Skip to content
Back to homepage

Legal

Privacy policy

This policy explains which personal data is processed when you visit this website, for what purpose, who receives it, and what rights you have.

Data controller

The controller responsible for data processing on this website is:

DM Werbeflaechen Service

Owner: Vincent Steiner

Biberweg 8

71686 Remseck am Neckar

Germany

Phone: +49 176 53935830

Email: info@designmediaads.de

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

We have not appointed a data protection officer. The conditions of Art. 37 GDPR and Section 38 BDSG do not apply to us. For any data protection question, please use the contact details above.

Hosting and server log files

This website runs on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Germany.

Every time a page is called up, your browser automatically transmits data that the server records in log files. This covers the IP address of the requesting device, the date and time of access, the address requested, the previously visited page, the browser used including its version, the operating system, and the volume of data transferred.

This processing is technically necessary in order to deliver the website, keep it running reliably, and detect attacks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of this website. Log files are deleted after seven days at the latest. We keep them longer only where this is required to investigate a specific security incident.

Technical maintenance and operation of the website are carried out by Niels Schwarz Digital Services, owner Niels Schwarz, Germany, acting as a processor. Hetzner Online GmbH is engaged as a sub-processor. Data processing agreements under Art. 28 GDPR are in place with both.

Images on this website are converted to the AVIF and WebP formats on our own server and delivered from there. No external image service is used.

Encrypted connection

This website uses transport encryption in line with current technical standards. You can recognise an encrypted connection by the https prefix in your browser address bar and by the padlock symbol.

While encryption is active, the data you send us cannot be read by third parties in transit. In addition, we protect the server through up to date software, a firewall, and separated access rights.

Cookies and storage on your device

We do not use analytics, tracking, or advertising cookies. There is no reach measurement and no user profiling.

Only two technically necessary items are stored.

NEXT_LOCALE. A cookie that stores the language you selected so that the site appears in German or English on later visits. Lifetime one year, transmission restriction SameSite Lax.

designmedia_cookie_consent. An entry in your browser local storage recording that you have seen the privacy notice on this site, so the notice is not shown again on every visit. The entry contains only the status and a time stamp.

Both are strictly necessary for us to provide the service you have expressly requested. They are therefore exempt from consent under Section 25(2) no. 2 TDDDG. The subsequent processing of the stored information is based on Art. 6(1)(f) GDPR. Our legitimate interest is a working website delivered in the language you selected.

You can delete or block cookies and local storage at any time in your browser settings. The website will remain fully usable, but it will no longer remember your language choice.

Inquiry form

You can send us an advertising inquiry through the form on this website. We process the details you enter there: first and last name, company, email address, phone number, the advertising surfaces you selected together with the number of faces requested or your request for a recommendation, your preferred way of being contacted, and your questions and comments in the free text field.

The purpose is to handle your inquiry and to prepare a possible contract for advertising space. The legal basis is Art. 6(1)(b) GDPR, because the processing is necessary for pre-contractual steps taken at your request. Where your inquiry is not aimed at a contract, we base the processing on Art. 6(1)(f) GDPR. Our legitimate interest is answering inquiries addressed to our business.

To keep automated programs from misusing the form, we check two technical signals: a field that is invisible to you and only filled in by programs, and the time elapsed between the form loading and being submitted. No additional personal data is collected for this and the check values are not stored. The legal basis is Art. 6(1)(f) GDPR with our legitimate interest in preventing spam.

Storage and delivery of your enquiry

When you submit the enquiry form, your enquiry is first stored on our server in Germany and then delivered by email to our mailbox. Storing it before sending makes sure your enquiry is not lost if delivery fails. It contains the same details you entered into the form.

Delivery runs through our own email system at Google Workspace. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the data solely for us and on our instructions, on the basis of a data processing agreement under Art. 28 GDPR in the form of the Google Cloud Data Processing Addendum.

The handover to our mailbox does not happen from your browser but from our own server. Your IP address and your browser identifier are therefore not transmitted. What is transmitted is only the content you entered into the form, together with your email address as the reply address so that we can answer you directly.

Google Ireland Limited may draw on systems operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA, in order to run its services. This can involve a transfer to the United States. Google LLC is certified under the EU-US Data Privacy Framework. In its implementing decision of 10 July 2023, the European Commission established that certified companies in the United States provide an adequate level of protection. The transfer is therefore based on Art. 45(1) GDPR. In addition, Google has agreed to the European Commission Standard Contractual Clauses under Art. 46(2)(c) GDPR. You can request a copy of those clauses from us at info@designmediaads.de.

For technical reasons the record on our server also notes whether delivery succeeded. Our server log files contain only a sequential reference number and, where applicable, a technical error message, none of your details.

We delete your enquiry from the record and from the mailbox once it has been dealt with, and twelve months after the last contact at the latest. If a contract is concluded, we keep the related records for six years under Section 257(4) HGB and, where they are relevant for tax purposes, for ten years under Section 147(3) AO.

Further information on data processing by Google is available at https://policies.google.com/privacy.

