Loading (custom)...

Privacy Policy and Data Protection

Privacy Policy of Brightest GmbH

Effective from August 10th, 2026
Note on the authoritative language version
As Brightest is a company based in Germany, the German version of this privacy document is the authoritative original version. Translations into other languages are provided only as a service and to make the document easier to understand. If there are any differences, uncertainties, or contradictions between the German version and a translation, the German version shall apply.

We are very pleased that you are interested in our company. Data protection is particularly important to the management of Brightest GmbH in Berlin. In general, you can use our websites without providing any personal data. However, if a data subject wishes to use certain services offered by our company through our website, it may be necessary to process personal data. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain the consent of the data subject.

Personal data, such as a data subject’s name, address, email address, or telephone number, is always processed in accordance with the General Data Protection Regulation (GDPR) and the country-specific data protection rules that apply to us. Through this Privacy Policy, we would like to inform the public about the type, scope, and purpose of the personal data that we collect, use, and process. This Privacy Policy also informs data subjects about their rights.

As the controller responsible for processing, Brightest GmbH, Berlin, has implemented a range of technical and organisational measures to provide the best possible protection for the personal data processed through this website. However, data transmitted over the Internet may have security weaknesses, which means that complete protection cannot be guaranteed. For this reason, every data subject is free to provide personal data to us by other means, for example by telephone.

1. Definitions

The Privacy Policy of Brightest GmbH, Berlin, is based on the terms used in the General Data Protection Regulation (GDPR). Our Privacy Policy should be easy to read and understand for the general public as well as for our customers and business partners. To ensure this, we would first like to explain the terminology used.

In this Privacy Policy, we use the following terms, among others:

a) Personal data

Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more specific factors relating to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

b) Data subject

A data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.

c) Processing

Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or any other form of making available, alignment or combination, restriction, erasure, or destruction.

d) Restriction of processing

Restriction of processing means marking stored personal data to limit its future processing.

e) Controller or controller responsible for the processing

The controller, or the controller responsible for the processing, is the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of such processing are determined by European Union law or the law of the Member States, the controller or the specific criteria for appointing the controller may be provided for by European Union law or the law of the Member States.

f) Processor

A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.

g) Recipient

A recipient is a natural or legal person, public authority, agency, or other body to which personal data is disclosed, whether or not it is a third party. However, public authorities that may receive personal data as part of a specific investigation under European Union law or the law of the Member States are not considered recipients.

h) Third party

A third party is a natural or legal person, public authority, agency, or other body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

i) Consent

Consent means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, in the form of a statement or another clear affirmative action, by which the data subject confirms that they agree to the processing of personal data relating to them.

 

2. Name and Address of the Controller Responsible for the Processing

The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union, and other provisions relating to data protection is:

  • Brightest GmbH
  • Lehmbruckstr. 18, 10245 Berlin
  • Tel.: +49 (0) 176 7074 2936
  • Email: info@brightest.org
  • Website: www.brightest.org

Questions and requests for information, correction, restriction, or deletion may be submitted by post to this address or by email to info@brightest.org. 

 

3. Name and Address of the Data Protection Officer

The Data Protection Officer of the controller responsible for the processing is:

  • Günter Hilgers (EcoVisio GmbH)
  • Rheinwerkalle 3, 53227 Bonn
  • Email: dataprotection@brightest.com

Any data subject may contact our Data Protection Officer directly at any time with any questions or suggestions concerning data protection.

 

4. Contact Details of the Supervisory Authority

The competent supervisory authority for the controller responsible for the processing is:

  • Name: Berlin Commissioner for Data Protection and Freedom of Information
  • Street: Friedrichstraße 219
  • City: 10969 Berlin
  • Telephone: +49 (0) 13889-0
  • Fax: +49 (0) 2155050
  • Email: mailbox@datenschutz-berlin.de

 

5. External Hosting

This website is hosted by an external service provider (hosting provider). We have commissioned:

  • Amazon Web Services EMEA SARL
  • 38 Avenue John F. Kennedy, L-1855 Luxembourg (Luxembourg)

Personal data collected on this website is stored on the hosting provider’s servers. This may include, in particular, IP addresses, contact requests, metadata and communication data, contract data, contact details, names, website visits, and other data generated through a website.

We use the hosting provider to fulfil our contracts with potential and existing customers (Art. 6(1)(b) GDPR) and in our legitimate interest in providing our online services securely, quickly, and efficiently through a professional provider (Art. 6(1)(f) GDPR).

Our hosting provider will process your data only to the extent necessary to fulfil its service obligations and will follow our instructions regarding this data.

Conclusion of a Data Processing Agreement

To ensure that data is processed in accordance with data protection requirements, we have concluded a Data Processing Agreement with the service provider under Art. 28 GDPR.

 

6. Cookies

We use cookies on our websites. A cookie is a small data file stored on your device that contains information such as personal page settings and login information. This data file is created and sent to you by the web server to which you have connected through your web browser. In general, we use cookies to analyse interest in our websites and improve their user-friendliness. In principle, you can also access our websites without cookies. However, if you wish to use our websites fully and conveniently, you should accept the cookies that enable certain functions or make them easier to use. The purposes of the cookies we use are explained in the consent management system when you first visit our website. You can review them later by opening the cookie services settings under “Cookies” on our website. When using our websites, you will be asked to consent to the use of cookies unless they are necessary for the proper operation of the websites. You can decide whether to consent to cookies that require consent through the consent manager on our website.

You can also configure your browser to display cookies before they are stored, to accept or reject only certain cookies, or to reject all cookies. Please note that any changes to your browser settings apply only to that particular browser. If you use different browsers or switch devices, you will need to configure the settings again. You can also delete cookies from your browser at any time. For information about cookie settings, how to change them, and how to delete cookies, please refer to your web browser’s help function.

A distinction is made between session cookies, which are deleted when you close your browser, and permanent cookies, which remain stored beyond an individual session. Cookies can also be divided into the following categories according to their function:

6.1 Essential / Necessary Cookies

These cookies are strictly necessary for the operation of the website. They ensure that basic technical processes and essential services work reliably. Essential cookies include, in particular, those that ensure users remain logged in, that shopping basket functions work correctly, that security-related settings are applied, and that cookie consent choices are stored correctly.

As essential cookies are strictly necessary for the website to operate, they may be placed on your device without your consent. The legal basis for this is Section 25(2) TDDDG. Where personal data is processed, the processing is based on Art. 6(1), sentence 1(b) GDPR (performance of a contract, e.g. a shopping basket) or Art. 6(1), sentence 1(f) GDPR (legitimate interest in providing a secure and functional website).

6.2 Functional Cookies

These cookies improve the website's user-friendliness. Although they are not strictly necessary for its operation, they make it much more convenient to use. This includes, in particular, storing settings such as language, display preferences, and region, as well as information already entered, so it does not need to be entered again when you return to the website.

As functional cookies are not necessary for the website to operate, they may be placed only with your consent. The legal bases for the use of these cookies are Art. 6(1), sentence 1(a) GDPR (consent to the processing of personal data) and Section 25(1) TDDDG (access to information on a device only with consent).

6.3 Performance / Analytics Cookies

Performance and analytics cookies are used to statistically evaluate user behaviour and optimise the website. These cookies help us, as the website operator, understand how you use our website. For example, we collect information about which pages are visited most often, how long visitors remain on individual pages, whether error messages occur, which links or search terms bring visitors to the website, which devices, browsers, or screen sizes are used, and how quickly content loads. The information processed is used only to optimise our website and improve the user experience.

Data collected through performance and analytics cookies is generally processed in anonymised or pseudonymised form. We do not intend to identify the data subject.

As performance and analytics cookies are not necessary for the website to operate, they may only be placed with your consent. The legal bases for the use of these cookies are Art. 6(1), sentence 1(a) GDPR (consent to the processing of personal data) and Section 25(1) TDDDG (access to information on a device only with consent).

6.4 Tracking and Advertising Cookies

Tracking and advertising cookies record user behaviour across websites to display personalised advertising. These cookies enable the creation of interest profiles, the measurement of advertising campaign effectiveness, and the formation of user groups (“audiences”). The information collected helps us make our advertising activities more targeted and efficient. Marketing and tracking cookies typically collect pseudonymised data such as user IDs, shortened IP addresses, device and browser information, pages visited, click paths, interactions with advertisements, timestamps, and the source of the visit, such as a search engine, social media platform, or advertisement. This data may be combined with information from other sources to create an interest profile that is as accurate as possible. We do not intend to identify the data subject.

As tracking and advertising cookies are not necessary for the website to operate, they may be placed only with your consent. The legal bases for the use of these cookies are Art. 6(1), sentence 1(a) GDPR (consent to the processing of personal data) and Section 25(1) TDDDG (access to information on a device only with consent).

