relevant to taxes for which the assessment period has not yet expired (Section 147(3) AO). In addition, we will retain data relating to consents subject to documentation requirements, as well as to complaints and claims, for the duration of the statutory limitation periods. Data stored for advertising purposes will be deleted if you object to processing for this purpose.

In addition, the following retention periods apply to specific processing activities:

- **Contact enquiries:** We retain your enquiry and the associated correspondence for as long as is necessary to deal with your request and to answer follow-up questions. If the correspondence concerns a commercial transaction, the commercial and tax law retention periods stated above apply in addition.
- **Chat and WhatsApp conversations:** Intercom automatically and completely deletes the records of visitors who have not returned for nine months. As soon as you start a conversation, however, Intercom creates a contact record which is not covered by this automatic deletion. We retain conversations and the associated contact records for as long as is necessary to deal with your request and to answer follow-up questions.
- **Appointment bookings:** We retain the booking data for as long as is necessary to carry out the appointment and to deal with the matters arising from it.
- **Applications:** Application documents of rejected applicants are anonymized in our applicant management system no later than six months after the conclusion of the application procedure, unless express consent to longer storage has been given.
- **Server log files:** The log data of our hosting platform (Cloudflare Workers Logs) is deleted automatically after seven days.
- **Email delivery:** The log data of our sending provider (sender, recipient, subject, delivery status) is stored for 31 days, and a copy of the message content for about seven days (see the “Email Delivery” section).

## Categories of Data Recipients

We use processors in the course of processing your data. Processing operations carried out by such processors include, for example, hosting, maintenance and support of IT systems, customer and order management, accounting and billing, or the destruction of files and data carriers. Processors do not use the data for their own purposes but carry out the processing exclusively for the controller and are contractually obliged to ensure appropriate technical and organizational data protection measures.

Data processing agreements pursuant to Art. 28 GDPR are in place with the following service providers:

- Cloudflare – hosting, protection against misuse (Turnstile) and email delivery
- Microsoft – email mailbox
- Intercom – chat and WhatsApp
- Cal.com – appointment booking
- Personio – job postings and applications
- Conva Ventures Inc. – web analytics (Fathom Analytics)

We state the full legal entity and registered seat of each provider below, in the section describing the service concerned.

Furthermore, we may transfer your personal data to entities such as postal and delivery services, our bank, tax advisors/auditors, or the tax authorities. Additional recipients may arise from the following sections.

## Transfers to Third Countries

Visiting our website may involve the transfer of certain personal data to third countries, i.e., countries outside the European Union and the European Economic Area. In particular, we use services whose providers are based in the USA or in Canada.

Such a transfer is permissible if the European Commission has determined that an adequate level of data protection is ensured in the third country concerned (adequacy decision). For the USA, such an adequacy decision exists under the EU-U.S. Data Privacy Framework, but only for those providers that are certified under it. For Canada, an adequacy decision exists for the private sector. If no adequacy decision exists, or if it does not apply to the individual provider, the transfer takes place only where appropriate safeguards pursuant to Art. 46 GDPR are in place (in particular EU standard contractual clauses) or where one of the conditions of Art. 49 GDPR is met. You can check which providers are certified under the EU-U.S. Data Privacy Framework at any time yourself on the list maintained by the U.S. Department of Commerce at <https://www.dataprivacyframework.gov/list>.

In detail, this concerns the following providers; in each case, the basis on which the transfer relies is stated:

- **Cloudflare, Inc.**, 101 Townsend Street, San Francisco, CA 94107, USA – hosting, protection against misuse (Turnstile) and email delivery. Basis: adequacy decision on the EU-U.S. Data Privacy Framework; Cloudflare, Inc. is listed as an active participant on the official list.
- **Intercom, Inc.**, San Francisco, California, USA – chat. Basis: adequacy decision on the EU-U.S. Data Privacy Framework (details in the “Chat: Intercom” section).
- **Cal.com, Inc.**, 2261 Market Street #4382, San Francisco, CA 94114, USA – appointment booking. Basis: EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR; this provider is **not** certified under the EU-U.S. Data Privacy Framework (details in the “Appointment Booking: Cal.com” section).
- **Conva Ventures Inc.**, 26 Bastion Square, Third Floor Burnes House, Victoria, British Columbia, V8W 1H9, Canada – web analytics (Fathom Analytics). Basis: adequacy decision for Canada.
- **Microsoft Ireland Operations Limited**, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland – email mailbox. The provider is established in the European Union and stores our mailbox data in Germany; in the exceptional cases documented by Microsoft – for example, certain support and security operations – a transfer to third countries may nevertheless take place. The basis for this is the EU standard contractual clauses or the adequacy decision on the EU-U.S. Data Privacy Framework (details in the “Email Mailbox: Microsoft 365” section).

