Data privacy

Transparency declaration on the processing of personal data for contractual relationships.

Privacy policy

Company: Equitania Software GmbH, Weiherstraße 13, 75173 Pforzheim, Germany

Phone: +49 7231 166 040

Fax: +49 7231 166 04 200


Managing Directors: Martin Schmid, Hannes Bischoff

Register court: Mannheim

Register number. HRB 511803

Sales tax identification number according to § 27a sales tax law: DE814544688

Data Protection Officer of Equitania Software GmbH:

c/o TÜV SÜD Akademie GmbH

Westendstrasse 160

80339 Munich



It is possible to use our website without providing personal data. Different regulations may apply to the use of individual services on our website, which are explained separately below. Your personal data (e.g. name, address, e-mail, telephone number, etc.) will only be processed by us in accordance with the provisions of German data protection law. Data is considered personal if it can be clearly assigned to a specific natural person. The legal basis for data protection can be found in the General Data Protection Regulation (GDPR). The following regulations inform you in this respect about the type, scope and purpose of the collection, use and processing of personal data by the provider.

1.basic information on data processing and legal basis

1.1. this data protection declaration clarifies the type, scope and purpose of the processing of personal data within our online offer and the associated websites, functions and content (hereinafter jointly referred to as "online offer" or "website"). The privacy policy applies regardless of the domains, systems, platforms and devices (e.g. desktop or mobile) on which the online offer is executed.

1.2. the terms used, such as "personal data" or their "processing", we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

1.3. the personal data of users processed in the context of this online offer includes inventory data (e.g., names and addresses of customers), contract data (e.g., services used, names of clerks, payment information), usage data (e.g., the websites visited on our online offer, interest in our products) and content data (e.g., entries in the contact form).

1.4 The term "user" includes all categories of data subjects affected by data processing. These include our business partners, customers, interested parties and other visitors to our online offering. The terms used, such as "user", are to be understood as gender-neutral.

1.5 We only process users' personal data in compliance with the relevant data protection regulations. This means that user data will only be processed if we have legal permission to do so. I.e., in particular if the data processing is necessary for the provision of our contractual services (e.g. processing of orders) and online services, or is required by law, if the user has given consent, as well as on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation and security of our online offer within the meaning of Art. 6 para. 1 lit. f. GDPR, in particular in the case of reach measurement, creation of profiles and advertising profiles). GDPR, in particular when measuring reach, creating profiles for advertising and marketing purposes and collecting access data and using the services of third-party providers.

1.6. we would like to point out that the legal basis for the consents is Art. 6 para. 1 lit. a. and Art. 7 GDPR, the legal basis for the processing for the fulfillment of our services and implementation of contractual measures Art. 6 para. 1 lit. b. GDPR, the legal basis for processing for the fulfillment of our legal obligations Art. 6 para. 1 lit. c. GDPR, and the legal basis for the processing for the protection of our legitimate interests Art. 6 para. 1 lit. f. GDPR is. measures

2.1. we take organizational, contractual and technical security measures in accordance with the state of the art to ensure that the provisions of data protection laws are complied with and to protect the data processed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons.

2.2. security measures include in particular the encrypted transmission of data between your browser and our server.

Our website uses SSL encryption when it comes to the transmission of confidential or personal content of our users. This encryption is activated, for example, when processing payment transactions and for inquiries that you send to us via our website. Please make sure that SSL encryption is activated on your side for corresponding activities. The use of encryption is easy to recognize: the display in your browser line changes from "http://" to "https://". Data encrypted via SSL cannot be read by third parties. Only transmit your confidential information if SSL encryption is activated and contact us if in doubt.

3.disclosure of data to third parties and third-party providers

3.1. your data will only be used by us within Equitania Software GmbH and its affiliated companies within the CMC Group. We will only pass on your data to other third parties to the extent described below.