6.5 Authentication Cookies

Authentication cookies are used to clearly identify users during a session and ensure that only authorised persons can access protected areas of our website or online services. These cookies are placed as soon as you log in with your login details, allowing our system to identify your session.

Authentication cookies ensure you remain logged in during your visit, so you don't have to log in again each time you move to another page. They also ensure that only authorised users can access protected content or functions. In addition, they support security checks, such as detecting unusual login activity or preventing unauthorised access. Authentication cookies contain only the information necessary for authentication, such as a randomly generated session ID. They do not store personal data such as passwords or the content of your user account.

As authentication cookies are strictly necessary for the secure operation of our website and the provision of protected functions, they are used on the basis of Section 25(2), no. 2 TDDDG (technically necessary cookies) and Art. 6(1)(f) GDPR (legitimate interest in the secure and functional provision of our services). Consent is not required for these cookies.

6.6 Load-Balancing Cookies

Load-balancing cookies are used to ensure the technical performance and stability of our website. These cookies ensure that incoming requests are distributed evenly among different servers, a process known as “load balancing”. This prevents individual servers from becoming overloaded and allows the website to remain reliable and fast even when it receives a high number of visitors.

Load-balancing cookies contain only technical information, such as an anonymised session or server ID. They are not used to identify users or track their behaviour. The cookies only ensure that your browser communicates consistently with the same server during a visit so that pages load correctly and no error messages occur.

As load-balancing cookies are technically necessary for the secure and reliable operation of our website, they are used on the basis of Section 25(2), no. 2 TDDDG (technically necessary cookies) and Art. 6(1)(f) GDPR (legitimate interest in the stable, secure, and efficient provision of our website). Consent is not required for these cookies.

6.7 Social Media Cookies

Social media cookies are placed by social networks or their integrated services when relevant features are enabled on our website, such as “Like” or “Share” buttons, embedded posts or videos, or login functions. These cookies allow the relevant social media providers to track your user behaviour even if you do not have an account with the network or are not logged in.

Depending on the provider, the data processed through social media cookies may be pseudonymised or may constitute personal data.

As social media cookies are not technically necessary, they are stored, and information is accessed on your device only with your consent in accordance with Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. These cookies will not be placed without your consent.

 

7. Cookie Consent Using the Klaro! Consent Manager

7.1 Description and Purpose of Data Processing

To allow you to control the use of cookies, a cookie consent tool has been implemented on the website (hereinafter referred to as “Klaro!”). Klaro! is provided as an open-source tool by KIProtect GmbH, Bismarckstr. 10 – 12, 10625 Berlin, and is operated by us on our own systems. Klaro! displays a list of cookies organised by functional category, explains the purposes of the cookie categories and individual cookies, and indicates how long they are stored.

When you enter our website, a Klaro! cookie is stored in your browser. This cookie records the consent you have given or withdrawn. This data is not transmitted to the provider of “Klaro!”.

7.1.1 Legal Basis for Processing

Klaro! is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6(1), sentence 1(c) GDPR.

7.1.2 Storage Period and Options for Objection and Deletion

The data collected in this way is stored until you delete the Klaro! cookie or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected. Details about the processing of data by the Klaro! cookie can be found at klaro.kiprotect.com.

7.1.3 Processing on Our Behalf

Klaro! is operated on our own servers. No personal data is transmitted.

 

8. Collection of General Data and Information1

Each time our website is accessed by a data subject or an automated system, it collects a range of general data. This general data and information is stored in the server log files. The following information may be collected: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (known as the referrer), (4) the subpages accessed on our website by the accessing system, (5) the date and time the website was accessed, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) other similar data and information used to prevent risks in the event of attacks on our information technology systems.

When using this general data and information, we do not draw any conclusions about the data subject. Instead, this information is required to (1) deliver the content of our website correctly, (2) optimise the content of our website and its advertising, (3) ensure that our information technology systems and website technology remain operational, and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack. We therefore analyse this anonymised data and information for statistical purposes and to improve data protection and security within our company. Our aim is to ensure the highest possible level of protection for the personal data we process. The anonymous data contained in the server log files is stored separately from any personal data provided by a data subject.

SSL Encryption

For security and to protect the transmission of confidential content, such as enquiries you send to us as the website operator, this website uses SSL (Secure Sockets Layer) encryption. You can recognise an encrypted connection because the address in your browser changes from “http://” to “https://” and a padlock symbol appears in the address bar.

When SSL encryption is enabled, the data you transmit to us cannot be read by third parties.

 

9. Scope and Purpose of the Data Collected

9.1 Brightest Websites – General

Whenever a webpage or a file accessible through a browser is requested, the following data is stored:

  • the requested webpage or file,
  • the date and time of the request,
  • the amount of data transferred,
  • a description of the type of web browser and operating system used,
  • the IP address of the computer making the request.

This information is used to optimise the Brightest websites and to record possible attacks on our online services.

The data listed above is automatically deleted after one year or by employees of Brightest GmbH.

9.2 Brightest Websites – Contact Form, Support Requests, and Webinars

The Brightest websites allow users to contact Brightest GmbH with general enquiries, submit requests directly to Brightest GmbH Support, or register for webinars. At least the following data from the mandatory fields is stored:

  • first name and surname,
  • email address,
  • company (only for requested quotations),
  • free-text information (only for contact forms and support requests),
  • telephone number (for webinars only).

Brightest GmbH uses this data to respond to enquiries or provide information about webinar dates.

The data stored in each case corresponds to the fields shown in the relevant forms and can therefore be seen directly in those forms. The data is disclosed to third parties only with the consent of the relevant user.

9.3 Brightest Websites – Registration

During registration on the website, the user’s email address is stored. The password entered during registration is stored only in encrypted form and cannot be decrypted by Brightest GmbH.

Brightest GmbH expressly points out that the email addresses of all active users, meaning users whose accounts have not been deleted, are used to inform them about important changes, such as changes to the scope of services or technically necessary changes.

The data entered during registration is processed as a pre-contractual measure pursuant to Art. 6(1)(b) GDPR.

Your registration data will remain stored by us until you request its deletion.

9.4 Stripe Payments

You can pay for your bookings immediately on our website. As part of our contractual and other legal relationships, due to legal obligations, or on the basis of our legitimate interests, we offer a payment method provided by the payment service provider Stripe. Payments are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. We provide Stripe with the information you submit during the ordering process, as well as information about your order.

Data Processed

Basic data (e.g. names and addresses), payment data (e.g. bank details, invoices, and payment history), contract data (e.g. subject matter of the contract, contract term, and customer category), usage data (e.g. websites visited, interest in content, and access times), and metadata and communication data (e.g. device information and IP addresses).

Purposes of Processing

Provision of contractual services and customer support. Processing of payment transactions.

Data Subjects:

Customers

Legal Bases for Processing

Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).

9.5 Customer Database

Brightest GmbH maintains an internal customer database that stores all relevant customer-related activities and notes. These include:

  • customer number,
  • company name,
  • company address,
  • email addresses of all active users, meaning users whose accounts have not been deleted,
  • names of all active users, meaning users whose accounts have not been deleted,
  • notes about telephone calls,
  • billing information,
  • statistical information about usage.

This data is used to improve the support our support and sales teams provide to our customers. Statistical analyses of this data are also used to improve the range of Brightest services. This data is not disclosed to third parties.

Users may request deletion of this data in writing, using the addresses listed in Section 2.

 

10. Subscription to Our Newsletter

On our website, you can subscribe to our newsletter. The personal data transmitted to the controller when you subscribe to the newsletter is shown in the registration form used for this purpose.

We regularly inform you about the company’s offers through our newsletter. In general, a data subject may receive our company’s newsletter only if:

  • the data subject has a valid email address and
  • the data subject has registered to receive the newsletter.

For legal reasons, a confirmation email is sent via the double-opt-in process to the email address the data subject provided when they first registered for the newsletter. This confirmation email is used to check whether the owner of the email address has authorised the receipt of the newsletter.

When you register for the newsletter, we also store the IP address assigned by the Internet service provider (ISP) to the data subject's computer system at the time of registration, as well as the date and time of registration. The collection of this data is necessary to identify any possible misuse of a data subject’s email address at a later date. It therefore provides legal protection for the controller (legal basis: Art. 6(1), sentence 1(c) GDPR).

The personal data collected when a person registers for the newsletter is used only to send our newsletter. Newsletter subscribers may also be informed by email if this is necessary for the operation of the newsletter service or a related registration, for example, if there are changes to the newsletter service or its technical conditions. Personal data collected through the newsletter service is not disclosed to third parties.

The data subject may cancel the newsletter subscription at any time. The consent we have to store personal data for sending the newsletter may also be withdrawn at any time. Every newsletter contains a link for withdrawing consent. You may also unsubscribe from the newsletter at any time directly through the controller’s website, by email or post using the contact details provided in Sections 2 and 3, or by informing the controller in another way.