You can request a copy of the safeguards applicable in each case using the contact details stated in the “Controller” section.

## Your Rights

As a data subject, you have the right to assert your data subject rights against us. In particular, you have the following rights:

### Right of Access (Art. 15 GDPR)

You have the right to request confirmation as to whether we process personal data concerning you. If this is the case, you have the right to access this personal data as well as further information pursuant to Art. 15 GDPR.

### Right to Rectification (Art. 16 GDPR)

You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed.

### Right to Erasure (Art. 17 GDPR)

You have the right to request that we erase personal data concerning you without undue delay, provided that one of the reasons set out in Art. 17 GDPR applies, e.g., if the data is no longer needed for the purposes pursued.

### Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request the restriction of the processing of your personal data if one of the conditions set out in Art. 18 GDPR is met, e.g., if you have objected to the processing.

### Right to Data Portability (Art. 20 GDPR)

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided that the processing is based on consent or on a contract and is carried out by automated means.

### Right to Object (Art. 21 GDPR)

**Pursuant to Art. 21(1) GDPR, you have the right to object, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or (f) GDPR.**

**Where we process personal data concerning you for direct marketing purposes, you may object to such processing at any time and without giving reasons pursuant to Art. 21(2) and (3) GDPR.**

### Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on your consent, you have the right to withdraw your consent at any time. This does not affect the lawfulness of processing based on consent before its withdrawal.

### Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), the data protection authority for the German state of North Rhine-Westphalia\
Postfach 20 04 44, 40102 Düsseldorf\
Kavalleriestr. 2–4, 40213 Düsseldorf\
Phone: +49 211 38424‑0\
Email: poststelle@ldi.nrw.de\
[https://www.ldi.nrw.de](https://www.ldi.nrw.de/)

### Processing When You Exercise Your Rights

When you exercise your rights under Art. 15–22 GDPR, we process the personal data transmitted for the purpose of implementing these rights and in order to be able to provide evidence thereof. The legal basis for this processing is Art. 6(1)(c) GDPR in conjunction with Art. 15–22 GDPR and Section 34(2) BDSG.

## Automated Decision-Making

Automated decision-making, including profiling, pursuant to Art. 22 GDPR does not take place.

## Data Processing on Our Website

When you use our website, we collect information that you provide yourself. In addition, certain information about your use of the website is automatically collected by us during your visit. Under data protection law, the IP address is generally also considered personal data.

### Server Log Files

When you use our website purely for informational purposes, general information that your browser transmits to our server is stored automatically. This includes, by default: browser type/version, operating system used, page accessed, previously visited page (referrer URL), IP address, date and time of the server request, and HTTP status code.

The processing serves our legitimate interests and is based on Art. 6(1)(f) GDPR. This processing serves the technical administration and security of the website.

### Hosting: Cloudflare

Our website is hosted on the Cloudflare Workers platform and delivered via Cloudflare’s content delivery network. Cloudflare also provides the DNS service and protection against overload and abuse attacks. In doing so, Cloudflare processes your IP address and further technical data relating to your request (see “Server Log Files”).

The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare processes the data as a processor on our behalf.

The legal basis for the processing is Art. 6(1)(f) GDPR (legitimate interest in reliable and secure web hosting). Insofar as personal data is transferred to the USA, this takes place on the basis of the adequacy decision on the EU-U.S. Data Privacy Framework; Cloudflare, Inc. is listed as an active participant on the official list (see the “Transfers to Third Countries” section).

Further information: <https://www.cloudflare.com/privacypolicy/>

### Web Analytics: Fathom Analytics

To analyze the use of our website, we use Fathom Analytics, a service provided by Conva Ventures Inc. (Canada). Fathom Analytics is a privacy-friendly analytics service that sets no cookies and creates no individual user profiles. IP addresses are processed by Fathom only temporarily on the server side and are anonymized immediately; no personal data is stored. Evaluation is carried out exclusively on the basis of anonymized and aggregated data.

The data recorded is: the page accessed, including certain parameters contained in its address (a fixed, defined list of campaign and page parameters), the previously visited page, the duration of your stay on the page (recorded up to a maximum of 30 minutes), and general technical information. If you reach our website via an advertisement, the address may contain campaign parameters, which then form part of the page address transmitted. In addition, we record four events without any further information about you personally: the submission of the contact form, and a confirmed appointment booking, distinguished by the three consultation locations Düsseldorf, Essen and Online.

