Privacy Policy

Last updated: Sep­tem­ber 2026

1. Controller

The con­trol­ler within the mea­ning of the Gene­ral Data Pro­tec­tion Regu­la­ti­on (GDPR) and other appli­ca­ble data pro­tec­tion laws is: 

IZP Dres­den mbH
Am Wald­schlöss­chen 4
01099 Dresden
Germany 

Phone: +49 351 8040-323
Email: info@izp.de

Mana­ging Share­hol­der: Dr. Harald Jung 

2. General Information on Data Processing

We pro­cess per­so­nal data only to the ext­ent neces­sa­ry to pro­vi­de our web­site and ser­vices, where a legal basis exists for such pro­ces­sing or where you have given your consent. 

Per­so­nal data means any infor­ma­ti­on rela­ting to an iden­ti­fied or iden­ti­fia­ble natu­ral per­son. This includes, for exam­p­le, cont­act details, com­mu­ni­ca­ti­on con­tent, con­trac­tu­al and regis­tra­ti­on data, as well as tech­ni­cal data that may be pro­ces­sed when using a website. 

The respec­ti­ve pur­po­ses and legal bases of pro­ces­sing, as well as fur­ther infor­ma­ti­on on reci­pi­ents and reten­ti­on peri­ods, are explai­ned below for the indi­vi­du­al pro­ces­sing activities. 

3. Provision of the Website and Server Log Files

When you access our web­site, our web ser­ver pro­ces­ses tech­ni­cal infor­ma­ti­on that is neces­sa­ry for ope­ra­ti­on. This may include in particular: 

  • the IP address of the device used to access the website,
  • date and time of access,
  • the page or file accessed,
  • the amount of data trans­fer­red and access status,
  • the refer­rer URL, where trans­mit­ted by the browser,
  • the brow­ser used and brow­ser ver­si­on, and
  • the ope­ra­ting sys­tem of the device used.

This pro­ces­sing is car­ri­ed out in order to pro­vi­de the web­site tech­ni­cal­ly, to ensu­re sys­tem secu­ri­ty and sta­bi­li­ty, and to detect and pre­vent abu­si­ve or security-relevant access. 

The legal basis is Art. 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in the secu­re, sta­ble and tech­ni­cal­ly error-free ope­ra­ti­on of our website. 

Ser­ver log data is gene­ral­ly dele­ted or anony­mi­sed no later than 14 days after coll­ec­tion, unless lon­ger sto­rage is requi­red to inves­ti­ga­te or pre­vent a spe­ci­fic secu­ri­ty incident. 

Reci­pi­ents may include hos­ting, main­ten­an­ce and IT ser­vice pro­vi­ders used by us inso­far as they are requi­red for the tech­ni­cal ope­ra­ti­on of our web­site. Where such ser­vice pro­vi­ders pro­cess per­so­nal data on our behalf, they are enga­ged as pro­ces­sors in accordance with the appli­ca­ble legal requirements. 

4. Encrypted Data Transmission

Our web­site uses an encrypt­ed HTTPS con­nec­tion. This pro­tects data trans­mit­ted bet­ween your brow­ser and our web ser­ver against unaut­ho­ri­sed access during trans­mis­si­on in accordance with the cur­rent state of technology. 

5. Cookies and Similar Storage Technologies

Our web­site uses coo­kies and simi­lar tech­no­lo­gies such as your browser’s local sto­rage. Infor­ma­ti­on may be stored on your device or infor­ma­ti­on alre­a­dy stored there may be accessed. 

Sto­rage or access that is strict­ly neces­sa­ry for tech­ni­cal pur­po­ses is car­ri­ed out on the basis of Sec­tion 25(2) TDDDG, inso­far as it is neces­sa­ry to pro­vi­de a digi­tal ser­vice express­ly reques­ted by you. 

For coo­kies or simi­lar tech­no­lo­gies that are not tech­ni­cal­ly neces­sa­ry, we obtain your con­sent befo­re sto­ring or acces­sing infor­ma­ti­on in accordance with Sec­tion 25(1) TDDDG. Where per­so­nal data is pro­ces­sed in this con­text, such pro­ces­sing is based on your con­sent pur­su­ant to Art. 6(1)(a) GDPR. 

You may with­draw or chan­ge your con­sent at any time with effect for the future via our coo­kie set­tings. The lawful­ness of pro­ces­sing car­ri­ed out on the basis of con­sent prior to its with­dra­wal remains unaffected. 