 

11. Data Protection Provisions Regarding the Use of Google Analytics

If you have given your consent, this website uses Google Analytics 4, a web analytics service provided by Google LLC. The controller responsible for users in the EU, the EEA, and Switzerland is Google Ireland Limited, Google Building, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

Scope of Processing

Google Analytics uses cookies to analyse how you use our websites. The information collected by cookies about your use of this website is generally transferred to and stored on a Google server in the USA.

We use Google Signals. This allows Google Analytics to collect additional information about users who have enabled personalised advertisements, including interests and demographic data. Advertisements may also be shown to these users across different devices as part of remarketing campaigns.

In Google Analytics 4, IP address anonymisation is enabled by default. As a result, Google shortens your IP address within the Member States of the European Union or other states that are parties to the Agreement on the European Economic Area. Only in exceptional cases is the complete IP address transferred to a Google server in the USA and shortened there. According to Google, the IP address your browser sends to Google Analytics is not combined with other Google data.
During your visit to the website, your usage data is recorded as “events”. Events may include:

  • page views
  • first visit to the website
  • start of the session
  • your “click path” and interactions with the website
  • scrolling (whenever a user scrolls to 90% of the page)
  • clicks on external links 
  • internal searches
  • interactions with videos
  • file downloads
  • advertisements viewed or clicked
  • language settings

The following information is also collected:

  • your approximate location (region)
  • your IP address (in shortened form)
  • technical information about your browser and the devices you use (e.g. language settings and screen resolution)
  • your Internet service provider
  • the referrer URL (the website or advertising material through which you reached this website)
Purposes of Processing

The reports provided by Google Analytics are used to analyse our website's performance and the success of our marketing campaigns.

Recipients

The recipients of the data are or may include:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as a processor under Art. 28 GDPR)
  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
  • Alphabet Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

It cannot be ruled out that US authorities may access the data stored by Google.

Transfer to Third Countries

Where data is processed outside the EU or EEA and the level of data protection does not meet European standards, we have concluded EU Standard Contractual Clauses with the service provider to ensure an appropriate level of data protection. The parent company of Google Ireland, Google LLC, is based in California, USA. It therefore cannot be ruled out that Google may also process your personal data in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. By consenting to the use of Google Analytics 4 through the consent management system, you also consent to the transfer of data to the USA. In this case, the transfer is based on your consent to the use of Google cookies in accordance with Art. 6(1)(a) in conjunction with Art. 49(1)(a) GDPR. A transfer of data to the USA cannot be ruled out when you consent to the use of Google cookies.

Google LLC, 160 Amphitheatre Parkway, Mountain View, CA 94043-1351, USA, is certified under the EU-U.S. Data Privacy Framework Program. The EU-U.S. Data Privacy Framework is a bilateral adequacy decision that allows the transfer of personal data from the EU to the U.S. Proof of certification is available here: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active

Storage Period

The data we send and link to cookies is automatically deleted after 14 days. Data that has reached the end of its retention period is automatically deleted once a month.

Legal Basis

“Google cookies” are stored, and this tool is used based on the consent you provide through the consent management system. The processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time through the website’s consent management system.

Withdrawal of Consent

You may withdraw your consent at any time with effect for the future by opening the cookie settings in the consent management system and changing your selection. This does not affect the lawfulness of any processing carried out on the basis of your consent before it was withdrawn.

You can also prevent cookies from being stored from the beginning by configuring your browser software accordingly. However, if you configure your browser to reject all cookies, some functions on this and other websites may be limited. You may also prevent Google from collecting the data generated by the cookie relating to your use of the website, including your IP address, and from processing this data by:

a) not giving your consent to the placement of the cookie through the consent management system, or

b) downloading and installing the browser add-on for disabling Google Analytics https://tools.google.com/dlpage/gaoptout.

More information about the Google Analytics Terms of Service and Google’s data protection practices is available at https://marketingplatform.google.com/about/analytics/terms/de/ and https://policies.google.com/.

 

12. Hotjar

This website uses Hotjar, a service provided by Hotjar Limited (Level 2, St Julian’s Business Centre, 3 Elia Zammit Street, St Julian’s STJ 1000, Malta). We use Hotjar to better understand our users' needs and improve the services we offer on our website.

Purposes of Processing

Hotjar helps us better understand our users' experiences. For example, we can learn how much time you spend on particular pages, which links you click, and what you like or dislike. We use this information to adapt our services based on user feedback.

Hotjar uses cookies and similar technologies to collect information about your behaviour and the devices you use. This information includes:

  • the IP address of your computer (collected and stored in an anonymous format)
  • screen size
  • browser information (browser, version, etc.)
  • your location (country)
  • your preferred language setting
  • webpages visited (subpages)
  • the date and time you accessed one of our subpages (webpages)

Further information about Hotjar’s Privacy Policy and the data it collects and processes is available at https://www.hotjar.com/legal/policies/privacy.

Legal Basis and Legitimate Interests

“Hotjar cookies” are stored, and this tool is used based on the consent you provide through the consent management system. The processing is carried out exclusively on the basis of Art. 6(1), sentence 1(a) GDPR and Section 25(1) TDDDG. You may withdraw or change your consent at any time through the consent management system.

Storage Period

Neither Hotjar nor we use the information listed above to identify individual users or combine it with other data concerning individual users. Hotjar states that your data will be deleted within 1 year.

Disclosure

According to Hotjar, it does not store any of your personal data for analysis. The company also states that it does not disclose data to third parties.

We do not disclose any personal data ourselves.

Options for Objection

You can configure your browser to notify you when cookies are placed, allow cookies only in individual cases, reject cookies in certain cases or in general, and automatically delete cookies when the browser is closed. If cookies are disabled, some functions of this website may be limited.

 

13. Google Ads Conversion

Scope and Purpose of Processing

As part of our Google AdWords campaign, we use conversion tracking. We use Google Ads Conversions to draw attention to our offers through advertising materials on external websites. Our aim is to show you relevant advertising, make our website more interesting to you, and ensure advertising costs are calculated fairly. When you click on an advertisement placed by Google, a conversion-tracking cookie is stored. If the user visits certain pages on this website before the cookie expires, Google and we can recognise that the user clicked on the advertisement and was redirected to that page. The information collected using conversion cookies is used to create conversion statistics for AdWords customers who have chosen to use conversion tracking. We learn the total number of users who clicked on an advertisement and were redirected to a page containing a conversion-tracking tag. However, we do not receive any information that allows us to personally identify individual users. 

We do not collect or process personal data ourselves as part of these advertising activities.

Due to the marketing tools used, your browser automatically establishes a direct connection to Google’s server. We have no influence over the extent or further use of the data collected by Google through this tool. We therefore provide you with information based on our current knowledge: By integrating Ads Conversion, Google receives information indicating that you accessed the relevant part of our website or clicked on one of our advertisements. If you are registered with a Google service, Google may link the visit to your Google account. Even if you are not registered with Google or logged in, the provider may still obtain and store your IP address.

Legal Basis for Processing

“Google cookies” are stored, and this tool is used based on the consent you provide through the consent management system. The processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw or change your consent at any time through the consent management system.

Objection to Data Collection

If you do not wish to participate in tracking, you can object to this use by disabling the Google conversion-tracking cookie in your Internet browser’s user settings. You will then not be included in the conversion-tracking statistics.

Further information about the handling of user data in connection with Google AdWords and Google conversion tracking can be found in Google’s Privacy Policy: https://policies.google.com/privacy.

You can configure your browser to notify you when cookies are placed, allow cookies only in individual cases, reject cookies in certain cases or in general, and automatically delete cookies when the browser is closed. If cookies are disabled, some functions of this website may be limited.

Storage Period

These cookies expire after 30 days and are not used to identify users personally.

 

14. Google Consent Mode V2

Under the Digital Markets Act (DMA), companies such as Google and other “gatekeepers” are required to obtain users’ consent to the collection and processing of data and to provide evidence of this consent to the relevant authorities. This consent is required before user data may be processed for personalised advertising. In this case, the consent requirement is based on Art. 5(2)(b) DMA.

Gatekeepers are companies whose platform services hold a dominant position in the market. Google holds a dominant position in online advertising.

Under the “traditional” consent management process, you, as the user, primarily gave your consent to us as the website operator. This consent concerns the use of your data and cookies and is obtained through the website’s consent management system. Google Analytics’ new consent mode does not change this process.

For the purposes of the DMA, you must also give your consent to Google. Google simplifies this process by transferring responsibility for obtaining this consent directly to us as the website operator.

Through Consent Mode, Google has created an interface between our opt-in process and Google Analytics, so that your consent also applies to Google.

Google distinguishes between a basic and an advanced implementation. The two versions differ in how tags behave. With the basic implementation, Google tags remain blocked until you consent to their use. With the advanced implementation, Google tags are loaded before the consent request is displayed. If cookie consent has not been given, these tags send pings without cookies. In this case, Google Analytics runs but sends reduced data and does not place cookies.