Fathom Analytics sets no cookies and stores nothing on your device for analytics purposes. When it loads, the script merely checks, directly on your device, whether you have set a blocking flag there with which the counting can be switched off permanently for your own browser; the result of this check remains on your device and is not transmitted. Consent under Section 25 TDDDG is not required for this. We base the server-side processing of access data on Art. 6(1)(f) GDPR (legitimate interest in the anonymized analysis of website use). For Canada, an adequacy decision of the European Commission exists for the private sector.

Further information: <https://usefathom.com/legal/privacy>

### Protection Against Misuse: Cloudflare Turnstile

To protect our forms against automated access, we use the Cloudflare Turnstile service on the pages containing the contact form, the appointment booking, and the job-saving function. This service is not loaded on any other page.

For this purpose, a script provided by Cloudflare is loaded which checks whether the input originates from a human. Your IP address as well as technical information about your browser and device are processed for this purpose. To confirm the check, we additionally transmit your IP address to Cloudflare from our server.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing misuse and automated requests). Insofar as personal data is transferred to the USA, this takes place on the basis of the adequacy decision on the EU-U.S. Data Privacy Framework; Cloudflare, Inc. is listed as an active participant on the official list (see the “Transfers to Third Countries” section).

Further information: <https://www.cloudflare.com/privacypolicy/>

### Contact Form

You can send us an enquiry via our contact form. In doing so, we process your name, your email address, and – if you enter one – your message. Name and email address are required in order to process your enquiry; without this information we cannot deal with your request. Providing a message is optional. In addition, before submitting, you must confirm that you have taken note of this privacy policy.

Your details are transmitted by email to our mailbox; your email address is set as the reply address so that we can respond to you directly. We deliberately do not send you a confirmation copy.

Insofar as your enquiry is directed towards the conclusion or performance of a contract with us, Art. 6(1)(b) GDPR is the legal basis for the data processing. Otherwise, we process the data on the basis of our legitimate interest in communicating with enquiring persons. The legal basis is then Art. 6(1)(f) GDPR.

### Chat: Intercom

On our website we offer you a chat through which you can write to us directly. Technically, this chat is provided by Intercom.

**The chat is not loaded until you expressly request it.** When you merely open our pages, all that is embedded is a button we built ourselves. As long as you do not activate it, your browser establishes no connection to Intercom, no data about you is transmitted to Intercom, and nothing is stored on or read from your device. Only when you click that button, or a button expressly marked as chat, is the chat loaded.

Once the chat has loaded, the following data is processed: your IP address, technical details of your browser and device, the pages of our website you have visited, the language setting, and the content of your messages including any details you voluntarily provide there (such as your name and email address). In addition, the identifiers listed below under “Cookies and Storage on Your Device” are stored on your device. You can use the chat without giving your name or your email address; providing them is optional. Without them, however, we can only reply to you within the chat itself and not by any other route.

Once you have opened the chat, this is recorded in your browser so that replies to an ongoing conversation can still be shown to you on a later visit. In that case – and only then – the chat is loaded automatically on a later visit. You can remove this record at any time by clearing the website data in your browser.

The contracting party and provider is Intercom R\&D Unlimited Company, 124 St Stephen’s Green, Dublin 2, D02 C628, Ireland. Intercom processes the data as a processor on our behalf.

**Transfer to the USA.** The chat infrastructure is operated in the United States. Your chat data is therefore transferred to Intercom, Inc., San Francisco, California, USA. The United States is a third country within the meaning of the GDPR. The transfer is based on the European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR): Intercom, Inc. is listed as an active participant in the EU-U.S. Data Privacy Framework on the list maintained by the U.S. Department of Commerce, including for data other than HR data.

You can verify this participation yourself at <https://www.dataprivacyframework.gov/list>.

**WhatsApp.** The messages you send to our two WhatsApp numbers also arrive in Intercom: our WhatsApp accounts are connected to Intercom as a channel. The data processed is your telephone number, the profile name you have set in WhatsApp, the content of your messages, and the associated metadata such as time and delivery status. WhatsApp itself is responsible for transporting the message (see the “Links to External Services” section); once the message reaches us, Intercom processes it as a processor on our behalf – including the transfer to the USA described above. Nothing is stored on your device by us in this process; the identifiers listed above come into existence only if you open the chat on our website.