Fur­ther infor­ma­ti­on on the coo­kies and sto­rage tech­no­lo­gies curr­ent­ly used on our web­site, their pur­po­ses and reten­ti­on peri­ods can be found in our
Coo­kie Poli­cy (EU).

6. Consent Management with Complianz

We use Com­pli­anz on our web­site to mana­ge your con­sent to coo­kies and simi­lar technologies. 

Com­pli­anz stores the pri­va­cy set­tings and con­sent decis­i­ons you make so that they can be taken into account on sub­se­quent visits and, where neces­sa­ry, docu­men­ted. For this pur­po­se, coo­kies with names such as cmplz_* are used. 

Under our cur­rent con­fi­gu­ra­ti­on, the rele­vant con­sent infor­ma­ti­on is stored for up to 365 days. 

The sto­rage of infor­ma­ti­on requi­red for con­sent manage­ment is based on Sec­tion 25(2) No. 2 TDDDG. Where per­so­nal data is pro­ces­sed for the pur­po­se of docu­men­ting and demons­t­ra­ting con­sent, such pro­ces­sing is car­ri­ed out in order to com­ply with our accoun­ta­bi­li­ty and docu­men­ta­ti­on obli­ga­ti­ons under Art. 6(1)© GDPR in con­junc­tion with Art. 5(2) and Art. 7(1) GDPR. 

7. Website Analytics with Burst Statistics

We use Burst Sta­tis­tics to sta­tis­ti­cal­ly analyse the use of our web­site. Burst Sta­tis­tics is inte­gra­ted into our Word­Press instal­la­ti­on. The sta­tis­ti­cal data coll­ec­ted is gene­ral­ly stored within our own Word­Press instal­la­ti­on or on our web server. 

The fol­lo­wing infor­ma­ti­on may in par­ti­cu­lar be processed: 

  • pages and con­tent accessed,
  • time and dura­ti­on of page views,
  • refer­rer or source of a page view,
  • brow­ser and device type used,
  • ope­ra­ting system,
  • inter­ac­tions with our web­site, and
  • tech­ni­cal infor­ma­ti­on requi­red for sta­tis­ti­cal analysis.

In our cur­rent con­fi­gu­ra­ti­on, Burst Sta­tis­tics uses the first-party coo­kie burst_uid. This con­ta­ins a ran­dom­ly gene­ra­ted visi­tor iden­ti­fier and enables page views from the same brow­ser to be grou­ped tog­e­ther for sta­tis­ti­cal pur­po­ses. The coo­kie is curr­ent­ly stored for up to one month. 

Pro­ces­sing by Burst Sta­tis­tics takes place only if you have con­sen­ted to the use of sta­tis­ti­cal tech­no­lo­gies via our con­sent manage­ment system. 

The legal bases are Sec­tion 25(1) TDDDG for sto­ring or acces­sing infor­ma­ti­on on your device and Art. 6(1)(a) GDPR for the asso­cia­ted pro­ces­sing of per­so­nal data. 

You may with­draw your con­sent at any time with effect for the future via our coo­kie settings. 

The data coll­ec­ted with Burst Sta­tis­tics is not used by us for per­so­na­li­sed adver­ti­sing or to crea­te per­so­nal mar­ke­ting pro­files. Under our cur­rent con­fi­gu­ra­ti­on, the sta­tis­ti­cal data is not dis­c­lo­sed to third par­ties for adver­ti­sing purposes. 

8. Accessibility Functions with OneTap

We use the OneTap acces­si­bi­li­ty tool on our web­site. OneTap allows visi­tors to indi­vi­du­al­ly adjust various dis­play, con­trast, font, navi­ga­ti­on and other acces­si­bi­li­ty settings. 

Accor­ding to the pro­vi­der, OneTap’s acces­si­bi­li­ty func­tions are exe­cu­ted enti­re­ly within the visitor’s brow­ser. Accor­ding to the pro­vi­der, no user data is coll­ec­ted for ana­ly­tics or track­ing pur­po­ses and no per­so­nal visi­tor data is trans­mit­ted to exter­nal OneTap servers. 

In order for acces­si­bi­li­ty set­tings sel­ec­ted by you to be retai­ned during your use of our web­site or on sub­se­quent page views, cor­re­spon­ding set­tings may be stored local­ly in your brow­ser. For exam­p­le, local sto­rage ent­ries such as accessibility-onetap, apop-accessibility-pro or onetap-accessibility-pro may be used. 