Google code runs and sends a “ping” containing a unique “ping ID”, which is a number created only for the specific page view. Google also has access to automatically transmitted information such as the IP address, browser details, operating system, and URL visited. With the advanced implementation of Consent Mode, it is not possible to analyse user behaviour within a connected context. Without cookies, Google cannot track the activities of website visitors across several webpages. In this case, visits to different pages appear in Google Analytics as activities performed by different users because a separate ping ID is created for each visit and used to track that visit to a webpage.

However, in advanced mode and even without the user’s consent, Google can still determine whether website visitors reached the website through a Google advertisement. For this purpose, Google uses what are known as “conversion IDs”.

To avoid possible data protection issues relating to consent requirements, we have chosen to implement “server-side tracking”. This means that user data is collected without being sent directly from the user’s browser to Google. This process takes place in the following steps:

  • The website operator collects data that users transmit to the server. This includes the IP address, referrer URL, visited URLs, and relevant times.
  • The collected data is stored as a “digital fingerprint” and pseudonymised. Importantly, the user ID created when a ping is sent to Google is also removed because it would allow the data to be linked directly to a user.
  • Only pseudonymised data is then transmitted to Google.

 

15. Use of YouTube

We have embedded YouTube videos on our website. This allows us to show you interesting videos presenting our company and our work directly on our website. YouTube is a video platform that has been a subsidiary of Google LLC since 2006. The providers are Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

When you use YouTube videos, information about your use of this website, including your IP address, may be transmitted to Google LLC, located at 1600 Amphitheatre Parkway, Mountain View, California, USA.

The software places a cookie on the user’s computer. When individual pages of our website are accessed, the following data is stored:

  • IP address (anonymised)
  • browser information (referrer URL, browser, operating system, device information, date and time, and/or website content)
  • usage data (views, scrolling, and clicks)

When you visit the website, YouTube/Google receives information that you have accessed our website and the relevant subpages. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists.

If you are logged in to Google, your data will be linked directly to your account.

If you do not want this information to be linked to your YouTube profile, you must log out before giving your consent to the use of YouTube cookies.

We use YouTube in “Privacy-Enhanced Mode” to display videos to you. Without this “Privacy-Enhanced Mode”, a connection to a YouTube server in the USA is established as soon as you access one of our webpages containing an embedded YouTube video.

Storage of Data

YouTube stores your data in the form of usage profiles and uses it for advertising, market research, and/or the design of its website to better meet users’ needs. Such analysis is carried out, in particular, to provide targeted advertising, including to users who are not logged in, and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these usage profiles. To exercise this right, you must contact YouTube.

Legal Basis for Processing

“YouTube cookies” are stored, and this tool is used based on the consent you provide through the consent management system. The processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw or change your consent at any time through the consent management system.

You can configure your browser to notify you when cookies are placed, allow cookies only in individual cases, reject cookies in certain cases or in general, and automatically delete cookies when the browser is closed. If cookies are disabled, some functions of this website may be limited.

Disclosure of Data

Google/YouTube also processes your personal data in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. By consenting to the use of YouTube through the consent management system, you also consent to the transfer of data to the USA. In this case, the transfer is based on your consent to the use of YouTube cookies in accordance with Art. 6(1)(a) in conjunction with Art. 49(1)(a) GDPR, as a transfer of data to the USA cannot be ruled out when you consent to the use of YouTube cookies.

In addition, your data is transferred and processed on the basis of the Standard Contractual Clauses in accordance with Art. 46(2)(c) GDPR.

Google LLC, 160 Amphitheatre Parkway, Mountain View, CA 94043-1351, USA, is also certified under the EU-U.S. Data Privacy Framework. The EU-U.S. Data Privacy Framework is a bilateral adequacy decision that allows the transfer of personal data from the EU to the U.S. Proof of certification is available here: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active

We do not disclose any personal data ourselves.

Options for Objection

YouTube users can use the advertising preferences settings to control the extent to which their user behaviour is recorded when they visit our YouTube page. Further information about the purpose and scope of YouTube's data collection and processing can be found in its Privacy Policy. There, you will also find further information about your rights and the settings available to protect your privacy: https://policies.google.com/privacy.

You can prevent information from being processed by YouTube cookies by blocking third-party and YouTube/Google cookies in your browser settings.

Please note that in this case you may not be able to use all the functions of our website.

Further information about the purpose and scope of YouTube's data collection and processing can be found in its Privacy Policy. There, you will also find further information about your rights and the settings available to protect your privacy: https://policies.google.com/privacy.

 

16. Google Web Fonts

To display our content correctly and attractively across different browsers, we use “Google Web Fonts” from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter referred to as “Google”) to display fonts on our website.

We have installed this script library locally on our web server. Therefore, no connection to Google is established when you visit our website, and no “Google cookie” is placed.

Legal Basis for Processing

The legal basis for using Google Web Fonts is our legitimate interest under Art. 6(1), sentence 1(f) GDPR in displaying our website correctly and attractively. As we have installed the script library locally on our own web server, no data is transferred to Google. Your express consent is therefore not required for the use of Google Web Fonts.

Disclosure of Data

As the script library is installed locally on our web server, no data is disclosed to third parties.

Storage Period

We do not collect any personal data when the script library is installed locally on our server.

 

17. Google reCAPTCHA

To protect requests submitted through our online forms, we use the reCAPTCHA service provided by Google Inc. (“Google”). The check is used to determine whether information has been entered by a person or improperly through automated processing. This check includes sending your IP address and, where applicable, other data required by Google for the reCAPTCHA service. For this purpose, your input is transmitted to and used by Google. By using reCAPTCHA, you agree that the recognition work you perform may contribute to the digitalisation of older works. If IP anonymisation is enabled on this website, Google will first shorten your IP address within the Member States of the European Union or other states that are parties to the Agreement on the European Economic Area. Only in exceptional cases will the complete IP address be transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of this service.

The IP address your browser transmits as part of reCAPTCHA is not combined with other Google data. Google’s separate data protection provisions apply to this data. Further information about Google’s Privacy Policy is available at https://policies.google.com/privacy

 

18. Amazon CloudFront

Description, Scope, and Purposes of Data Processing

Our website uses Amazon CloudFront. This is JavaScript code from Amazon Web Services that runs when the page is loaded. It is a Content Delivery Network (CDN). A CDN is a service that helps deliver the content of our online services, particularly large media files such as graphics or scripts, more quickly by serving them from servers located in different regions and connected through the Internet. Your data, such as your IP address and possibly your browser data, is processed only for the purposes described above and to maintain the CDN's security and operation.

The data processing is carried out by:

Amazon Web Services, Inc., P.O. Box 81226, Seattle, WA 98108, USA (Amazon CloudFront – Content Delivery Network (CDN))

If JavaScript is enabled in your browser and you have not installed a JavaScript blocker, your browser may transmit personal data to Amazon CloudFront. 

Further information is available in the Amazon CloudFront Privacy Policy

To prevent JavaScript code from Amazon CloudFront from running, you can install a JavaScript blocker, such as http://www.noscript.net or http://www.ghostery.com.

Legal Bases

“Amazon CDN cookies” are stored, and this tool is used based on the consent you provide through the consent management system. The processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw or change your consent at any time through the consent management system.

You can configure your browser to notify you when cookies are placed, allow cookies only in individual cases, reject cookies in certain cases or in general, and automatically delete cookies when the browser is closed. If cookies are disabled, some functions of this website may be limited.

Disclosure of Data

We have no influence over Amazon's data collection or processing. We also do not know the scope of the data collection, the purposes of processing, or the applicable storage periods. It therefore cannot be ruled out that data is transferred to produce anonymised statistics.

If you consent to the use of the “Amazon CDN cookie”, some of the information collected may also be processed outside the European Union by Amazon Web Services, Inc., which is based in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. Through the consent management system, you decide whether to consent to the use of the “Amazon CDN cookie” under Art. 6(1)(a) GDPR and therefore also to a transfer to the USA. In this case, the transfer is based on your consent in accordance with Art. 49(1)(a) GDPR.

In addition, your data is transferred and processed on the basis of the Standard Contractual Clauses in accordance with Art. 46(2)(c) GDPR.

Amazon Web Services, Inc., P.O. Box 81226, Seattle, WA 98108, USA (Amazon CloudFront – Content Delivery Network (CDN)), as a company of Amazon.com, Inc., 410 Terry Avenue North, Seattle, Washington 98109, USA, is also certified under the EU-U.S. Data Privacy Framework Program. The EU-U.S. Data Privacy Framework is a bilateral adequacy decision under Art. 45 GDPR for transferring personal data from the EU to the USA. Proof of certification is available here: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active.

We do not disclose any personal data ourselves.

