General Data Protection Regulation (GDPR)
One of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by ExciteLab and how we use it.
If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.
1. The person responsible for
this website in terms of data protection law is ExciteLab GmbH, Freiberger Straße 37, 01067 Dresden, represented by the managing directors, e-mail: info@excitelab.co.
2. Visiting our website
When you visit our website, the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the retrieved file
- Website from which the access is made (referrer URL)
- the browser used and, if applicable, the operating system of your computer and the name of your access provider.
This data is processed in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. The legitimate interest arises from ensuring the technical functionality of our website.
The log files are deleted after 6 months.
3. Third-party sites
Insofar as we provide links to other websites on the site, our privacy policy does not apply to these sites. Please read the respective data protection notices. Due to our lack of influence, we are not liable for the content and effects of external websites. We also do not receive any data about you from the external websites if you follow the links or enter data on the linked pages.
4. Technology
4.1 SSL/TLS encryption
This site uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of confidential content, such as orders, login data or contact requests that you send to us as the operator. You can recognize an encrypted connection by the fact that the address line of the browser contains "https://" instead of "http://" and by the lock symbol in your browser line.
We use this technology to protect your transmitted data.
4.2 Hosting by Hubspot
We host our website with HubSpot Ireland Limited, HUBSPOT HOUSE, 662881, Ireland.
When you visit our website, your personal data (e.g. IP addresses in log files) is processed on Hubspot's servers.
The use of Hubspot is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the most reliable presentation, provision and security of our website.
5. Analysis, advertising tracking
5.1 Use of Google Analytics
On our website, we use the web analysis service Google Analytics from Google LLC. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). If you have your habitual residence in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller responsible for your data. Google Ireland Limited is therefore the company affiliated with Google that is responsible for the processing of your data and compliance with the applicable data protection laws, and the data processing serves the purpose of analyzing this website and its visitors as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator. The following information may be collected: IP address, date and time of the page view, click path, information about the browser you are using and the device you are using, pages visited, referrer URL (website from which you accessed our website), location data, purchase activities. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.Google Analytics uses technologies such as cookies, web storage in the browser and tracking pixels that enable your use of the website to be analyzed. The information generated about your use of this website is usually transmitted to a Google server in the USA and stored there. There is no adequacy decision by the EU Commission for the USA. The data transfer takes place on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at:
https://policies.google.com/privacy/frameworks. Both Google and US state authorities have access to your data. Your data may be linked by Google with other data, such as your search history, your personal accounts, your usage data from other devices and any other data that Google has about you, and IP anonymization is activated on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.the use of cookies or comparable technologies takes place with your consent on the basis of § 15 para. 3 sentence 1 TMG i.V.m. Art. 6 para. 1 lit. a GDPR. Your personal data is processed with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. You can find more information on terms of use and data protection at
https://www.google.com/analytics/terms/de.html or at
https://www.google.de/intl/de/policies/ and at
https://policies.google.com/technologies/cookies?hl=de.
5.2 Use of the Google Tag Manager
On our website, we use the Google Tag Manager of Google LLC. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google") on our website. If you have your habitual residence in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller responsible for your data. Google Ireland Limited is therefore the company affiliated with Google that is responsible for processing your data and complying with the applicable data protection laws.this application is used to manage JavaScript tags and HTML tags that are used to implement tracking and analysis tools in particular. The data processing serves the purpose of designing and optimizing our website in line with requirements, and the Google Tag Manager itself does not store cookies or process personal data. However, it enables the triggering of other tags that can collect and process personal data.you can find more information on terms of use and data protection
here.
6. Cookies
6.1 General information about cookies
Cookies are small files that your browser automatically creates and that are stored on your IT system (laptop, tablet, smartphone, etc.) when you visit our website.
Information is stored in the cookie that results from the connection with the specific end device used. However, this does not mean that we obtain direct knowledge of your identity.
The use of cookies serves to make the use of our website more pleasant for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of our website. These are automatically deleted after you leave our site.
In addition, we also use temporary cookies to optimize user-friendliness, which are stored on your end device for a specified period of time. If you visit our site again to use our services, it is automatically recognized that you have already visited us and which entries and settings you have made so that you do not have to enter them again.