These local sto­rage ent­ries are used exclu­si­ve­ly to pro­vi­de and retain the acces­si­bi­li­ty set­tings express­ly sel­ec­ted by you. We do not use them for ana­ly­tics, adver­ti­sing or track­ing purposes. 

Where sto­rage on your device is neces­sa­ry to pro­vi­de an acces­si­bi­li­ty func­tion express­ly sel­ec­ted by you, such sto­rage is based on Sec­tion 25(2) No. 2 TDDDG. 

You may reset stored acces­si­bi­li­ty set­tings using the OneTap func­tions or dele­te the cor­re­spon­ding web­site data in your browser. 

Fur­ther infor­ma­ti­on on data pro­tec­tion at OneTap can be found at
https://wponetap.com/tutorial/is-the-onetap-one-click-accessibility-plugin-gdpr-compliant/.

9. Website and IT Security with Wordfence

We use the Word­fence secu­ri­ty solu­ti­on to pro­tect our web­site against attacks, mal­wa­re, unaut­ho­ri­sed access attempts and other forms of misuse. 

The pro­vi­der is: 

Defi­ant, Inc.
1700 West­la­ke Ave N, Suite 200
Seat­tle, WA 98109
USA 

Word­fence ana­ly­ses access to our web­site in order to detect and pre­vent security-relevant events, attempt­ed attacks and mal­wa­re. The fol­lo­wing data may in par­ti­cu­lar be processed: 

  • IP address and, where appli­ca­ble, proxy IP address,
  • reques­ted URL,
  • HTTP hea­ders and tech­ni­cal request information,
  • where appli­ca­ble, the con­tent of an HTTP request inso­far as this is neces­sa­ry for secu­ri­ty checks,
  • for logged-in users, where appli­ca­ble, user­na­me and email address, and
  • tech­ni­cal infor­ma­ti­on rela­ting to security-relevant events.

Pro­ces­sing is based on Art. 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in pro­tec­ting our web­site, our IT sys­tems and the data pro­ces­sed through them against attacks, mal­wa­re and misuse. 

Word­fence may use coo­kies that are tech­ni­cal­ly neces­sa­ry, in par­ti­cu­lar to reco­g­ni­se logged-in users within the scope of its secu­ri­ty func­tions. Where such coo­kies are strict­ly neces­sa­ry to ensu­re the secu­ri­ty and func­tion­a­li­ty of the web­site, sto­rage is based on Sec­tion 25(2) No. 2 TDDDG. 

In con­nec­tion with the pro­vi­si­on of Word­fence ser­vices, per­so­nal data may be trans­fer­red to Defi­ant, Inc. in the USA. Accor­ding to its con­trac­tu­al terms, Defi­ant pro­ces­ses the rele­vant data as a pro­ces­sor. For trans­fers of per­so­nal data to third count­ries, Defi­ant pro­vi­des in par­ti­cu­lar the Stan­dard Con­trac­tu­al Clau­ses adopted by the Euro­pean Commission. 

Data is pro­ces­sed only for as long as neces­sa­ry to pro­vi­de the secu­ri­ty func­tions, detect and pre­vent attacks, and com­ply with legal obli­ga­ti­ons. Secu­ri­ty logs may be retai­ned for a lon­ger peri­od depen­ding on the natu­re of a secu­ri­ty inci­dent where this is neces­sa­ry for inves­ti­ga­ti­on or legal defence. 

Fur­ther infor­ma­ti­on can be found in the
Word­fence Pri­va­cy Policy
and in the
Defi­ant Data Pro­ces­sing Adden­dum.

10. Contacting Us

If you cont­act us by email, tele­pho­ne, cont­act form or by any other means, we pro­cess the data you pro­vi­de in order to hand­le your enquiry and com­mu­ni­ca­te with you. 

This may include in particular: 

  • name,
  • com­pa­ny,
  • email address and tele­pho­ne number,
  • sub­ject and con­tent of your enquiry, and
  • any fur­ther infor­ma­ti­on you pro­vi­de voluntarily.

If your enquiry rela­tes to an exis­ting con­trac­tu­al rela­ti­onship or ser­ves to prepa­re a con­tract, pro­ces­sing is based on Art. 6(1)(b) GDPR. 

