Privacy Policy
Last updated: September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
IZP Dresden mbH
Am Waldschlösschen 4
01099 Dresden
Germany
Phone: +49 351 8040-323
Email: info@izp.de
Managing Shareholder: Dr. Harald Jung
2. General Information on Data Processing
We process personal data only to the extent necessary to provide our website and services, where a legal basis exists for such processing or where you have given your consent.
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, contact details, communication content, contractual and registration data, as well as technical data that may be processed when using a website.
The respective purposes and legal bases of processing, as well as further information on recipients and retention periods, are explained below for the individual processing activities.
3. Provision of the Website and Server Log Files
When you access our website, our web server processes technical information that is necessary for operation. This may include in particular:
- the IP address of the device used to access the website,
- date and time of access,
- the page or file accessed,
- the amount of data transferred and access status,
- the referrer URL, where transmitted by the browser,
- the browser used and browser version, and
- the operating system of the device used.
This processing is carried out in order to provide the website technically, to ensure system security and stability, and to detect and prevent abusive or security-relevant access.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and technically error-free operation of our website.
Server log data is generally deleted or anonymised no later than 14 days after collection, unless longer storage is required to investigate or prevent a specific security incident.
Recipients may include hosting, maintenance and IT service providers used by us insofar as they are required for the technical operation of our website. Where such service providers process personal data on our behalf, they are engaged as processors in accordance with the applicable legal requirements.
4. Encrypted Data Transmission
Our website uses an encrypted HTTPS connection. This protects data transmitted between your browser and our web server against unauthorised access during transmission in accordance with the current state of technology.
5. Cookies and Similar Storage Technologies
Our website uses cookies and similar technologies such as your browser’s local storage. Information may be stored on your device or information already stored there may be accessed.
Storage or access that is strictly necessary for technical purposes is carried out on the basis of Section 25(2) TDDDG, insofar as it is necessary to provide a digital service expressly requested by you.
For cookies or similar technologies that are not technically necessary, we obtain your consent before storing or accessing information in accordance with Section 25(1) TDDDG. Where personal data is processed in this context, such processing is based on your consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw or change your consent at any time with effect for the future via our cookie settings. The lawfulness of processing carried out on the basis of consent prior to its withdrawal remains unaffected.
Further information on the cookies and storage technologies currently used on our website, their purposes and retention periods can be found in our
Cookie Policy (EU).
6. Consent Management with Complianz
We use Complianz on our website to manage your consent to cookies and similar technologies.
Complianz stores the privacy settings and consent decisions you make so that they can be taken into account on subsequent visits and, where necessary, documented. For this purpose, cookies with names such as cmplz_* are used.
Under our current configuration, the relevant consent information is stored for up to 365 days.
The storage of information required for consent management is based on Section 25(2) No. 2 TDDDG. Where personal data is processed for the purpose of documenting and demonstrating consent, such processing is carried out in order to comply with our accountability and documentation obligations under Art. 6(1)© GDPR in conjunction with Art. 5(2) and Art. 7(1) GDPR.
7. Website Analytics with Burst Statistics
We use Burst Statistics to statistically analyse the use of our website. Burst Statistics is integrated into our WordPress installation. The statistical data collected is generally stored within our own WordPress installation or on our web server.
The following information may in particular be processed:
- pages and content accessed,
- time and duration of page views,
- referrer or source of a page view,
- browser and device type used,
- operating system,
- interactions with our website, and
- technical information required for statistical analysis.
In our current configuration, Burst Statistics uses the first-party cookie burst_uid. This contains a randomly generated visitor identifier and enables page views from the same browser to be grouped together for statistical purposes. The cookie is currently stored for up to one month.
Processing by Burst Statistics takes place only if you have consented to the use of statistical technologies via our consent management system.
The legal bases are Section 25(1) TDDDG for storing or accessing information on your device and Art. 6(1)(a) GDPR for the associated processing of personal data.
You may withdraw your consent at any time with effect for the future via our cookie settings.
The data collected with Burst Statistics is not used by us for personalised advertising or to create personal marketing profiles. Under our current configuration, the statistical data is not disclosed to third parties for advertising purposes.