Contact by email and telephone

If you write to us by email or call us, we process your details in order to deal with your request. For emails this covers your email address, your name, and the content of your message including attachments; for calls it covers your phone number and whatever you tell us during the conversation.

The legal basis is Art. 6(1)(b) GDPR where your message relates to entering into or performing a contract. In all other cases it is Art. 6(1)(f) GDPR with our legitimate interest in answering inquiries.

We delete messages once your request has been dealt with and no statutory retention obligation applies, and twelve months after the last contact at the latest. Business correspondence is subject to the commercial and tax retention periods under Section 257 HGB and Section 147 AO.

Please note that an unencrypted email is not necessarily fully protected in transit. For confidential information we are happy to offer you another way of sending it.

Appointment booking via Cal.com

On the contact page you can book an appointment for a first conversation. We use the Cal.com service for this. The provider is Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. Felix Kolodziej is named as its representative in the European Union under Art. 27 GDPR, reachable at felix@cal.com.

The calendar does not load on its own. At first you only see a notice and a button. Only when you click it does your browser establish a connection to Cal.com. Until then no data is transmitted to Cal.com and no cookies from Cal.com are set.

With that click your browser transmits the data technically required to establish the connection to Cal.com, including your IP address, your browser identifier and the page you are on. If you then book an appointment, Cal.com additionally processes the details you enter in the booking dialogue, in particular your name, your email address and the slot you selected.

The legal basis for loading the calendar, and for the associated storage on your device, is your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR, which you give by clicking the button. You can withdraw it at any time with effect for the future by leaving the page without clicking again or by clearing the stored data in your browser. The lawfulness of processing carried out before the withdrawal is not affected.

The legal basis for processing your booking details is Art. 6(1)(b) GDPR, because the processing is necessary in order to take steps at your request prior to entering into a contract.

Cal.com processes the data in the United States. A data processing agreement under Art. 28 GDPR is in place with Cal.com. The transfer to the United States is based on the European Commission Standard Contractual Clauses under Art. 46(2)(c) GDPR. You can request a copy of those clauses from us at info@designmediaads.de.

If you would rather not use the calendar, you can reach us at any time by phone or email using the contact details given in the imprint.

Further information on data processing by Cal.com is available at https://cal.com/privacy.

Map of advertising locations (OpenFreeMap)

This website shows the locations of our advertising surfaces on an interactive map. The map is rendered with the open source MapLibre GL library, which is served from our own server. The map material, meaning the tiles, glyphs, and icons of the Positron style, comes from OpenFreeMap at tiles.openfreemap.org.

OpenFreeMap is operated by Hyperknot Software Kft., Petofi Sandor utca 48., 2724 Ujlengyel, Hungary. When the map sections load, your browser connects directly to that service. In doing so it transmits your IP address, the map sections requested, and technical details such as browser type, operating system, referrer, and the time of the request.

OpenFreeMap states that it does not log IP addresses in normal operation and only enables IP logging for a maximum of 30 days when it detects a specific security incident, after which those logs are deleted. According to its own statement the service does not use cookies or other tracking technologies. No registration, key, or user account is required.

OpenFreeMap uses the content delivery network of Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA, for delivery. Your request may therefore pass through servers in the United States. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, so the transfer is based on Art. 45(1) GDPR.

The legal basis for embedding the map is Art. 6(1)(f) GDPR. Our legitimate interest is showing our locations clearly using a map service that does not build user profiles. We do not use map services from Google or Mapbox.

The OpenFreeMap privacy policy is available at https://openfreemap.org/privacy and the Cloudflare privacy policy at https://www.cloudflare.com/privacypolicy.

Fonts

We use the Plus Jakarta Sans typeface. The font files are downloaded when the website is built and stored on our own server. Your browser loads them from there only.

No connection to Google Fonts or any other external font service is established when you visit this website. No data is transmitted to third parties in this context.

Recipients of your data

We pass on personal data only where this is necessary for the purposes described or where we are legally required to do so. The recipients are:

Niels Schwarz Digital Services, owner Niels Schwarz, Germany. Technical maintenance and operation of this website as a processor.

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Provision and operation of the server as a sub-processor.

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Operating our email system and therefore delivering and holding the enquiries, acting as a processor.

Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. Appointment booking, only if you explicitly load the calendar.

Hyperknot Software Kft., Petofi Sandor utca 48., 2724 Ujlengyel, Hungary. Provider of the map material, which your browser requests directly when the map loads.

Data processing agreements under Art. 28 GDPR are in place with all processors. They bind the processors to our instructions and oblige them to maintain confidentiality and appropriate technical safeguards.

Beyond that, our tax adviser, our bank, and public authorities receive data only where statutory obligations or the performance of a contract require it. We do not pass on data for advertising purposes and we do not sell data.

Transfers to third countries

Personal data is transferred to countries outside the European Union and the European Economic Area in three cases.

First, when enquiries are delivered and held, because Google Ireland Limited may draw on systems operated by Google LLC in the United States in order to run its services.