Data Storage Period

We have no control over the exact storage period of the processed data. This period is determined by Amazon Web Services, Inc. Further information is available in the AWS CloudFront Privacy Policy: https://aws.amazon.com/privacy/.

Options for Objection

You may withdraw or change your consent at any time through the consent management system.

You can configure your browser to notify you when cookies are placed, allow cookies only in individual cases, reject cookies in certain cases or in general, and automatically delete cookies when the browser is closed. If cookies are disabled, some functions of this website may be limited.

 

19. Data Protection Provisions Regarding the Use of Fan Pages on Facebook, X, Instagram, LinkedIn, XING, YouTube, Bluesky, and TikTok

19.1 Privacy Policy for Facebook
Controllers

As the operator of this Facebook page, we (Brightest GmbH, Lehmbruckstr. 18, 10245 Berlin, Germany) are jointly responsible with the operator of the Facebook social network (Facebook Ireland Ltd.) within the meaning of Art. 4, no. 7 of the General Data Protection Regulation (GDPR). When you visit our Facebook page, Facebook processes your personal data as the controller. Below, we explain what data is involved, how it is processed, and what rights you have in this regard. As the controller responsible for this page, we have entered into agreements with Facebook that govern, among other things, the terms of use of the Facebook page. The applicable terms are the Facebook Terms of Service and the other terms and policies listed there.

Purposes of Processing

The processing of this information is intended, among other things, to allow Facebook to improve the advertising system it provides through its network. It also allows us, as the operator of the Facebook page, to receive statistics created by Facebook based on visits to our page. These statistics help us manage the marketing of our activities. For example, they allow us to learn about the profiles of visitors who appreciate our Facebook page or use its applications. This helps us provide them with more relevant content and develop functions that may be of greater interest to them.

To better understand how our Facebook page can support our objectives, demographic and geographical analyses are also generated from the information collected and provided to us. We can use this information to display targeted, interest-based advertisements without directly learning the visitor’s identity. If visitors use Facebook on several devices, information may also be collected and analysed across these devices, provided that they are registered users and logged in to their profiles on each device. The visitor statistics created are provided to us only in anonymised form. We do not have access to the underlying data.

Legal Basis and Legitimate Interests

We use this Facebook page to introduce our company to Facebook users and other interested visitors, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in presenting our company in an optimised manner (Art. 6(1)(f) GDPR).

Disclosure of Data

We have no influence over Facebook's data collection or processing. We also do not know the scope of the data collection, the purposes of processing, or the applicable storage periods. It therefore cannot be ruled out that data is transferred to produce anonymised statistics.

When you visit our Facebook page, some of the information collected may also be processed outside the European Union by Facebook Inc., which is based in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. Through the consent management system on the Facebook page, you decide whether to consent to such a transfer. In this case, the transfer is based on your consent in accordance with Art. 6(1)(a) GDPR.

We do not disclose any personal data ourselves.

Options for Objection

Facebook users can use the advertising preferences settings to control the extent to which their user behaviour is recorded when they visit our Facebook page. Further options are available through the Facebook settings, the fan page’s consent management system, or the right-to-object form. You can prevent information from being processed through cookies used by Facebook by blocking third-party cookies and Facebook cookies in your browser settings.

Nature of Joint Responsibility

The agreements with Facebook, including those concerning joint responsibility, generally state that requests for information and the exercise of other data subject rights should be addressed directly to Facebook. As the provider of the social network and the option to include Facebook pages within it, Facebook alone has direct access to the necessary information. Facebook can also take any necessary measures directly and provide the relevant information. However, if you require our support, you may contact us at any time.

Information About Contact Options and Other Rights of Data Subjects

Further information about our contact details, your rights as a data subject in relation to us, and how we otherwise process personal data can be found in this Privacy Policy. Information about how Facebook handles personal data is available in its Privacy Policy.

19.2 Privacy Policy for X
Controllers

As the operator of an X account, we (Brightest GmbH, Lehmbruckstr. 18, 10245 Berlin, Germany) are jointly responsible with the operator of the X social network (X International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, a company of X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94102, USA) within the meaning of Art. 4, no. 7 of the General Data Protection Regulation (GDPR). When you visit our X page, personal data is processed by the controllers. Below, we explain what data is involved, how it is processed, and what rights you have in this regard.

As the controller responsible for this page, we have entered into agreements with X that govern, among other things, the terms of use of the X page. The applicable terms are the general terms and conditions available at https://x.com/en/tos#intlTerms, as well as the other terms and policies listed there.

Purposes of Processing

The processing of this information is intended, among other things, to allow X to improve the system it uses to distribute advertising through its network. It also allows us, as the operator of the X page, to receive statistics created by X based on visits to our X page. These statistics help us manage the marketing of our activities. For example, they allow us to learn about the profiles of visitors who appreciate our X page or use its applications. This helps us provide them with more relevant content and develop functions that may be of greater interest to them.

To help us better understand how our X page can support our objectives, demographic and geographical analyses are also created from the information collected and provided to us. We can use this information to display targeted, interest-based advertisements without directly learning the visitor’s identity. If visitors use X on multiple devices, information may also be collected and analysed across those devices, provided they are registered users and logged in to their profiles on each device.

The visitor statistics created are provided to us only in anonymised form. We do not have access to the underlying data. 

Legal Basis and Legitimate Interests

We use this X page to introduce our company to X users and other interested visitors, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in presenting our company in an optimised manner (Art. 6(1)(f) GDPR).

This service is used on the basis of your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time.

Disclosure of Data

When you visit our X page, some of the information collected may also be processed outside the European Union by X Corp., which is based in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. Through the consent management system on the X page, you decide whether to consent to such a transfer. In this case, the transfer is based on your consent in accordance with Art. 6(1)(a) GDPR.

In addition, X Corporation, 1355 Market Street, Suite 900, San Francisco, CA 94102, USA, is certified under the EU-U.S. Data Privacy Framework Program. The EU-U.S. Data Privacy Framework is a bilateral adequacy decision that allows the transfer of personal data from the EU to the U.S. Proof of certification is available here: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000KzNaAAK&status=Active.

We do not disclose any personal data ourselves.

Options for Objection

X provides relevant options in the X account settings and at https://x.com/en/privacy.

You can prevent information from being processed through cookies used by X by blocking third-party cookies and X cookies in your browser settings.

Nature of Joint Responsibility

The agreements with X, including those concerning joint responsibility, generally state that requests for information and the exercise of other data subject rights should be addressed directly to X. As the provider of the social network and the option to include X pages within it, X alone has direct access to the necessary information. X can also take any necessary measures directly and provide the relevant information. However, if you require our support, you may contact us at any time.

Information About Contact Options and Other Rights of Data Subjects

Further information about our contact details, your rights as a data subject in relation to us, and how we otherwise process personal data can be found in this Privacy Policy.

Information about how X handles personal data is available in its Privacy Policy at: https://x.com/de/privacy.

19.3 Privacy Policy for Instagram
Controllers

As the operator of this Instagram page, we (Brightest GmbH, Lehmbruckstr. 18, 10245 Berlin, Germany) are jointly responsible with the operator of the Instagram social network (Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland) within the meaning of Art. 4, no. 7 of the General Data Protection Regulation (GDPR). When you visit our Instagram page, personal data is processed by the controllers. Below, we explain what data is involved, how it is processed, and what rights you have in this regard.

As the controller responsible for this page, we have entered into agreements with Facebook that govern, among other things, the Instagram page's terms of use. The applicable terms are the Instagram Terms of Use available at https://help.instagram.com/581066165581870, as well as the other terms and policies listed there.

Purposes of Processing

The processing of this information is intended, among other things, to allow Facebook to improve the advertising system it provides through its network. It also allows us, as the operator of the Instagram page, to receive statistics from Facebook based on visits to our page. These statistics help us manage the marketing of our activities. For example, they allow us to learn about the profiles of visitors who appreciate our Instagram page or use its applications. This helps us provide them with more relevant content and develop functions that may be of greater interest to them.

To better understand how our Instagram page can support our objectives, demographic and geographical analyses are also generated from the information collected and provided to us. We can use this information to display targeted, interest-based advertisements without directly learning the visitor’s identity. If visitors use Facebook on several devices, information may also be collected and analysed across these devices, provided that they are registered users and logged in to their profiles on each device.

The visitor statistics created are provided to us only in anonymised form. We do not have access to the underlying data.

Legal Basis and Legitimate Interests

We use this Instagram page to introduce our company to users and other interested visitors, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in presenting our company in an optimised manner (Art. 6(1)(f) GDPR).

Disclosure of Data

We have no influence over Instagram's data collection or Facebook's data processing. We also do not know the scope of the data collection, the purposes of processing, or the applicable storage periods. It therefore cannot be ruled out that data is transferred to produce anonymised statistics.