The respective storage duration of the cookies can be found in the settings of the consent tool used.
6.2 Legal basis for the use of cookies
The data processed by the cookies, which are required for the proper functioning of the website, are therefore necessary to safeguard our legitimate interests and those of third parties in accordance with Art. 6 para. 1 lit. f GDPR.
For all other cookies, you have given your consent to this via our opt-in cookie banner within the meaning of Art. 6 para. 1 lit. a GDPR.
6.3 Notes on avoiding cookies in common browsers
You can delete cookies, allow only selected cookies or deactivate cookies completely at any time via the settings of the browser you are using. Further information can be found on the support pages of the respective providers:
6.4 Hubspot Cookie (Consent Management Tool)
We use the Hubspot cookie plugin from HubSpot Ireland Limited, HUBSPOT HOUSE, 662881, Ireland. This service enables us to obtain and manage the consent of website users for data processing.
Hubspot Cookie uses cookies to collect data generated by end users who use our website. If an end user gives consent, the following data, among others, is automatically logged by the plugin at Complianz:
● Cookie runtime,
● Cookie version,
● Domain and path of the Hubspot page,
● Selection in the cookie banner,
● UID (a randomly generated ID),
The consent status is also stored in the end user's browser so that the website can automatically read and follow the end user's consent in all subsequent page requests and future end user sessions for up to 12 months. The consent data (consent and withdrawal of consent) is stored for three years. The retention period corresponds to the regular limitation period pursuant to Section 195 of the German Civil Code (BGB). The data will then be deleted immediately.
The functionality of the website is not guaranteed without the described processing. The user has no right to object as long as there is a legal obligation to obtain the user's consent to certain data processing operations, Art. 7 para. 1, 6 para. 1 sentence 1 lit. c GDPR.
The data collected will not be forwarded to Hubspot, nor will it have access to it.
7. Contact
If you send us a message using the contact details provided on our website, your contact details and all other personal data resulting from the message will be processed by us for the purpose of processing the request
The personal data processed by us may include
- Salutation
- First and last name
- Address
- Telephone or fax number
- E-mail address
This data is processed on the basis of your (implied) consent in accordance with Art. 6 para. 1 lit. a GDPR.If the communication serves to initiate a business transaction, the processing is also carried out on the basis of Art. 6 para. 1 sentence 1 lit. b GD
The data will be deleted immediately after the matter has been processed, unless the communication is necessary for the defense or assertion of claims or must be retained due to tax law requirements. In this case, the deletion takes place after three years, starting with the year following the year in which the communication took place, or after 10 years.
8. Our activities in social networks
So that we can also communicate with you on social networks and inform you about our services, we have our own pages there. If you visit one of our social media pages, we are jointly responsible with the provider of the respective social media platform for the processing operations triggered by this, within the meaning of Art. 26 GDPR.
We are not the original provider of these pages, but only use them within the scope of the possibilities offered to us by the respective providers.
As a precautionary measure, we would therefore like to point out that your data may also be processed outside the European Union or the European Economic Area. Use may therefore be associated with data protection risks for you, as it may be more difficult to safeguard your rights, e.g. to information, deletion, objection, etc., and processing in social networks is often carried out directly for advertising purposes or for the analysis of user behavior by the providers without us being able to influence this. If user profiles are created by the provider, cookies are often used or the user behavior is assigned to your own social network member profile.
The described processing operations of personal data are carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest and the legitimate interest of the respective provider in order to be able to communicate with you in a timely manner or to inform you about our services. If you have to give your consent to data processing as a user with the respective providers, the legal basis is Art. 6 para. 1 lit. a GDPR in conjunction with Art. 7 GDPR. Art. 7 GDPR.
As we do not have access to the providers' databases, we would like to point out that it is best to assert your rights (e.g. to information, correction, deletion, etc.) directly with the respective provider. Further information on the processing of your data in the social networks is provided below by the respective social network provider we use:
8.1 Meta
(Joint) controller for data processing in Europe: Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
8.2 LinkedIn
(Joint) controller for data processing in Europe:
LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland
8.3 X
(Joint) controller for data processing in Europe: X International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland
8.4 YouTube
(Joint) controller for data processing in Europe:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
9. Social media plugins
9.1 LinkedIn plugin
We have integrated components of the LinkedIn Corporation on this website. LinkedIn is an Internet-based social network that enables users to connect with existing business contacts and make new business contacts.