For other busi­ness or gene­ral enqui­ries, pro­ces­sing is based on Art. 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in the pro­per hand­ling and respon­se to com­mu­ni­ca­ti­ons addres­sed to us. 

The data is dele­ted once it is no lon­ger requi­red to pro­cess your enquiry and no sta­tu­to­ry reten­ti­on obli­ga­ti­ons or legi­ti­ma­te inte­rests in fur­ther sto­rage, for exam­p­le for the estab­lish­ment or defence of legal claims, apply. 

11. Requests for Course Materials, White Papers, Specialist Information and Downloads

If you request cour­se mate­ri­als, white papers, spe­cia­list infor­ma­ti­on or other docu­ments via our web­site, we pro­cess the data you pro­vi­de in the rele­vant form in order to hand­le your request and pro­vi­de or send you the reques­ted materials. 

This may include in par­ti­cu­lar your name, com­pa­ny, email address and the mate­ri­als requested. 

Where the request ser­ves to prepa­re a poten­ti­al con­trac­tu­al rela­ti­onship, pro­ces­sing is based on Art. 6(1)(b) GDPR. In the case of gene­ral infor­ma­ti­on requests, pro­ces­sing is based on Art. 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in pro­vi­ding spe­cia­list infor­ma­ti­on express­ly reques­ted by visi­tors and in hand­ling cor­re­spon­ding enquiries. 

The cont­act details pro­vi­ded in con­nec­tion with a request for mate­ri­als will not be used for sen­ding our news­let­ter sole­ly on the basis of that request. Sepa­ra­te con­sent is requi­red for news­let­ter distribution. 

The data is dele­ted once it is no lon­ger requi­red to pro­cess the request and no sta­tu­to­ry reten­ti­on obli­ga­ti­ons or other legal grounds for fur­ther sto­rage apply. 

12. Registration for Seminars, Webinars, Training Courses and Events

If you regis­ter for a semi­nar, web­i­nar, trai­ning cour­se or other event, we pro­cess the per­so­nal data requi­red to prepa­re, con­duct and admi­nis­ter the rele­vant event. 

This may include in particular: 

  • name and, where appli­ca­ble, job function,
  • com­pa­ny,
  • busi­ness cont­act details,
  • the sel­ec­ted event or trai­ning programme,
  • where appli­ca­ble, bil­ling address and other invoi­cing data, and
  • other infor­ma­ti­on requi­red to con­duct the rele­vant event.

Pro­ces­sing is based on Art. 6(1)(b) GDPR for the per­for­mance of pre-contractual mea­su­res and for estab­li­shing and per­forming the respec­ti­ve con­trac­tu­al relationship. 

Where com­mer­cial, tax or other sta­tu­to­ry reten­ti­on obli­ga­ti­ons apply, fur­ther sto­rage is based on Art. 6(1)© GDPR. 

Data is dis­c­lo­sed to ser­vice pro­vi­ders, event part­ners or coope­ra­ti­on part­ners only to the ext­ent neces­sa­ry for orga­ni­s­ing and con­duc­ting the rele­vant event, per­forming the con­tract or com­ply­ing with legal obligations. 

Where cer­tain infor­ma­ti­on is mark­ed as man­da­to­ry, pro­vi­ding that infor­ma­ti­on is neces­sa­ry to pro­cess the regis­tra­ti­on or per­form the con­trac­tu­al rela­ti­onship. Wit­hout such infor­ma­ti­on, the rele­vant regis­tra­ti­on may not be possible. 

13. Newsletter

You can sub­scri­be to our news­let­ter, through which we pro­vi­de infor­ma­ti­on in par­ti­cu­lar about our semi­nars and web­i­nars, spe­cia­list publi­ca­ti­ons, events and other subject-related news. 

At mini­mum, a valid email address is requi­red for registration. 

We use a dou­ble opt-in pro­ce­du­re to veri­fy sub­scrip­ti­ons. Your news­let­ter sub­scrip­ti­on only beco­mes effec­ti­ve after you con­firm it via a con­fir­ma­ti­on mes­sa­ge sent to your email address. The rele­vant regis­tra­ti­on and con­fir­ma­ti­on pro­ces­ses are log­ged so that we can demons­tra­te that con­sent was pro­per­ly obtained. 

The legal basis for sen­ding the news­let­ter is your con­sent pur­su­ant to Art. 6(1)(a) GDPR. 