3.2. data will only be passed on to third parties within the framework of the legal requirements. We only pass on user data to third parties if this is necessary, for example, on the basis of Art. 6 para. 1 lit. b) GDPR for contractual purposes or on the basis of legitimate interests pursuant to Art. 6 para. 1 lit. f. GDPR in the economic and effective operation of our business operations

3.3. if we use subcontractors to provide our services, we take appropriate legal precautions and appropriate technical and organizational measures to ensure the protection of personal data in accordance with the relevant legal regulations

3.4. if content, tools or other means from other providers (hereinafter collectively referred to as "third-party providers") are used within the scope of this privacy policy and their registered office is located in a third country, it must be assumed that data will be transferred to the countries in which the third-party providers are based. Third countries are countries in which the GDPR is not directly applicable law, i.e. generally countries outside the EU or the European Economic Area. The transfer of data to third countries takes place either if there is an adequate level of data protection, user consent or other legal permission.

4.provision of contractual services

4.1. we process inventory data (e.g., names and addresses as well as contact data of users), contract data (e.g., services used, names of contact persons, payment information) for the purpose of fulfilling our contractual obligations and services in accordance with Art. 6 para. 1 lit. b. GDPR. GDPR.

4.2 If you wish to use the paid services offered on our website, we may need to collect additional data from you for billing purposes and for security reasons. This usually involves your name, a valid e-mail address and, if applicable, your address and telephone number and, depending on the individual case, other information. This may also involve content that allows us to verify the data provided, such as your ownership of the e-mail address provided. For legal reasons, we must ensure that you actually wish to receive the services offered and that we can properly invoice you for the service. We work with the SSL encryption standard in payment transactions to secure your data, recognizable by the browser line "https://".

4.3. users can optionally create a user account in which they can view their orders in particular. As part of the registration process, users will be provided with the required mandatory information. The user accounts are not public and cannot be indexed by search engines. If users have terminated their user account, their data will be deleted with regard to the user account, subject to their retention is necessary for commercial or tax law reasons in accordance with Art. 6 para. 1 lit. c GDPR. It is the responsibility of the users to back up their data in the event of termination before the end of the contract. We are entitled to irretrievably delete all user data stored during the term of the contract.

4.4 In the context of registration and renewed logins as well as use of our online services, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as those of the user in protection against misuse and other unauthorized use. This data is not passed on to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Art. 6 para. 1 lit. c GDPR.

4.5. we process usage data (e.g., the websites visited on our online offering, interest in our products) and content data (e.g., entries in the contact form or user profile) for advertising purposes in a user profile, e.g., to display product information to users based on the services they have used to date. us

5.1. when contacting us (via contact form or e-mail), the user's details are processed to process the contact request and its handling in accordance with Art. 6 Para. 1 lit. b) GDPR.

5.2. user data may be stored in our Customer Relationship Management System ("CRM System") or comparable inquiry organization.

6.collection of access data and log files

6.1. on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. GDPR. GDPR, we collect data about every access to the server on which this service is located (so-called server log files). The access data includes the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider.

6.2. Logfile-Informationen werden aus Sicherheitsgründen (z.B. zur Aufklärung von Missbrauchs- oder Betrugshandlungen) für die Dauer von maximal sieben Tagen gespeichert und danach gelöscht. Daten, deren weitere Aufbewahrung zu Beweiszwecken erforderlich ist, sind bis zur endgültigen Klärung des jeweiligen Vorfalls von der Löschung ausgenommen.

7.cookies & reach measurement

7.1. cookies are information that is transferred from our web server or third-party web servers to the user's web browser and stored there for later retrieval. Cookies may be small files or other types of information storage.

7.2. we use "session cookies", which are only stored for the duration of the current visit to our online presence (e.g. to enable the storage of your login status or the shopping cart function and thus the use of our online offer at all). A randomly generated unique identification number, a so-called session ID, is stored in a session cookie. In addition, a cookie contains information about its origin and the storage period. These cookies cannot store any other data. Session cookies are deleted when you have finished using our online offer and log out or close the browser, for example.