The operating company of LinkedIn is LinkedIn Corporation, 2029 Stierlin Court Mountain View, CA 94043, USA. LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible for data protection matters outside the USA.
Each time you access our website, which is equipped with a LinkedIn component (LinkedIn plugin), this component causes the browser you are using to download a corresponding representation of the LinkedIn component. Further information about the LinkedIn plug-ins may be accessed under
https://developer.linkedin.com/plugins. As part of this technical process, LinkedIn receives information about which specific subpage of our website you have visited.
If you are logged in to LinkedIn at the same time, LinkedIn recognizes which specific subpage of our website you are visiting each time you access our website and for the entire duration of your visit to our website. This information is collected by the LinkedIn component and assigned to your LinkedIn account by LinkedIn. If you click on a LinkedIn button integrated on our website, LinkedIn assigns this information to your personal LinkedIn user account and stores this personal data.
LinkedIn always receives information via the LinkedIn component that you have visited our website if you are logged in to LinkedIn at the same time as accessing our website; this occurs regardless of whether you have clicked on the LinkedIn component or not. If you do not want this information to be transmitted to LinkedIn, you can prevent it from being transmitted by logging out of your LinkedIn account before accessing our website.
10. HubSpot
We use HubSpot to manage our customers. This service is provided by HubSpot Ireland Limited, HUBSPOT HOUSE, 662881, Ireland.
The following personal data is processed: Name, e-mail address, telephone number, address, company. If you provide us with CVs or other files, all personal data contained in these documents will also be processed by us.
This data is processed on the basis of your (implied) consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR, for the performance of a contractual relationship pursuant to Art. 6 para. 1 lit. b GDPR and on the basis of our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR The legitimate interest lies in the effective organization of business operations.
We process the personal data resulting from the transmitted message until the purpose has been achieved, deleted after 10 years at the latest.
11. Font Awesome
Font Awesome is a font service provided by Fonticons 307 S. Main St., Suite 202, Bentonville, AR 72712, USA. Font Awesome collects the following data:
IP address
- operating system
- browser information
The purpose of using this service is to display the website content correctly and optimally The fonts and symbols used are integrated locally.
The legal basis for storage is your consent within the meaning of Art. 6 para. 1 sentence 1 lit. a GDPR
We do not store the data. However, this does not necessarily apply to processing by Font Awesome. You can find out more about the storage and processing of data at Font Awesome at
https://fontawesome.com/privacy.
12. Cloudflare
We use Cloudflare to protect our services and servers. This is a reverse proxy designed to prevent cyber attacks (e.g. DDoS attacks). The service is provided by Cloudflare, Inc, 101 Townsend St, San Francisco, CA 94107, USA.
The following personal data is processed:
- IP address
- Referrer URL
- URL of the website accessed
- Information on the system configuration and the device
This data is processed on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR. The legitimate interest lies in the protection of our services and servers.
We do not store the data.
Further information on data protection at Cloudflare can be found at the following
linkhttps://www.cloudflare.com/privacypolicy/.
13. Rights of data subjects
You have the right:
-
in accordance with Art. 7 para. 3 GDPR, to withdraw consent once given to us at any time. As a result, we may no longer continue the data processing that was based on this consent in the future;
-
to request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, and the existence of automated decision-making including profiling and, if applicable, meaningful information about its details;
-
in accordance with Art. 16 GDPR, to immediately request the correction of incorrect or incomplete personal data stored by us;
-
in accordance with Art. 17 GDPR, to demand the deletion of your personal data stored by us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
-
in accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data if the accuracy of the data is disputed by you, the processing is unlawful but you refuse to delete it and we no longer need the data, but you need it to assert, exercise or defend legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR;
-
in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller
-
to object to the processing of your personal data in accordance with Art. 21 GDPR, provided that the processing is based on our legitimate interest and there are reasons for the objection arising from your particular situation and
-
to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.