Second, when map sections load, because OpenFreeMap uses the content delivery network of Cloudflare, Inc. in the United States for delivery.

Third, when you book an appointment, provided you explicitly load the calendar. Cal.com, Inc. processes the data in the United States. That transfer is covered by the European Commission Standard Contractual Clauses under Art. 46(2)(c) GDPR. We have no evidence of a certification for Cal.com under the EU-US Data Privacy Framework.

Google LLC and Cloudflare, Inc. are certified under the EU-US Data Privacy Framework. In its implementing decision of 10 July 2023, the European Commission established that certified companies in the United States provide an adequate level of protection. The transfer is therefore based on Art. 45(1) GDPR. In addition, the Standard Contractual Clauses adopted by the European Commission under Art. 46(2)(c) GDPR apply.

We will provide you with a copy of the Standard Contractual Clauses and evidence of certification on request at info@designmediaads.de. The list of certified companies is available at https://www.dataprivacyframework.gov.

No other transfers to third countries take place.

Retention periods

We store personal data only as long as it is needed for the relevant purpose or as long as statutory retention periods require. In detail:

Server log files: deleted after seven days at the latest. Longer storage only takes place in order to investigate a specific security incident and ends when that investigation is closed.

Enquiries from the form, both in the record on our server and in the mailbox, as well as emails and notes from phone calls: deleted once the matter has been dealt with, and twelve months after the last contact at the latest.

Appointments booked through Cal.com: deleted after the appointment, and twelve months after the last contact at the latest.

Records relating to concluded contracts and the associated business correspondence: six years under Section 257(4) HGB, and ten years for records relevant for tax purposes under Section 147(3) AO. The period starts at the end of the calendar year in which the transaction was completed.

NEXT_LOCALE language cookie: one year from being set, and you can delete it in your browser at any time.

designmedia_cookie_consent entry in local storage: until you delete it in your browser.

Once these periods expire, the data is deleted. Where immediate deletion is not technically possible, we block the data and exclude it from any further processing.

Whether you have to provide data

Providing your personal data is neither required by law nor by contract. You are under no obligation to send us data, and you can read this entire website without giving any information about yourself.

If you wish to use the inquiry form, however, we do need the fields marked as mandatory. Without your name, company, email address, and phone number we cannot allocate or answer your inquiry and cannot prepare a quote. You suffer no other disadvantage if you choose not to provide this information. You can reach us by phone at any time on +49 176 53935830.

No automated decision making

We do not carry out automated decision making in individual cases, including profiling, within the meaning of Art. 22(1) and (4) GDPR.

Your inquiries are read and answered by us personally. We do not build user profiles, we do not evaluate personal characteristics, and we do not take decisions about you based solely on automated processing.

Your rights

You have the following rights in relation to your personal data:

Access under Art. 15 GDPR to whether and which data we process about you, for what purposes, to which recipients, and for how long.

Rectification of inaccurate data and completion of incomplete data under Art. 16 GDPR.

Erasure under Art. 17 GDPR, provided no statutory retention obligation and no remaining purpose stands in the way.

Restriction of processing under Art. 18 GDPR, for example while we verify the accuracy of data you have contested.

Data portability under Art. 20 GDPR, meaning release of the data you provided in a common machine readable format or transmission to another controller.

Withdrawal of a consent you have given, under Art. 7(3) GDPR, at any time and with effect for the future. The lawfulness of processing carried out before the withdrawal is not affected.

An informal message to info@designmediaads.de or a letter to the address given in the controller section is enough. We respond without undue delay and within one month of receiving your request at the latest. Access and the first copy are free of charge. To avoid releasing your data to unauthorised persons, we may ask you to prove your identity.

Right to object

Where we process data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21(1) GDPR to object to that processing at any time on grounds relating to your particular situation. On this website this concerns the server log files, the technically necessary storage in your browser, the spam protection in the inquiry form, and the embedded map.

If you object, we will stop processing the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or unless the processing serves to establish, exercise, or defend legal claims.

Where your data is processed for direct marketing purposes, you have the right under Art. 21(2) GDPR to object at any time without giving reasons. After such an objection we will no longer use your data for that purpose.

Please send your objection informally to info@designmediaads.de or to the address given in the controller section.

Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement.

The authority responsible for us is:

Der Landesbeauftragte fuer den Datenschutz und die Informationsfreiheit Baden-Wuerttemberg

Heilbronner Strasse 35

70191 Stuttgart, Germany

Postal address: Postfach 10 29 32, 70025 Stuttgart

Phone: +49 711 615541 0

Email: poststelle@lfdi.bwl.de

Web: https://www.baden-wuerttemberg.datenschutz.de

We would ask you to contact us first if you have a complaint. This does not affect your right to lodge a complaint with the authority.

Changes to this privacy policy

We adapt this privacy policy whenever the legal situation, the technology we use, or our services change. The version published at the time applies to each new visit to this website.

The date of the current version is shown at the top of this page. The applicable version is available at any time at https://designmediaads.de/en/privacy.