7.3. users are informed about the use of cookies in the context of pseudonymous reach measurement in the context of this data protection declaration.

7.4. if users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in the system settings of their browser. Stored cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer.

7.5. you can opt out of the use of cookies for reach measurement and advertising purposes via the deactivation page of the Network Advertising Initiative ( ) and additionally the US-American website ( ) or the European website ( ) contradict.

8.integration of third-party services and content

8.1. within our online offer on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f. DSGVO). GDPR) content or service offers from third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as "content"). This always presupposes that the third-party providers of this content are aware of the IP address of the user, as they would not be able to send the content to their browser without the IP address. The IP address is therefore required to display this content. We endeavor to only use content whose respective providers only use the IP address to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Pixel tags can be used to analyze information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our online offer, as well as being linked to such information from other sources.

8.2. the following lists provide an overview of third-party providers and their content, together with links to their data protection declarations, which contain further information on the processing of data and, in some cases already mentioned here, options for objection (so-called opt-out): Analytics with anonymization function

9.1. on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f. GDPR). GDPR) Google Analytics, a web analytics service provided by Google Inc. ("Google") Google uses cookies. The information generated by the cookie about the use of the online offer by the user is usually transmitted to a Google server in the USA and stored there.

9.2. Google is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection law ( ).

9.3. google will use this information on our behalf to evaluate the use of our online offer by users, to compile reports on the activities within this online offer and to provide us with further services associated with the use of this online offer and the use of the Internet. Pseudonymous user profiles can be created from the processed data.

9.4. Wir setzen Google Analytics ein, um die durch innerhalb von Werbediensten Googles und seiner Partner geschalteten Anzeigen, nur solchen Nutzern anzuzeigen, die auch ein Interesse an unserem Onlineangebot gezeigt haben oder die bestimmte Merkmale (z.B. Interessen an bestimmten Themen oder Produkten, die anhand der besuchten Webseiten bestimmt werden) aufweisen, die wir an Google übermitteln (sog. „Remarketing-“, bzw. „Google-Analytics-Audiences“). Mit Hilfe der Remarketing Audiences möchten wir auch sicherstellen, dass unsere Anzeigen dem potentiellen Interesse der Nutzer entsprechen und nicht belästigend wirken.

9.5. Wir setzen Google Analytics nur   mit aktivierter IP-Anonymisierung ein. Das bedeutet, die IP-Adresse der Nutzer wird von Google innerhalb von Mitgliedstaaten der Europäischen Union oder in anderen Vertragsstaaten des Abkommens über den Europäischen Wirtschaftsraum gekürzt. Nur in Ausnahmefällen wird die volle IP-Adresse an einen Server von Google in den USA übertragen und dort gekürzt.

9.6. Die von dem Browser des Nutzers übermittelte IP-Adresse wird nicht mit anderen Daten von Google zusammengeführt. Die Nutzer können die Speicherung der Cookies durch eine entsprechende Einstellung ihrer Browser-Software verhindern; die Nutzer können darüber hinaus die Erfassung der durch das Cookie erzeugten und auf ihre Nutzung des Onlineangebotes bezogenen Daten an Google sowie die Verarbeitung dieser Daten durch Google verhindern, indem sie das unter folgendem Link verfügbare Browser-Plugin herunterladen und installieren: .

9.7 You can find further information on the use of data by Google, setting and objection options on Google's websites: ("Data use by Google when you use our partners' websites or apps"), ("Use of data for advertising purposes"), ("Manage information that Google uses to show you advertising"). Re/Marketing Services

10.1. Wir nutzen auf Grundlage unserer berechtigten Interessen (d.h. Interesse an der Analyse, Optimierung und wirtschaftlichem Betrieb unseres Onlineangebotes im Sinne des Art. 6 Abs. 1 lit. f. DSGVO) die Marketing- und Remarketing-Dienste (kurz „Google-Marketing-Services”) der Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, („Google“).