When you visit our Instagram page, some of the information collected may also be processed outside the European Union by Facebook Inc., which is based in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. Through the consent management system on the Instagram page, you decide whether to consent to such a transfer. In this case, the transfer is based on your consent in accordance with Art. 6(1)(a) GDPR.

We do not disclose any personal data ourselves.

Options for Objection

Instagram users can use the advertising preferences settings to control the extent to which their user behaviour is recorded when they visit our Instagram page. Further options are available through the Facebook and Instagram settings at: https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Fads%2Fpreferences%2F%3Fentry_product%3Dad_settings_screen
https://www.instagram.com/accounts/login/?next=/accounts/privacy_and_security/, through the fan page’s consent management system, or through the right-to-object form available at: https://www.facebook.com/help/contact/1994830130782319.

You can prevent information from being processed through cookies used by Facebook by blocking third-party cookies and Facebook cookies in your browser settings.

Nature of Joint Responsibility

The agreements with Facebook, including those concerning joint responsibility, generally state that requests for information and the exercise of other data subject rights should be addressed directly to Facebook. As the provider of the social network and the option to include Facebook pages within it, Facebook alone has direct access to the necessary information. Facebook can also take any necessary measures directly and provide the relevant information. However, if you require our support, you may contact us at any time.

Information About Contact Options and Other Rights of Data Subjects

Further information about our contact details, your rights as a data subject in relation to us, and how we otherwise process personal data can be found in this Privacy Policy.

Information about how Facebook handles personal data on Instagram is available in its Privacy Policy at https://help.instagram.com/519522125107875.

19.4 Privacy Policy for LinkedIn
Controllers

As the operator of this LinkedIn page, we (Brightest GmbH, Lehmbruckstr. 18, 10245 Berlin, Germany) are jointly responsible with the operator of the LinkedIn social network (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) within the meaning of Art. 4, no. 7 of the General Data Protection Regulation (GDPR). When you visit our LinkedIn page, personal data is processed by the controllers. Below, we explain what data is involved, how it is processed, and what rights you have in this regard.

As the controller responsible for this page, we have entered into agreements with LinkedIn that govern, among other things, the terms of use of the LinkedIn page. The applicable terms are LinkedIn’s Terms of Service available at: https://www.linkedin.com/legal/user-agreement?src=or-search&veh=www.google.com%7Cgo-pa&trk=sem_lms_gaw

Purposes of Processing

The processing of this information is intended, among other things, to allow LinkedIn to improve the advertising system it provides through its network. It also allows us, as the operator of the LinkedIn page, to receive statistics created by LinkedIn based on visits to our LinkedIn page. These statistics help us manage the marketing of our activities. For example, they allow us to learn about the profiles of visitors who appreciate our LinkedIn page or use its applications. This helps us provide them with relevant content and develop functions that may be of particular interest to them.

To better understand how our LinkedIn page can support our objectives, demographic and geographical analyses are also generated from the information collected and provided to us. We can use this information to display targeted, interest-based advertisements without directly learning the visitor’s identity. If visitors use LinkedIn on multiple devices, information may also be collected and analysed across devices, provided they are registered users and logged in to their profiles on each device.

The visitor statistics created are provided to us only in anonymised form. We do not have access to the underlying data.

Legal Basis and Legitimate Interests

We use this LinkedIn page to introduce our company to users and other interested visitors, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in presenting our company in an optimised manner (Art. 6(1)(f) GDPR).

Disclosure of Data

We have no influence over LinkedIn's data collection or processing. We also do not know the scope of the data collection, the purposes of processing, or the applicable storage periods. It therefore cannot be ruled out that data is transferred to produce anonymised statistics.

When you visit our LinkedIn page, some of the information collected may also be processed outside the European Union by LinkedIn Corporation, which is based in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. Through the consent management system on the LinkedIn page, you decide whether to consent to such a transfer. In this case, the transfer is based on your consent in accordance with Art. 6(1)(a) GDPR.

We do not disclose any personal data ourselves.

Options for Objection

LinkedIn users can use the consent management system on our LinkedIn page to control how their user behaviour is recorded when they visit our page. Further options are available in the LinkedIn account settings and through the fan page’s consent management system.

You can prevent information from being processed through cookies used by LinkedIn by blocking third-party cookies and LinkedIn cookies in your browser settings.

Nature of Joint Responsibility

The agreements with LinkedIn, including those concerning joint responsibility, generally state that requests for information and the exercise of other data subject rights should be addressed directly to LinkedIn. As the provider of the social network and the option to include LinkedIn pages within it, LinkedIn alone has direct access to the necessary information. LinkedIn can also take any necessary measures directly and provide the relevant information. However, if you require our support, you may contact us at any time.

Information About Contact Options and Other Rights of Data Subjects

Further information about our contact details, your rights as a data subject in relation to us, and how we otherwise process personal data can be found in this Privacy Policy.

Information about how LinkedIn handles personal data is available in its Privacy Policy (https://www.linkedin.com/legal/privacy-policy).

19.5 Privacy Policy for XING
Controllers

As the operator of this XING page, we (Brightest GmbH, Lehmbruckstr. 18, 10245 Berlin, Germany) are jointly responsible with the operator of the XING social network (XING SE, Dammtorstraße 30, 20354 Hamburg, Germany) within the meaning of Art. 4, no. 7 of the General Data Protection Regulation (GDPR). When you visit our XING page, personal data is processed by the controllers. Below, we explain what data is involved, how it is processed, and what rights you have in this regard.

As the controller responsible for this XING page, we operate it in accordance with the applicable terms of use. The applicable terms are the General Terms and Conditions of XING available at https://privacy.xing.com/en/privacy-policy and the additional terms and policies listed there.

Purposes of Processing

We collect personal data to communicate with you and other interested persons and to provide information about our company.

When you visit our XING page, cookies are generally placed on your computer and used to store information about your user behaviour. XING provides us with this usage data in anonymised and aggregated form for analysis.

Below, we provide information about how your personal data is handled. Personal data means any data that can be used to identify you personally. Please carefully consider which personal data you share with us through XING. Further information about XING's data processing is available in the XING Privacy Policy at https://privacy.xing.com/en/privacy-policy.

Legal Basis and Legitimate Interests

We use this XING page to introduce our company to XING users and other interested visitors, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in presenting our company in an optimised manner (Art. 6(1)(f) GDPR).

If you also provide data through XING, the legal basis is your consent under Art. 6(1), sentence 1(a) GDPR.

Disclosure of Data

We do not disclose any data that we receive from you through XING. Regarding the disclosure of data by XING, please refer to the link to XING’s Privacy Policy.

Options for Objection

You can prevent XING from processing information through cookies by using the options provided in its Cookie Policy and by blocking third-party and XING cookies in your browser settings.

Nature of Joint Responsibility

The agreements with XING, including those concerning joint responsibility, generally state that requests for information and the exercise of other data subject rights should be addressed directly to XING. As the provider of the social network and the option to include XING pages within it, XING alone has direct access to the necessary information. XING can also take any necessary measures directly and provide the relevant information. However, if you require our support, you may contact us at any time.

Storage Period / Deletion of Data

We delete the data you have provided to us through XING as soon as the purpose of processing has been fulfilled and no further statutory retention obligations apply. As there may be different reasons and purposes for contacting us through XING, the storage period depends directly on the relevant reason or purpose.

Information about how XING handles personal data, including data deletion, is available in its Privacy Policy at https://privacy.xing.com/en/privacy-policy

You can contact XING’s Data Protection Officer using the contact form provided by XING at https://www.xing.com/support/contact/security/data_protection

19.6 Privacy Policy for YouTube
Controllers

As the operator of this YouTube page, we (Brightest GmbH, Lehmbruckstr. 18, 10245 Berlin, Germany) are jointly responsible with the operator of the YouTube website (YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA, a subsidiary of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) within the meaning of Art. 4, no. 7 of the General Data Protection Regulation (GDPR). When you visit our YouTube page, personal data is processed by the controllers. Below, we explain what data is involved, how it is processed, and what rights you have in this regard.

All data protection settings for YouTube must be managed through your Google account. As the controller responsible for this page, we have entered into agreements with Google that govern, among other things, the terms for using Google services, specifically YouTube. The applicable terms are Google’s Terms of Service and the other terms and policies listed there.

Purposes of Processing

The processing of this information is intended, among other things, to allow YouTube to improve the advertising system it provides through its network. It also allows us, as the operator of the YouTube page, to receive YouTube-generated statistics on page visits. These statistics help us manage the marketing of our activities. For example, they allow us to learn about the profiles of visitors who appreciate our YouTube videos or use the page’s applications. This helps us provide them with relevant content and develop functions that may be of particular interest to them.

To better understand how our YouTube page can support our objectives, demographic and geographical analyses are also generated from the information collected and provided to us. We can use this information to display targeted, interest-based advertisements without directly learning the visitor’s identity. If visitors use YouTube on multiple devices, information may also be collected and analysed across devices, provided they are registered users and logged in to their profiles on each device.