The legal basis for processing your chat and WhatsApp messages is Art. 6(1)(b) GDPR where your enquiry concerns the conclusion or performance of a contract with us, and otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries through the channel you have chosen).

Storing and reading the identifiers on your device is necessary in order to provide the chat as the service you have expressly requested; it is therefore based on Section 25(2) no. 2 TDDDG. We do not obtain consent for this because the chat is not loaded without your express request.

If you do not wish to use the chat, do not open it – it is not loaded when you merely visit our pages. If you have opened the chat before, it is loaded automatically on later visits (see above); you can end this at any time by clearing the website data in your browser – after that, the chat is not loaded again until you click it again. All content on our website is fully usable without the chat. For enquiries, the contact form, the email address and the telephone number in the “Controller” section are available to you on equal terms.

Further information: <https://www.intercom.com/legal/privacy>

### Appointment Booking: Cal.com

For booking a free consultation, we use the appointment booking service Cal.com. When you book an appointment, we transmit your first name, last name, email address, mobile number, the selected appointment, the time zone, and the language of the appointment communication (German) to Cal.com in order to create the booking, send you the appointment confirmation and remind you of the appointment by SMS or WhatsApp; the booking is additionally given an internal note that it was received via our website. All of this information is required for the booking; without it we cannot create an appointment for you.

The provider is Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. Cal.com processes the data as a processor on our behalf.

**Transfer to the USA.** The United States is a third country within the meaning of the GDPR. Cal.com, Inc. is not listed as a participant in the EU-U.S. Data Privacy Framework; the European Commission’s adequacy decision therefore does not apply to this transfer. The transfer is instead based on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR), which form part of the data processing agreement concluded with Cal.com. You can request a copy of these safeguards using the contact details stated in the “Controller” section.

The appointment request is transmitted from our server to Cal.com. Your browser does not establish its own connection to Cal.com; your IP address is not transmitted to Cal.com.

The legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).

### Job Postings and Applications: Personio

The job postings displayed on our careers pages are retrieved once from our applicant management system Personio when the website is built, and are embedded statically into the page. When you visit the careers pages, **no** connection is therefore established between your browser and Personio, and no data about you is transmitted to Personio.

If you wish to apply, a link takes you to Personio’s application portal. Only there do you enter your application data; the privacy notices of that site then apply. We are the controller for the processing of your application data; Personio acts as a processor on our behalf in this respect.

The provider is Personio SE & Co. KG, Seidlstraße 3, 80335 München, Germany (Amtsgericht München, HRA 115934). Personio processes the data as a processor on our behalf; the provider is established in Germany.

The legal basis for processing applicant data is Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG (establishment of an employment relationship). Application documents of rejected applicants are anonymized in our applicant management system no later than six months after the conclusion of the application procedure, unless express consent to longer storage has been given.

### Sending a Job Posting by Email

On our job pages, you can have a link to a job posting sent to yourself by email. For this purpose, we process the email address you provide as well as the selected position and language. Without the email address we cannot deliver the message; providing it is therefore required for this function. The address is used to send this one email; we do not store it in our own systems. For the log data that arises at our sending provider in the process, see the “Email Delivery” section. In addition, we derive a check value (a hash) from the address in order to limit how often the same address can be written to; this prevents the form from being used to bombard someone else’s mailbox with messages. Only that check value is counted, not the address itself, and it is held briefly rather than stored permanently. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in protecting third parties against misuse). The email contains a short greeting, the title of the position, the link to our own job page, and a note on how your address is handled; it contains no advertising.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing this function, which you have expressly requested).

### Email Delivery

To send the emails described above, we use Cloudflare Email Service (Email Sending), a service provided by Cloudflare, Inc. In doing so, the data provided in the respective form and the recipient address are processed.

Cloudflare logs every message sent. The data stored includes the sender and recipient address, the subject, message identifiers, the delivery status, and any error messages. These log entries are stored and available to us for 31 days; the service offers no option to shorten that period. In addition, Cloudflare keeps a copy of the full message content for about seven days so that we can see which message was actually sent. In the case of a contact enquiry, this copy also includes your name, your email address, and the text of your message. The legal basis for both is Art. 6(1)(f) GDPR (legitimate interest in delivery monitoring and in troubleshooting email delivery).

Addresses to which delivery permanently fails, or from which a message is reported as spam, are automatically added by Cloudflare to a suppression list; no further messages are delivered to those addresses. The provider does not state how long such entries remain; the removal of automatically added entries is limited.