10.2. Google is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection law ( ).

10.3. Die Google-Marketing-Services erlauben uns Werbeanzeigen für und auf unserer Website gezielter anzuzeigen, um Nutzern nur Anzeigen zu präsentieren, die potentiell deren Interessen entsprechen. Falls einem Nutzer z.B. Anzeigen für Produkte angezeigt werden, für die er sich auf anderen Webseiten interessiert hat, spricht man hierbei vom „Remarketing“. Zu diesen Zwecken wird bei Aufruf unserer und anderer Webseiten, auf denen Google-Marketing-Services aktiv sind, unmittelbar durch Google ein Code von Google ausgeführt und es werden sog. (Re)marketing-Tags (unsichtbare Grafiken oder Code, auch als "Web Beacons" bezeichnet) in die Webseite eingebunden. Mit deren Hilfe wird auf dem Gerät der Nutzer ein individuelles Cookie, d.h. eine kleine Datei abgespeichert (statt Cookies können auch vergleichbare Technologien verwendet werden). Die Cookies können von verschiedenen Domains gesetzt werden, unter anderem von , , , , or . In dieser Datei wird vermerkt, welche Webseiten der Nutzer aufgesucht, für welche Inhalte er sich interessiert und welche Angebote er geklickt hat, ferner technische Informationen zum Browser und Betriebssystem, verweisende Webseiten, Besuchszeit sowie weitere Angaben zur Nutzung des Onlineangebotes. Es wird ebenfalls die IP-Adresse der Nutzer erfasst, wobei wir im Rahmen von Google-Analytics mitteilen, dass die IP-Adresse innerhalb von Mitgliedstaaten der Europäischen Union oder in anderen Vertragsstaaten des Abkommens über den Europäischen Wirtschaftsraum gekürzt und nur in Ausnahmefällen ganz an einen Server von Google in den USA übertragen und dort gekürzt wird. Die IP-Adresse wird nicht mit Daten des Nutzers innerhalb von anderen Angeboten von Google zusammengeführt. Die vorstehend genannten Informationen können seitens Google auch mit solchen Informationen aus anderen Quellen verbunden werden. Wenn der Nutzer anschließend andere Webseiten besucht, können ihm entsprechend seiner Interessen die auf ihn abgestimmten Anzeigen angezeigt werden.

10.4. Die Daten der Nutzer werden im Rahmen der Google-Marketing-Services pseudonym verarbeitet. D.h. Google speichert und verarbeitet z.B. nicht den Namen oder E-Mailadresse der Nutzer, sondern verarbeitet die relevanten Daten Cookie-bezogen innerhalb pseudonymer Nutzer-Profile. D.h. aus der Sicht von Google werden die Anzeigen nicht für eine konkret identifizierte Person verwaltet und angezeigt, sondern für den Cookie-Inhaber, unabhängig davon wer dieser Cookie-Inhaber ist. Dies gilt nicht, wenn ein Nutzer Google ausdrücklich erlaubt hat, die Daten ohne diese Pseudonymisierung zu verarbeiten. Die von Google-Marketing-Services über die Nutzer gesammelten Informationen werden an Google übermittelt und auf Googles Servern in den USA gespeichert.

10.5. we may also use the "Google Tag Manager" to integrate and manage Google analysis and marketing services on our website.

10.6 For more information about Google's use of data for marketing purposes, please visit the overview page: google's privacy policy is available at available.

10.7. if you wish to object to interest-based advertising by Google marketing services, you can use the setting and opt-out options provided by Google:

11.use of PayPal as a payment method

If you decide to pay with the online payment service provider PayPal as part of your order process, your contact details will be transmitted to PayPal as part of the order triggered in this way. PayPal is an offer from PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal assumes the function of an online payment service provider as well as a trustee and offers buyer protection services.