8. Accessibility Functions with OneTap
We use the OneTap accessibility tool on our website. OneTap allows visitors to individually adjust various display, contrast, font, navigation and other accessibility settings.
According to the provider, OneTap’s accessibility functions are executed entirely within the visitor’s browser. According to the provider, no user data is collected for analytics or tracking purposes and no personal visitor data is transmitted to external OneTap servers.
In order for accessibility settings selected by you to be retained during your use of our website or on subsequent page views, corresponding settings may be stored locally in your browser. For example, local storage entries such as accessibility-onetap, apop-accessibility-pro or onetap-accessibility-pro may be used.
These local storage entries are used exclusively to provide and retain the accessibility settings expressly selected by you. We do not use them for analytics, advertising or tracking purposes.
Where storage on your device is necessary to provide an accessibility function expressly selected by you, such storage is based on Section 25(2) No. 2 TDDDG.
You may reset stored accessibility settings using the OneTap functions or delete the corresponding website data in your browser.
Further information on data protection at OneTap can be found at
https://wponetap.com/tutorial/is-the-onetap-one-click-accessibility-plugin-gdpr-compliant/.
9. Website and IT Security with Wordfence
We use the Wordfence security solution to protect our website against attacks, malware, unauthorised access attempts and other forms of misuse.
The provider is:
Defiant, Inc.
1700 Westlake Ave N, Suite 200
Seattle, WA 98109
USA
Wordfence analyses access to our website in order to detect and prevent security-relevant events, attempted attacks and malware. The following data may in particular be processed:
- IP address and, where applicable, proxy IP address,
- requested URL,
- HTTP headers and technical request information,
- where applicable, the content of an HTTP request insofar as this is necessary for security checks,
- for logged-in users, where applicable, username and email address, and
- technical information relating to security-relevant events.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, our IT systems and the data processed through them against attacks, malware and misuse.
Wordfence may use cookies that are technically necessary, in particular to recognise logged-in users within the scope of its security functions. Where such cookies are strictly necessary to ensure the security and functionality of the website, storage is based on Section 25(2) No. 2 TDDDG.
In connection with the provision of Wordfence services, personal data may be transferred to Defiant, Inc. in the USA. According to its contractual terms, Defiant processes the relevant data as a processor. For transfers of personal data to third countries, Defiant provides in particular the Standard Contractual Clauses adopted by the European Commission.
Data is processed only for as long as necessary to provide the security functions, detect and prevent attacks, and comply with legal obligations. Security logs may be retained for a longer period depending on the nature of a security incident where this is necessary for investigation or legal defence.
Further information can be found in the
Wordfence Privacy Policy
and in the
Defiant Data Processing Addendum.
10. Contacting Us
If you contact us by email, telephone, contact form or by any other means, we process the data you provide in order to handle your enquiry and communicate with you.
This may include in particular:
- name,
- company,
- email address and telephone number,
- subject and content of your enquiry, and
- any further information you provide voluntarily.
If your enquiry relates to an existing contractual relationship or serves to prepare a contract, processing is based on Art. 6(1)(b) GDPR.
For other business or general enquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper handling and response to communications addressed to us.
The data is deleted once it is no longer required to process your enquiry and no statutory retention obligations or legitimate interests in further storage, for example for the establishment or defence of legal claims, apply.
11. Requests for Course Materials, White Papers, Specialist Information and Downloads
If you request course materials, white papers, specialist information or other documents via our website, we process the data you provide in the relevant form in order to handle your request and provide or send you the requested materials.
This may include in particular your name, company, email address and the materials requested.
Where the request serves to prepare a potential contractual relationship, processing is based on Art. 6(1)(b) GDPR. In the case of general information requests, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in providing specialist information expressly requested by visitors and in handling corresponding enquiries.
The contact details provided in connection with a request for materials will not be used for sending our newsletter solely on the basis of that request. Separate consent is required for newsletter distribution.
The data is deleted once it is no longer required to process the request and no statutory retention obligations or other legal grounds for further storage apply.