You may with­draw your con­sent at any time with effect for the future. In par­ti­cu­lar, you may use the unsub­scri­be link con­tai­ned in each news­let­ter or cont­act us at info@izp.de.

After unsub­scrib­ing, your email address will be remo­ved from the acti­ve news­let­ter mai­ling list. Where neces­sa­ry, infor­ma­ti­on requi­red to demons­tra­te pre­vious­ly gran­ted con­sent may be retai­ned for the dura­ti­on of sta­tu­to­ry docu­men­ta­ti­on and limi­ta­ti­on peri­ods. An email address retai­ned for this pur­po­se will no lon­ger be used to send newsletters. 

Where we use tech­ni­cal ser­vice pro­vi­ders for sen­ding or mana­ging the news­let­ter, they recei­ve only the data requi­red to pro­vi­de the respec­ti­ve ser­vice and, where neces­sa­ry, are enga­ged as processors. 

14. Online Appointment Scheduling via Calendly

Our web­site pro­vi­des links to the Calend­ly ser­vice for online appoint­ment scheduling. 

The pro­vi­der is: 

Calend­ly LLC
115 E Main St, Suite A1B
Buford, GA 30518
USA 

Calend­ly is acces­sed via an exter­nal link. A con­nec­tion to Calend­ly is the­r­e­fo­re gene­ral­ly estab­lished only when you actively sel­ect the cor­re­spon­ding appoint­ment boo­king link. You then leave our web­site and are redi­rec­ted to Calendly’s service. 

When using the appoint­ment sche­du­ling ser­vice, the fol­lo­wing data may in par­ti­cu­lar be processed: 

  • name,
  • email address,
  • where appli­ca­ble, tele­pho­ne num­ber and company,
  • reques­ted appointment,
  • infor­ma­ti­on you pro­vi­de vol­un­t­a­ri­ly, and
  • tech­ni­cal con­nec­tion and usage data.

Where appoint­ment sche­du­ling ser­ves to prepa­re or per­form a con­trac­tu­al rela­ti­onship, pro­ces­sing is based on Art. 6(1)(b) GDPR. 

For other business-related appoint­ments, pro­ces­sing is based on Art. 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in the simp­le and effi­ci­ent orga­ni­sa­ti­on of mee­tings and con­sul­ta­ti­on appointments. 

Calend­ly gene­ral­ly pro­ces­ses the per­so­nal data hand­led through the Calend­ly ser­vice for the pur­po­se of orga­ni­s­ing appoint­ments on our behalf as a pro­ces­sor. Calend­ly may, howe­ver, pro­cess data for its own pur­po­ses under its own respon­si­bi­li­ty, in par­ti­cu­lar when you direct­ly visit the Calend­ly website. 

Calend­ly also pro­ces­ses per­so­nal data in the USA and, where appli­ca­ble, in other count­ries out­side the Euro­pean Eco­no­mic Area. Accor­ding to its own infor­ma­ti­on, Calend­ly is cer­ti­fied under the EU-US Data Pri­va­cy Frame­work. Where this trans­fer mecha­nism is not appli­ca­ble to a par­ti­cu­lar trans­fer, Calendly’s cur­rent Data Pro­ces­sing Adden­dum addi­tio­nal­ly pro­vi­des for the Stan­dard Con­trac­tu­al Clau­ses of the Euro­pean Commission. 

Fur­ther infor­ma­ti­on can be found in the
Calend­ly Pri­va­cy Notice
and in the
Calend­ly Data Pro­ces­sing Adden­dum.

15. Local Provision of Fonts

We use fonts that are hos­ted local­ly on our own ser­ver in order to ensu­re a con­sis­tent pre­sen­ta­ti­on of our website. 

When these fonts are loa­ded, no con­nec­tion is estab­lished to Goog­le Fonts ser­vers or to other exter­nal font pro­vi­ders. No per­so­nal data is the­r­e­fo­re trans­mit­ted to Goog­le in con­nec­tion with the dis­play of these local­ly hos­ted fonts. 

16. Functional Website Settings and Pop-ups

Our web­site may use local sto­rage or tech­ni­cal­ly neces­sa­ry coo­kies to pro­vi­de cer­tain dis­play or ope­ra­ting func­tions. This includes, for exam­p­le, infor­ma­ti­on about whe­ther a noti­ce or pop-up has alre­a­dy been dis­play­ed or closed. 