The personal data transmitted to PayPal is usually first name, last name, address, telephone number, IP address, e-mail address, or other data required for order processing, as well as data related to the order, such as number of items, item number, invoice amount and taxes as a percentage, billing information, etc.

This transmission is necessary to process your order with the payment method you have selected, in particular to confirm your identity, to administer your payment and the customer relationship.

Please note, however, that PayPal may also pass on personal data to service providers, subcontractors or other affiliated companies if this is necessary to fulfill the contractual obligations arising from your order or if the personal data is to be processed on behalf of PayPal.

Depending on the payment method selected via PayPal, e.g. invoice or direct debit, the personal data transmitted to PayPal will be transmitted by PayPal to credit agencies. This transmission is used to check your identity and creditworthiness in relation to the order you have placed. To find out which credit agencies are involved and which data is generally collected, processed, stored and passed on by PayPal, please refer to PayPal's privacy policy at

12.use of Google Maps

We use the "Google Maps" component of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as "Google", on our website.

Each time the "Google Maps" component is called up, Google sets a cookie to process user settings and data when the page on which the "Google Maps" component is integrated is displayed. As a rule, this cookie is not deleted when the browser is closed, but expires after a certain period of time, unless you delete it manually beforehand.

If you do not agree with this processing of your data, you have the option of deactivating the "Google Maps" service and thus preventing the transfer of data to Google. To do this, you must deactivate the Java Script function in your browser. However, we would like to point out that in this case you will not be able to use "Google Maps" or only to a limited extent.

The use of "Google Maps" and the information obtained via "Google Maps" is subject to the Google Terms of Use

and the additional terms and conditions for "Google Maps"

13.use of reCAPTCHA

To protect input forms on our website, we use the "reCAPTCHA" service provided by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as "Google". By using this service, it is possible to distinguish whether the corresponding input is of human origin or whether it is misused by automated machine processing.

To our knowledge, the referrer URL, the IP address, the behavior of website visitors, information about the operating system, browser and length of stay, cookies, display instructions and scripts, the user's input behavior and mouse movements in the "reCAPTCHA" checkbox area are transmitted to "Google".

Among other things, Google uses the information obtained in this way to digitize books and other printed materials and to optimize services such as Google Street View and Google Maps (e.g. house number and street name recognition).

The IP address transmitted as part of "reCAPTCHA" will not be merged with other Google data unless you are logged into your Google account at the time you use the "reCAPTCHA" plug-in. If you want to prevent this transmission and storage of data about you and your behavior on our website by "Google", you must log out of "Google" before you visit our site or use the reCAPTCHA plug-in.

The use of the "reCAPTCHA" service is carried out in accordance with the Google Terms of Use:

14.use of YouTube components with extended data protection mode

On our website, we use components (videos) from YouTube, LLC 901 Cherry Ave, 94066 San Bruno, CA, USA, a company of Google Inc, Amphitheatre Parkway, Mountain View, CA 94043, USA.

We use the " - extended data protection mode - " option provided by YouTube.

When you access a page that has an embedded video, a connection to the YouTube servers is established and the content is displayed on the website by notifying your browser.

According to YouTube, in " - extended data protection mode -" only data is transmitted to the YouTube server, in particular which of our Internet pages you have visited when you watch the video. If you are logged in to YouTube at the same time, this information is assigned to your YouTube member account. You can prevent this by logging out of your member account before visiting our website.

Further information on data protection from YouTube is provided by Google under the following link:

15.use of Twitter

Functions of the Twitter service may be integrated into our online offering. These functions are offered by Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. By using Twitter and the "Re-Tweet" function, the websites you visit are linked to your Twitter account and made known to other users. We would like to point out that, as the provider of the website, we have no knowledge of the content of the data transmitted or how it is used by Twitter. Twitter's privacy policy can be found at You can change your data protection settings on Twitter in the account settings under ändern.


External code of the JavaScript framework "jQuery", provided by the third-party provider jQuery Foundation,