12. Registration for Seminars, Webinars, Training Courses and Events
If you register for a seminar, webinar, training course or other event, we process the personal data required to prepare, conduct and administer the relevant event.
This may include in particular:
- name and, where applicable, job function,
- company,
- business contact details,
- the selected event or training programme,
- where applicable, billing address and other invoicing data, and
- other information required to conduct the relevant event.
Processing is based on Art. 6(1)(b) GDPR for the performance of pre-contractual measures and for establishing and performing the respective contractual relationship.
Where commercial, tax or other statutory retention obligations apply, further storage is based on Art. 6(1)© GDPR.
Data is disclosed to service providers, event partners or cooperation partners only to the extent necessary for organising and conducting the relevant event, performing the contract or complying with legal obligations.
Where certain information is marked as mandatory, providing that information is necessary to process the registration or perform the contractual relationship. Without such information, the relevant registration may not be possible.
13. Newsletter
You can subscribe to our newsletter, through which we provide information in particular about our seminars and webinars, specialist publications, events and other subject-related news.
At minimum, a valid email address is required for registration.
We use a double opt-in procedure to verify subscriptions. Your newsletter subscription only becomes effective after you confirm it via a confirmation message sent to your email address. The relevant registration and confirmation processes are logged so that we can demonstrate that consent was properly obtained.
The legal basis for sending the newsletter is your consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future. In particular, you may use the unsubscribe link contained in each newsletter or contact us at info@izp.de.
After unsubscribing, your email address will be removed from the active newsletter mailing list. Where necessary, information required to demonstrate previously granted consent may be retained for the duration of statutory documentation and limitation periods. An email address retained for this purpose will no longer be used to send newsletters.
Where we use technical service providers for sending or managing the newsletter, they receive only the data required to provide the respective service and, where necessary, are engaged as processors.
14. Online Appointment Scheduling via Calendly
Our website provides links to the Calendly service for online appointment scheduling.
The provider is:
Calendly LLC
115 E Main St, Suite A1B
Buford, GA 30518
USA
Calendly is accessed via an external link. A connection to Calendly is therefore generally established only when you actively select the corresponding appointment booking link. You then leave our website and are redirected to Calendly’s service.
When using the appointment scheduling service, the following data may in particular be processed:
- name,
- email address,
- where applicable, telephone number and company,
- requested appointment,
- information you provide voluntarily, and
- technical connection and usage data.
Where appointment scheduling serves to prepare or perform a contractual relationship, processing is based on Art. 6(1)(b) GDPR.
For other business-related appointments, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the simple and efficient organisation of meetings and consultation appointments.
Calendly generally processes the personal data handled through the Calendly service for the purpose of organising appointments on our behalf as a processor. Calendly may, however, process data for its own purposes under its own responsibility, in particular when you directly visit the Calendly website.
Calendly also processes personal data in the USA and, where applicable, in other countries outside the European Economic Area. According to its own information, Calendly is certified under the EU-US Data Privacy Framework. Where this transfer mechanism is not applicable to a particular transfer, Calendly’s current Data Processing Addendum additionally provides for the Standard Contractual Clauses of the European Commission.
Further information can be found in the
Calendly Privacy Notice
and in the
Calendly Data Processing Addendum.
15. Local Provision of Fonts
We use fonts that are hosted locally on our own server in order to ensure a consistent presentation of our website.
When these fonts are loaded, no connection is established to Google Fonts servers or to other external font providers. No personal data is therefore transmitted to Google in connection with the display of these locally hosted fonts.
16. Functional Website Settings and Pop-ups
Our website may use local storage or technically necessary cookies to provide certain display or operating functions. This includes, for example, information about whether a notice or pop-up has already been displayed or closed.
Such information is used exclusively to provide the relevant website function and is not used for personalised advertising or cross-site tracking.
Where such storage is strictly necessary to provide a website function requested by you or to remember an operating decision already made by you, it is based on Section 25(2) No. 2 TDDDG.
17. Facebook Company Page
We maintain a company presence on Facebook in order to provide information about our services and activities and to communicate with prospective customers, customers and other users.