### Email Mailbox: Microsoft 365

Your enquiry is received and further retained in our email mailboxes, which we operate with Microsoft 365. This applies to enquiries via the contact form as well as to emails you write to us directly. The content you provide is processed, along with the traffic data required for delivery (sender and recipient address, subject, time).

The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. Microsoft processes this data as a processor on our behalf.

For customers with a sign-up country in the EU or EFTA, Microsoft has committed to storing and processing customer data within the so-called EU Data Boundary. Our Microsoft 365 tenant meets this requirement: according to the location information Microsoft states in the admin portal, the data in our mailboxes is stored in Germany, and the committed region is stated as the European Union/EFTA. We have not booked a Multi-Geo capability that would store data outside this region. In the exceptional cases documented by Microsoft – for example, certain support and security operations – transfers to third countries nevertheless take place; Microsoft bases these on the EU standard contractual clauses or the EU-U.S. Data Privacy Framework.

The legal basis is Art. 6(1)(b) GDPR where your message concerns the conclusion or performance of a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in handling enquiries).

### Links to External Services

On our location and contact pages you will find buttons that forward you to WhatsApp or to Google Maps. Only when you click such a button is data – in particular your IP address – transmitted to the respective provider. Without a click, no transmission takes place; in particular, no content from these providers is embedded in our pages.

These buttons link to an address belonging to the respective provider itself: **wa.me** for WhatsApp, **maps.app.goo.gl** for Google Maps. These are those providers’ own short addresses, which forward directly to their own destination pages. No third party’s short-link or redirect service is interposed, and we do not evaluate the use of these links statistically.

The processing by WhatsApp (WhatsApp Ireland Limited or WhatsApp LLC) and Google (Google Ireland Limited) is governed by their own privacy policies. We have no influence on the nature and scope of the data processed there. Use is voluntary; you can also reach us at any time via the contact form, by email, or by telephone. What happens to a WhatsApp message after it reaches us is described in the “Chat: Intercom” section – our WhatsApp numbers are connected to Intercom.

## Cookies and Storage on Your Device

Cookies are small text files stored by your browser when you visit a website. In addition to cookies, websites may also use other storage areas of your browser.

Our website stores only information that is necessary for the operation of the website or for a function you have expressly requested. Pursuant to Section 25(2) no. 2 TDDDG, no consent is required for this. Nothing is stored on or read from your device for advertising or analytics purposes.

### When you open our pages

- **dues:lang** (local storage): the language version you have chosen. Stored only after you have actively selected the language or confirmed the language notice – not when you merely open a page. Storage period: until you clear your browser’s storage.
- **dues:lang-dismissed** (session storage): records that you have closed the language notice. Storage period: until the browser tab is closed.

In addition, Cloudflare’s security and protection functions may set technically necessary cookies. Whether and which of these are set in an individual case depends on whether our protection functions trigger a check for your request:

- **\_\_cf\_bm** (Cloudflare): bot detection – storage period: max. 30 min.
- **\_cfuvid** (Cloudflare): distinguishing requests for rate limiting – storage period: session
- **cf\_clearance** (Cloudflare): set once you have passed a security check, so that it does not have to be repeated for every subsequent request – storage period: depends on the configuration of the security check, at most one year.

### Only once you open the chat

The following identifiers are stored only after you have opened the chat (see the “Chat: Intercom” section) by clicking on it. As long as you do not open the chat, none of these identifiers come into existence.

- **intercom-engaged** (local storage, set by us): records that you have opened the chat, so that replies to an ongoing conversation are shown to you on a later visit. Storage period: until you clear your browser’s storage.
- **intercom-session-…** (cookie, Intercom): identifier for the chat session; gives you access to your previous conversation. Storage period: 1 week.
- **intercom-id-…** (cookie, Intercom): pseudonymous identifier by which your conversation is associated with your browser. Storage period: 270 days, extended each time you use the chat again.
- **intercom-device-id-…** (cookie, Intercom): identifier for your device, used to prevent abuse. Storage period: 270 days, extended each time you use the chat again.

### No cookie banner

We do not use a consent management tool (“cookie banner”). The reason is not that our website manages without any storage, but that it stores nothing that would require consent: we embed no advertising, tracking or profiling services, our audience measurement sets no cookies and stores nothing on your device, and the chat is not loaded until you have requested it. Your decision is therefore made where it arises – by opening or not opening the chat – and not in a notice window as you enter the site.