The visitor statistics created are provided to us only in anonymised form. We do not have access to the underlying data.

Legal Basis and Legitimate Interests

We use this YouTube page to introduce our company to YouTube users and other interested viewers, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in presenting our company in an optimised manner (Art. 6(1)(f) GDPR).

Disclosure of Data

We have no influence over the data collected by Google or the data processing it performs. We also do not know the scope of the data collection, the purposes of processing, or the applicable storage periods. It therefore cannot be ruled out that data is transferred to produce anonymised statistics.

When you visit our YouTube page, some of the information collected may also be processed outside the European Union by YouTube LLC or Google Inc., which are based in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. Through the consent management system on the YouTube page, you decide whether to consent to such a transfer. In this case, the transfer is based on your consent in accordance with Art. 6(1)(a) GDPR.

We do not disclose any personal data ourselves.

Options for Objection

YouTube users can control the extent to which their user behaviour is recorded when they visit our YouTube page in their Google account settings. See also: https://policies.google.com/privacy?hl=en-US#infosharing.

You can prevent information from being processed by cookies used by YouTube or Google by blocking third-party, Google, and YouTube cookies in your browser settings.

Nature of Joint Responsibility

The agreements with YouTube and Google, including those concerning joint responsibility, generally state that requests for information and the exercise of other data subject rights should be addressed directly to YouTube or Google. As the provider of the social network and the option to include YouTube pages within it, YouTube alone has direct access to the necessary information. YouTube can also take any necessary measures directly and provide the relevant information. However, if you require our support, you may contact us at any time.

Information About Contact Options and Other Rights of Data Subjects

Further information about our contact details, your rights as a data subject in relation to us, and how we otherwise process personal data can be found throughout this Privacy Policy.

Information about how YouTube and Google handle personal data is available in Google’s Privacy Policy (https://policies.google.com/privacy).

19.7 Privacy Policy for Bluesky
Controller

We maintain a profile on the Bluesky social network (Bluesky Social PBC, 1925 Post Alley, Suite 301, Seattle, WA 98101-1028, USA) to communicate with interested persons and users and to provide information about our services.

When you visit our Bluesky profile, the network operator processes your personal data. This includes, in particular:

  • IP address
  • device and usage information
  • interactions with posts (e.g. likes, comments, and reposts)
  • profile data (if you have a Bluesky account)

Bluesky generally processes this data as an independent controller. We have no influence over the nature or scope of the data processing carried out by Bluesky.

Further information about Bluesky's data processing is available in the provider’s Privacy Policy: https://bsky.social/about/support/privacy-policy.

Purposes of Processing

We use Bluesky for the following purposes:

  • public relations and presenting our company
  • communication with users and interested persons
  • providing information and news

If you interact with us through Bluesky, for example through messages, comments, or likes, we process the data you provide, such as your username and the content of your messages, to handle your enquiry.

This data is processed only to respond to your enquiry and maintain communication with you. We store personal data processed as part of communication through Bluesky only for as long as necessary to handle your enquiry or comply with statutory retention obligations.

Legal Basis and Legitimate Interests

We use our Bluesky profile to present our company to Bluesky users and other interested visitors, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in ensuring that our company is as visible and accessible as possible (Art. 6(1)(f) GDPR).

If you contact us through Bluesky, the processing may also be based on Art. 6(1)(b) GDPR where it relates to a contractual or pre-contractual relationship.

Where Bluesky places cookies or accesses devices as part of the use of the Bluesky profile, this takes place on the basis of your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can provide this consent directly through Bluesky’s consent management system. You may withdraw your consent at any time with effect for the future through the consent management system.

Disclosure of Data

We have no influence over Bluesky's data collection or processing. We also do not know the scope of the data collection, the purposes of processing, or the applicable storage periods.

When you visit Bluesky, the personal data and information collected by Bluesky are processed outside the European Union in the USA. We would like to point out that the Court of Justice of the European Union has classified the USA as a country whose data protection level does not meet EU standards. There is therefore a risk that your data may be processed by US authorities for monitoring and surveillance purposes, possibly without any legal remedy available to you. Through the consent management system on the Bluesky page, you decide whether to consent to such a transfer. In this case, the transfer is based on your consent in accordance with Art. 6(1)(a) GDPR.

We do not disclose any personal data ourselves.

Options for Objection

You have the right to object at any time, for reasons relating to your particular situation, to the processing of your personal data where the processing is based on Art. 6(1)(f) GDPR (legitimate interest), in accordance with Art. 21(1) GDPR.

We process personal data in connection with our Bluesky profile, particularly on the basis of legitimate interests such as public relations and communication. If you object, we will stop processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.

Where personal data is processed for direct marketing purposes, you have the right to object to this processing at any time without providing a reason (Art. 21(2) GDPR). This also applies to any profiling related to such direct marketing. If you object, your personal data will no longer be used for direct marketing purposes.

You may submit your objection to us without any particular format by email or using the contact details provided in this Privacy Policy.

In addition, you may object to data processing by Bluesky directly to the provider, particularly by:

  • adjusting the privacy settings in your Bluesky account
  • limiting the visibility of your profile and content
  • using the available options to deactivate or delete your account

Please note that we do not have complete control over the data processing carried out by Bluesky. For certain processing activities, you may therefore need to submit your objection directly to the provider.

Joint Responsibility

Based on our current knowledge, there is no joint responsibility under Art. 26 GDPR because Bluesky independently determines how data is processed.

Information About Contact Options and Other Rights of Data Subjects

Further information about our contact details, your rights as a data subject in relation to us, and how we otherwise process personal data can be found in this Privacy Policy.

Further information about data processing by Bluesky is available in the provider’s Privacy Policy at: https://bsky.social/about/support/privacy-policy.

19.8 Privacy Policy for TikTok
Controllers

As the operator of this TikTok page, we (Brightest GmbH, Lehmbruckstr. 18, 10245 Berlin, Germany) are jointly responsible with the operators of the TikTok website (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and TikTok Information Technologies UK Limited, 4 Lindsey Street, London, EC1A 9HP, United Kingdom, both subsidiaries of ByteDance Ltd., 1 Raffles Quay, Singapore 048583) within the meaning of Art. 4, no. 7 of the General Data Protection Regulation (GDPR). When you visit our TikTok page, personal data is processed by the controllers. Below, we explain what data is involved, how it is processed, and what rights you have in this regard.

Purposes of Processing

TikTok is an international social media video platform. It is used for lip-syncing in music videos and other short video clips.

The processing of this information is intended, among other things, to allow TikTok to:

  • improve its advertising system
  • personalise content and advertisements
  • create usage statistics
  • identify security risks

For us, as the operator of the TikTok page, the processing allows us to:

  • access anonymised statistics about visitors to our page
  • gain information about reach, target groups, and interactions
  • optimise our content and marketing activities

The statistics are provided only in anonymised form. We do not have access to the underlying personal data.

Legal Basis and Legitimate Interests

We use this TikTok page to introduce our company to TikTok users and other interested visitors, and to communicate with them. Users’ personal data is processed on the basis of our legitimate interest in presenting our company in an optimised manner (Art. 6(1)(f) GDPR).

Where TikTok places cookies or accesses devices as part of the use of the TikTok page, this takes place on the basis of your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can provide this consent directly to TikTok through the consent management system on the TikTok page. You may withdraw your consent at any time with effect for the future through the consent management system on TikTok’s pages.

Disclosure of Data

We have no influence over TikTok's data collection or processing. We also do not know the scope of the data collection, the purposes of processing, or the applicable storage periods. It therefore cannot be ruled out that data is transferred to produce anonymised statistics.

When you visit our TikTok page, personal data and information collected by TikTok is also processed outside the European Union. For international data transfers, TikTok expressly relies on the Standard Contractual Clauses (SCCs) approved by the European Commission. In official proceedings, TikTok has also stated that transfers, including transfers to China, were carried out on the basis of SCCs. These are a permitted instrument under Art. 46(2)(c) GDPR for contractually ensuring an “appropriate level of protection” in third countries.

In 2025, the Irish Data Protection Authority, acting as the lead supervisory authority, found that although TikTok used SCCs, it could not demonstrate that they ensured an equivalent level of data protection in practice because effective supplementary measures and an adequate transfer impact assessment were missing.

We would like to point out that China, Singapore, and the USA do not provide data protection levels comparable to those required under European law. There are therefore no adequacy decisions, or only limited ones, for these countries, including the Data Privacy Framework in relation to the USA. There is a risk that your data may be accessed and processed by public authorities, possibly without any legal remedy available to you. Through the consent management system on the TikTok page, you decide whether to consent to such a transfer. In this case, the transfer is based on your consent in accordance with Art. 6(1)(a) GDPR.

We do not disclose any personal data ourselves.