Such infor­ma­ti­on is used exclu­si­ve­ly to pro­vi­de the rele­vant web­site func­tion and is not used for per­so­na­li­sed adver­ti­sing or cross-site tracking. 

Where such sto­rage is strict­ly neces­sa­ry to pro­vi­de a web­site func­tion reques­ted by you or to remem­ber an ope­ra­ting decis­i­on alre­a­dy made by you, it is based on Sec­tion 25(2) No. 2 TDDDG. 

17. Facebook Company Page

We main­tain a com­pa­ny pre­sence on Face­book in order to pro­vi­de infor­ma­ti­on about our ser­vices and acti­vi­ties and to com­mu­ni­ca­te with pro­s­pec­ti­ve cus­to­mers, cus­to­mers and other users. 

The pro­vi­der of Face­book ser­vices for users in the Euro­pean Eco­no­mic Area is: 

Meta Plat­forms Ire­land Limited
Mer­ri­on Road
Ballsbridge
Dub­lin 4, D04 X2K5
Ireland 

When you visit or inter­act with our Face­book page, Meta pro­ces­ses per­so­nal data in accordance with its own pri­va­cy poli­cy. We have only limi­t­ed influence over the natu­re, scope and dura­ti­on of pro­ces­sing car­ri­ed out by Meta under its own responsibility. 

Meta also pro­vi­des ope­ra­tors of Face­book pages with sta­tis­ti­cal ana­ly­ses con­cer­ning use of the respec­ti­ve page (“Page Insights”). Where joint con­trol­ler­ship pur­su­ant to Art. 26 GDPR appli­es in this con­text, the terms pro­vi­ded by Meta regar­ding joint con­trol­ler­ship apply. 

Where we pro­cess per­so­nal data our­sel­ves in con­nec­tion with our Face­book pre­sence, for exam­p­le when respon­ding to mes­sa­ges or comm­ents, such pro­ces­sing is based on Art. 6(1)(b) GDPR in the case of contract-related enqui­ries and other­wi­se on Art. 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in public rela­ti­ons and com­mu­ni­ca­ti­on with pro­s­pec­ti­ve cus­to­mers, cus­to­mers and other users. 

When using Face­book, per­so­nal data may be pro­ces­sed out­side the Euro­pean Union or the Euro­pean Eco­no­mic Area. Meta pro­vi­des infor­ma­ti­on on the data trans­fer mecha­nisms it uses in its pri­va­cy information. 

Fur­ther infor­ma­ti­on can be found in the
Meta Pri­va­cy Policy
and in the
infor­ma­ti­on on joint con­trol­ler­ship for Page Insights.

18. Recipients of Personal Data

We dis­c­lo­se per­so­nal data only where there is a legal basis for doing so, where dis­clo­sure is neces­sa­ry for the per­for­mance of a con­tract, where we are legal­ly obli­ged to do so or where you have given your consent. 

Reci­pi­ents or cate­go­ries of reci­pi­ents may include in particular: 

  • hos­ting and IT ser­vice providers,
  • IT secu­ri­ty ser­vice providers,
  • email and com­mu­ni­ca­ti­on ser­vice providers,
  • appoint­ment sche­du­ling and event orga­ni­sa­ti­on ser­vice providers,
  • tax advi­sers, audi­tors or other pro­fes­sio­nal advi­sers sub­ject to con­fi­den­tia­li­ty obligations,
  • aut­ho­ri­ties and public bodies where there is a sta­tu­to­ry obli­ga­ti­on, and
  • other ser­vice pro­vi­ders inso­far as their invol­vement is requi­red to pro­vi­de our services.

Where reci­pi­ents pro­cess per­so­nal data sole­ly on our behalf, they are enga­ged as pro­ces­sors in accordance with Art. 28 GDPR. 

19. Transfers of Personal Data to Third Countries

Per­so­nal data is trans­fer­red to count­ries out­side the Euro­pean Union or the Euro­pean Eco­no­mic Area only to the ext­ent descri­bed for the respec­ti­ve ser­vices and where the legal requi­re­ments for such trans­fers are met. 

Such trans­fers may in par­ti­cu­lar be based on an ade­quacy decis­i­on by the Euro­pean Com­mis­si­on, a valid cer­ti­fi­ca­ti­on of the rele­vant reci­pi­ent under the EU-US Data Pri­va­cy Frame­work or appro­pria­te safe­guards such as the Stan­dard Con­trac­tu­al Clau­ses of the Euro­pean Commission. 