## Data Processing on Our Social Media Pages

We maintain company pages on several social media platforms in order to offer further opportunities to learn about our company and to exchange information. Our company has company pages on the following platforms:

- Facebook (Meta Platforms Ireland Limited, Ireland)
- Instagram (Meta Platforms Ireland Limited, Ireland)
- LinkedIn (LinkedIn Ireland Unlimited Company, Ireland)

If you visit a profile on one of these platforms or interact with it, personal data about you may be processed.

### Facebook and Instagram Page

When you visit our Facebook or Instagram page, certain information about you is processed. The sole controller for this processing is Meta Platforms Ireland Limited (Ireland – “Meta”). Further information about the processing of personal data by Meta is available at <https://www.facebook.com/privacy/explanation>. Meta offers the option to object to certain data processing; related information and opt-out options can be found at <https://www.facebook.com/settings?tab=ads>.

Meta provides us with statistics and insights in anonymized form for our Facebook and Instagram page, which help us gain knowledge about the types of actions people take on our page (so-called “Page Insights”). This processing of personal data is carried out by Meta and us as joint controllers pursuant to Art. 26 GDPR. Meta is primarily responsible for the processing of the Insights data after collection. Data subject rights can be asserted both against us and against Meta. The processing serves our legitimate interest in evaluating the actions taken on our page and improving our page based on these insights. The legal basis is Art. 6(1)(f) GDPR.

We cannot attribute the information obtained via Page Insights to individual profiles. Details about the joint controllership arrangement are available at <https://www.facebook.com/legal/terms/information_about_page_insights_data>.

Please note that, according to Meta’s privacy policies, user data may also be processed in the USA or other third countries. Meta transfers user data only to countries for which an adequacy decision of the European Commission pursuant to Art. 45 GDPR exists or on the basis of appropriate safeguards pursuant to Art. 46 GDPR.

### LinkedIn Company Page

LinkedIn Ireland Unlimited Company (Ireland – “LinkedIn”) is generally the sole controller for the processing of personal data when you visit our LinkedIn page. Further information is available at <https://www.linkedin.com/legal/privacy-policy>.

When you visit our LinkedIn company page, follow this page, or engage with it, LinkedIn processes personal data to provide us with anonymized statistics and insights (so-called “Page Insights”). For this purpose, LinkedIn processes in particular data that you have already provided to LinkedIn via your profile, such as information about your role, country, industry, seniority, company size, and employment status. In addition, LinkedIn processes information about how you interact with our company page.

This processing is carried out by LinkedIn and us as joint controllers pursuant to Art. 26 GDPR. The processing serves our legitimate interest in evaluating the actions taken on our LinkedIn company page and improving it based on these insights. The legal basis is Art. 6(1)(f) GDPR. The joint controllership agreement is available at: <https://legal.linkedin.com/pages-joint-controller-addendum>.

You can exercise your data subject rights both against us and against LinkedIn. You can contact the Data Protection Officer at LinkedIn Ireland via the following link: <https://www.linkedin.com/help/linkedin/ask/TSO-DPO>. You also have the right to lodge a complaint with the competent supervisory authority, e.g., the Irish Data Protection Commission ([https://www.dataprotection.ie](https://www.dataprotection.ie/)) or any other competent supervisory authority.

Please note that, according to LinkedIn’s privacy policies, personal data may also be processed in the USA or other third countries. LinkedIn only transfers personal data to countries for which an adequacy decision exists pursuant to Art. 45 GDPR or on the basis of appropriate safeguards pursuant to Art. 46 GDPR.

### Comments and Direct Messages

We process information that you provide to us via our company pages on the respective social media platforms. Such information may include the username used, contact details, or a message to us. We process this data on the basis of our legitimate interest in communicating with enquiring persons. The legal basis is Art. 6(1)(f) GDPR. Additional processing may occur if you have given consent (Art. 6(1)(a) GDPR) or if it is necessary to comply with a legal obligation (Art. 6(1)(c) GDPR).

## Changes to This Privacy Policy

We reserve the right to amend this privacy policy at any time to ensure it always complies with current legal requirements or to reflect changes in our services. The new privacy policy will apply to your next visit.

This privacy policy is available in German and English. The German version is authoritative; in the event of any discrepancy, it prevails over the English translation.

Last updated: 11 August 2026

## The first step is hardest. We make it easy.

Book your free consultation. We’ll figure out the right course, handle your paperwork, and get you on your way to B1.

[Find your Course](https://dues-eckert.com/integration-courses) [Learn more about our free consultation](https://dues-eckert.com/free-consultation)