The provider of Facebook services for users in the European Economic Area is:
Meta Platforms Ireland Limited
Merrion Road
Ballsbridge
Dublin 4, D04 X2K5
Ireland
When you visit or interact with our Facebook page, Meta processes personal data in accordance with its own privacy policy. We have only limited influence over the nature, scope and duration of processing carried out by Meta under its own responsibility.
Meta also provides operators of Facebook pages with statistical analyses concerning use of the respective page (“Page Insights”). Where joint controllership pursuant to Art. 26 GDPR applies in this context, the terms provided by Meta regarding joint controllership apply.
Where we process personal data ourselves in connection with our Facebook presence, for example when responding to messages or comments, such processing is based on Art. 6(1)(b) GDPR in the case of contract-related enquiries and otherwise on Art. 6(1)(f) GDPR. Our legitimate interest lies in public relations and communication with prospective customers, customers and other users.
When using Facebook, personal data may be processed outside the European Union or the European Economic Area. Meta provides information on the data transfer mechanisms it uses in its privacy information.
Further information can be found in the
Meta Privacy Policy
and in the
information on joint controllership for Page Insights.
18. Recipients of Personal Data
We disclose personal data only where there is a legal basis for doing so, where disclosure is necessary for the performance of a contract, where we are legally obliged to do so or where you have given your consent.
Recipients or categories of recipients may include in particular:
- hosting and IT service providers,
- IT security service providers,
- email and communication service providers,
- appointment scheduling and event organisation service providers,
- tax advisers, auditors or other professional advisers subject to confidentiality obligations,
- authorities and public bodies where there is a statutory obligation, and
- other service providers insofar as their involvement is required to provide our services.
Where recipients process personal data solely on our behalf, they are engaged as processors in accordance with Art. 28 GDPR.
19. Transfers of Personal Data to Third Countries
Personal data is transferred to countries outside the European Union or the European Economic Area only to the extent described for the respective services and where the legal requirements for such transfers are met.
Such transfers may in particular be based on an adequacy decision by the European Commission, a valid certification of the relevant recipient under the EU-US Data Privacy Framework or appropriate safeguards such as the Standard Contractual Clauses of the European Commission.
20. Retention Period
Unless a specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary for the respective processing purpose.
Longer storage may in particular be required where statutory retention obligations apply, where data is required for the establishment, exercise or defence of legal claims, or where another legal basis permits further processing.
Once the respective processing purpose no longer applies and any statutory retention and limitation periods have expired, the relevant data is deleted or anonymised.
21. Your Rights
Subject to the applicable legal requirements, you have in particular the following rights:
- Right of access to your personal data pursuant to Art. 15 GDPR,
- Right to rectification of inaccurate or incomplete personal data pursuant to Art. 16 GDPR,
- Right to erasure pursuant to Art. 17 GDPR,
- Right to restriction of processing pursuant to Art. 18 GDPR,
- Right to data portability pursuant to Art. 20 GDPR, where the statutory requirements are met, and
- Right to object to certain processing activities pursuant to Art. 21 GDPR.
Where processing is based on your consent, you may withdraw your consent at any time with effect for the future. The lawfulness of processing carried out on the basis of consent prior to its withdrawal remains unaffected.
To exercise your rights, you may contact us using the contact details provided above or by email at info@izp.de.
22. Right to Object under Art. 21 GDPR
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right, pursuant to Art. 21 GDPR, to object to such processing at any time on grounds relating to your particular situation.
We will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.
23. Right to Lodge a Complaint with a Data Protection Supervisory Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.
You may in particular contact the data protection supervisory authority responsible for us:
Saxon Data Protection and Transparency Commissioner
(Sächsische Datenschutz- und Transparenzbeauftragte)
Maternistraße 17
01067 Dresden
Germany
Phone: +49 351 85471-101
Email: post@sdtb.sachsen.de
Website: www.datenschutz.sachsen.de
The right to lodge a complaint exists without prejudice to any other administrative or judicial remedy.
24. Automated Decision-Making and Profiling
No decision based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR takes place in connection with the processing activities described in this Privacy Policy.
25. Amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy if our website, the services used or the applicable legal or regulatory requirements change.
The version currently published on this website shall apply.