20. Retention Period

Unless a spe­ci­fic reten­ti­on peri­od is sta­ted in this Pri­va­cy Poli­cy, we retain per­so­nal data only for as long as neces­sa­ry for the respec­ti­ve pro­ces­sing purpose. 

Lon­ger sto­rage may in par­ti­cu­lar be requi­red where sta­tu­to­ry reten­ti­on obli­ga­ti­ons apply, where data is requi­red for the estab­lish­ment, exer­cise or defence of legal claims, or where ano­ther legal basis per­mits fur­ther processing. 

Once the respec­ti­ve pro­ces­sing pur­po­se no lon­ger appli­es and any sta­tu­to­ry reten­ti­on and limi­ta­ti­on peri­ods have expi­red, the rele­vant data is dele­ted or anonymised. 

21. Your Rights

Sub­ject to the appli­ca­ble legal requi­re­ments, you have in par­ti­cu­lar the fol­lo­wing rights: 

  • Right of access to your per­so­nal data pur­su­ant to Art. 15 GDPR,
  • Right to rec­ti­fi­ca­ti­on of inac­cu­ra­te or incom­ple­te per­so­nal data pur­su­ant to Art. 16 GDPR,
  • Right to era­su­re pur­su­ant to Art. 17 GDPR,
  • Right to rest­ric­tion of pro­ces­sing pur­su­ant to Art. 18 GDPR,
  • Right to data por­ta­bi­li­ty pur­su­ant to Art. 20 GDPR, where the sta­tu­to­ry requi­re­ments are met, and
  • Right to object to cer­tain pro­ces­sing acti­vi­ties pur­su­ant to Art. 21 GDPR.

Where pro­ces­sing is based on your con­sent, you may with­draw your con­sent at any time with effect for the future. The lawful­ness of pro­ces­sing car­ri­ed out on the basis of con­sent prior to its with­dra­wal remains unaffected. 

To exer­cise your rights, you may cont­act us using the cont­act details pro­vi­ded above or by email at info@izp.de.

22. Right to Object under Art. 21 GDPR


Where we pro­cess per­so­nal data on the basis of Art. 6(1)(f) GDPR, you have the right, pur­su­ant to Art. 21 GDPR, to object to such pro­ces­sing at any time on grounds rela­ting to your par­ti­cu­lar situation.

We will then no lon­ger pro­cess the per­so­nal data con­cer­ned unless we can demons­tra­te com­pel­ling legi­ti­ma­te grounds for the pro­ces­sing which over­ri­de your inte­rests, rights and free­doms, or unless the pro­ces­sing ser­ves the estab­lish­ment, exer­cise or defence of legal claims. 

23. Right to Lodge a Complaint with a Data Protection Supervisory Authority

Pur­su­ant to Art. 77 GDPR, you have the right to lodge a com­plaint with a data pro­tec­tion super­vi­so­ry aut­ho­ri­ty if you belie­ve that the pro­ces­sing of your per­so­nal data inf­rin­ges appli­ca­ble data pro­tec­tion law. 

You may in par­ti­cu­lar cont­act the data pro­tec­tion super­vi­so­ry aut­ho­ri­ty respon­si­ble for us: 

Saxon Data Pro­tec­tion and Trans­pa­ren­cy Commissioner
(Säch­si­sche Datenschutz- und Transparenzbeauftragte)

Mate­r­ni­stra­ße 17
01067 Dresden
Germany 

Phone: +49 351 85471-101
Email: post@sdtb.sachsen.de
Web­site: www.datenschutz.sachsen.de

The right to lodge a com­plaint exists wit­hout pre­ju­di­ce to any other admi­nis­tra­ti­ve or judi­cial remedy. 

24. Automated Decision-Making and Profiling

No decis­i­on based sole­ly on auto­ma­ted pro­ces­sing, inclu­ding pro­fil­ing, within the mea­ning of Art. 22 GDPR takes place in con­nec­tion with the pro­ces­sing acti­vi­ties descri­bed in this Pri­va­cy Policy. 

25. Amendments to this Privacy Policy

We reser­ve the right to amend this Pri­va­cy Poli­cy if our web­site, the ser­vices used or the appli­ca­ble legal or regu­la­to­ry requi­re­ments change. 

The ver­si­on curr­ent­ly published on this web­site shall apply.