Options for Objection

TikTok users can limit the collection of personal data through their device settings by:

  • disabling tracking,
  • resetting the advertising ID,
  • limiting app permissions,
  • blocking background data.

You can prevent information from being processed through cookies used by TikTok by withdrawing your consent through the website’s consent management system or by blocking third-party cookies and TikTok cookies in your browser settings.

Nature of Joint Responsibility

TikTok does not provide a publicly available agreement concerning joint responsibility.

There is:

  • no agreement under Art. 26 GDPR
  • no description of the parties’ roles
  • no division of responsibilities
  • no arrangement concerning the main point of contact

TikTok therefore does not meet the requirements of Art. 26(1) and (2) GDPR.

Nevertheless, joint responsibility exists because we, as the operator of a TikTok page, and TikTok jointly determine the purposes and means of processing, including reach analysis and interactions.

Due to the nature of this joint responsibility, requests for information and the exercise of other data subject rights should generally be addressed directly to TikTok. As the provider of the social network and the option to include TikTok pages within it, TikTok alone has direct access to the necessary information. TikTok can also take any necessary measures directly and provide the relevant information. However, if you require our support, you may contact us at any time.

Information About Contact Options and Other Rights of Data Subjects

Further information about our contact details, your rights as a data subject in relation to us, and how we otherwise process personal data can be found in this Privacy Policy.

Information about how TikTok handles personal data is available in its Privacy Policy (https://www.tiktok.com/legal/page/eea/privacy-policy/de).

 

20. Data Protection for Applications and the Recruitment Process

We offer you the opportunity to apply for a position with us, for example by email, by post, or through Facebook. Below, we provide information about the scope, purpose, and use of the personal data collected during the application process. We confirm that your data will be collected, processed, and used in accordance with applicable data protection law and all other legal requirements, and that it will be treated as strictly confidential.

Scope and Purpose of Data Collection

If you submit an application to us, we process the relevant personal data, such as contact and communication details, application documents, and interview notes, to the extent necessary to decide whether to establish an employment relationship.

The legal basis for this is Section 26 of the German Federal Data Protection Act (BDSG) concerning the establishment of an employment relationship, Art. 6(1)(b) GDPR concerning general pre-contractual measures and, where you have given your consent, Art. 6(1)(a) GDPR. You may withdraw your consent at any time.

Within our company, your personal data is disclosed only to persons involved in processing your application.

If your application is successful, the data you submitted will be stored in our data processing systems on the basis of Section 26 BDSG and Art. 6(1)(b) GDPR for the purpose of carrying out the employment relationship.

Data Retention Period

If we are unable to offer you a position, you reject a job offer, or you withdraw your application, we reserve the right to retain the data you submitted for up to six months after the end of the application process. This retention is based on our legitimate interests under Art. 6(1)(f) GDPR.

The data will then be deleted, and any physical application documents will be destroyed. The data is retained mainly as evidence in the event of a legal dispute. If it is clear that the data will still be required after the six-month period, for example because of a threatened or ongoing legal dispute, it will be deleted only when the purpose of the extended retention no longer applies.

The data may also be retained for a longer period if you have given your consent under Art. 6(1)(a) GDPR or if statutory retention obligations prevent its deletion.

 

21. Deletion and Restriction of Personal Data1

The controller processes and stores the data subject’s personal data only for the period necessary to achieve the purpose of storage, or as required by laws or regulations applicable to the controller.

If the purpose of storage no longer applies, or if a storage period required by another competent legislator has expired, the personal data will be restricted or deleted in accordance with the applicable legal requirements.

 

22. Legal Basis for Processing1

Unless otherwise stated:

Art. 6(1), sentence 1(a) GDPR serves as the legal basis for processing activities for which our company obtains consent for a specific purpose. If the processing of personal data is necessary to perform a contract to which the data subject is a party, for example where processing is required to deliver goods or provide another service or consideration, the processing is based on Art. 6(1), sentence 1(b) GDPR. The same applies to processing activities necessary to take pre-contractual measures, for example in the case of enquiries about our products or services. If our company is subject to a legal obligation requiring the processing of personal data, for example, to fulfil tax obligations, the processing is based on Art. 6(1), sentence 1(c) GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This could be the case, for example, if a visitor were injured at our premises and their name, age, health insurance information, or other vital information had to be disclosed to a doctor, hospital, or another third party. In this case, the processing would be based on Art. 6(1), sentence 1(d) GDPR.

Finally, processing activities may be based on Art. 6(1), sentence 1(f) GDPR. This legal basis applies to processing activities not covered by any of the legal bases listed above, where processing is necessary to protect a legitimate interest of our company or a third party, provided that the data subject's interests, fundamental rights, and freedoms do not override that interest. Such processing activities are permitted, in particular, because they have been expressly mentioned by the European legislator. The legislator considered that a legitimate interest may exist where the data subject is a customer of the controller (Recital 47, sentence 2 GDPR).

 

23. Legitimate Interests Pursued by the Controller or a Third Party1

Where the processing of personal data is based on Art. 6(1), sentence 1(f) GDPR, our legitimate interest is to conduct our business activities for the benefit and well-being of all our employees and shareholders.

 

24. Period for Which Personal Data Is Stored1

The relevant statutory retention period determines how long personal data is stored. After this period expires, the relevant data is routinely deleted unless it is still required to perform or enter into a contract.

 

25. Legal or Contractual Requirements to Provide Personal Data; Requirement for Entering into a Contract; Obligation of the Data Subject to Provide Personal Data; Possible Consequences of Not Providing It1

We would like to inform you that the provision of personal data is required in some cases by law, for example under tax regulations, or may result from contractual provisions, such as information about the contracting party.

In some cases, a data subject may need to provide us with personal data to conclude a contract. We must then process this data. For example, the data subject is required to provide us with personal data if our company enters into a contract with them. If the personal data is not provided, the contract with the data subject cannot be concluded.

Before providing personal data, the data subject must contact one of our employees. Our employee will explain, based on the individual case, whether the provision of personal data is required by law or contract, whether it is necessary to enter into the contract, whether there is an obligation to provide the personal data, and what the consequences of not providing it would be.

 

26. Rights of the Data Subject

a)  Right of Access

You may exercise your right of access under Art. 15 GDPR at any time to find out whether we process your personal data.

b)  Right to Rectification

You may exercise your right to rectification under Art. 16 GDPR at any time and request the correction of inaccurate personal data concerning you.

c)  Right to Restriction of Processing

You may exercise your right to restriction of processing under Art. 18 GDPR at any time and request that processing be restricted where the legal requirements are met.

d)  Right to Erasure

You may exercise your right to erasure under Art. 17 GDPR at any time and request that the relevant personal data be deleted without unnecessary delay if the data is no longer required for the purposes for which it was collected or otherwise processed. Other legal obligations, such as statutory retention obligations, may prevent the data from being deleted.

e)  Right to Be Informed

You may exercise your right to be informed under Art. 19 GDPR at any time. If you have exercised your right to erasure, rectification, or restriction of processing concerning your personal data, we are required to inform all recipients to whom the personal data was disclosed about the correction or deletion of the data or the restriction of processing, unless this is impossible or requires a disproportionate amount of effort. You have the right to be informed about these recipients.

f)  Right to Data Portability

You may exercise your right to data portability under Art. 20 GDPR at any time. You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or to request that it be transmitted to another controller where technically possible.

g)  Right to Object

You have the right to object at any time, for reasons relating to your particular situation, to the processing of personal data based on Art. 6(1)(e) or (f) GDPR.

If you object, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for processing that override the data subject's interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.

If we process personal data for direct marketing purposes, the data subject has the right to object at any time to such processing. If the data subject objects to processing for direct marketing purposes, we will no longer process the personal data for these purposes.

To exercise the right to object, the data subject may contact us directly. The data subject may also exercise this right through automated procedures.

h)  Right to Withdraw Consent Under Data Protection Law

You have the right to withdraw your consent to the processing of personal data at any time. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before it was withdrawn.

i)  Right to Lodge a Complaint with a Supervisory Authority

Without affecting any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your usual residence, your place of work, or the place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR.

 

27. Changes to This Privacy Policy

Brightest GmbH reserves the right to amend this Privacy Policy. The latest version of the Privacy Policy is always available under the Privacy Policy section.

1) The marked sections of this Privacy Policy were created using the Privacy Policy Generator operated and provided through a cooperation between DGD Deutsche Gesellschaft für Datenschutz GmbH, Dachau (available at: https://dsgvo-muster-datenschutzerklaerung.dg-datenschutz.de) and the law firm Wilde/Beuger/Solmecke Rechtsanwälte GbR, Cologne (available at: ). These texts are protected by the copyright of DGD Deutsche Gesellschaft für Datenschutz GmbH, Dachau, and the law firm Wilde/Beuger/Solmecke Rechtsanwälte GbR, Cologne.