Privacy Policy
1. Introduction
This website is operated by: ABC-TEAM Spielplatzgeräte GmbH.
It is very important to us to handle the data of our website visitors with the utmost care and to protect it as best as possible. For this reason, we make every effort to comply with the requirements of the GDPR.
Below, we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you truly understand what happens to your data.
2. General Information
2.1 Processing of Personal Data and Other Terms
Data protection applies to the processing of personal data. “Personal data” refers to any data that can be used to identify you personally. This includes, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently using. Such data is processed whenever “something happens to it.” For example, the IP address is transmitted from your browser to our provider and automatically stored there. This constitutes processing (pursuant to Art. 4(2) of the GDPR) of personal data (pursuant to Art. 4(1) of the GDPR).
These and other legal definitions can be found in Article 4 of the GDPR.
2.2 Applicable Regulations/Laws – GDPR, BDSG, and TDDDG
The scope of data protection is governed by laws. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.
In addition, the TDDDG supplements the provisions of the GDPR with regard to the use of cookies.
2.3 The Data Controller
The controller, as defined by the GDPR, is responsible for data processing on this website. This is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
You can contact the person in charge at:
ABC-TEAM Spielplatzgeräte GmbH
Eisensteinstraße 6
56235 Ransbach-Baumbach
Germany
info@abc-team.de
2.4 Data Protection Officer
We have appointed a data protection officer for our company. You can contact him or her at:
Mr. Bastian Hoffmann, Xpertus IT Systemhaus GmbH
Bahnhofstr. 14
56424 Mogendorf
datenschutz@abc-team.de
2.5 How Data Is Generally Processed on This Website
As we have already noted, certain data (e.g., IP address) is collected automatically. This data is primarily required for the technical operation of the website. To the extent that we use personal data or collect other data beyond this, we will inform you accordingly or ask for your consent.
You knowingly provide us with other personal data.
You can find detailed information on this below.
2.6 Your Rights
The GDPR grants you comprehensive rights. These include, for example, the right to receive, free of charge, information about the source, recipients, and purpose of your stored personal data. You may also request that this data be corrected, restricted, or deleted, or file a complaint with the relevant data protection supervisory authority. You may withdraw any consent you have given at any time.
For details on these rights and how to exercise them, please see the last section of this Privacy Policy.
2.7 Data Protection – Our Perspective
For us, data protection is more than just a burdensome obligation! Personal data is highly valuable, and handling it with care should be a matter of course in our digital world. Furthermore, as a website visitor, you should be able to decide for yourself what happens to your data, when, and by whom. That is why we are committed to complying with all legal requirements, collecting only the data we need, and, of course, treating it confidentially.
2.8 Disclosure and Deletion
The sharing and deletion of data are also important and sensitive issues. That is why we would like to briefly inform you in advance about our general approach to these matters.
Data will only be disclosed if there is a legal basis for doing so and only when it is unavoidable. This may be the case, in particular, when the recipient is a so-called data processor and a data processing agreement has been concluded in accordance with Article 28 of the GDPR.
We will delete your data once the purpose and legal basis for processing no longer apply and there are no other legal obligations preventing the deletion. Article 17 of the GDPR also provides a “good” overview of this.
Please refer to this Privacy Policy for further information, and contact the data controller if you have any specific questions.
2.9 Hosting
Raidboxes
We use the Raidboxes service to host our website. Raidboxes is a managed WordPress hosting provider operated by Raidboxes GmbH, Hafenstraße 32, 48153 Münster, Germany. The service provides web hosting services, particularly for WordPress websites, and thus handles the storage and delivery of website content, including performance optimization and technical administration. When using Raidboxes, personal data such as IP address, date and time of access, pages visited, and browser and device information are typically processed. This data is processed for the purpose of ensuring the secure and stable operation of the website, for the technical optimization of the hosting environment, and for error detection and correction. The legal basis for the processing is Article 6(1)(f) of the GDPR, based on the legitimate interest in the secure and efficient provision of the website by a professional hosting service. To the extent that Raidboxes uses cookies, this is done exclusively to ensure technical functionality and not for analytical or marketing purposes; necessary cookies are set on the basis of Article 6(1)(f) of the GDPR and Section 25(2)(2) of the TDDDG. Raidboxes does not transfer personal data to third countries, as all data processing takes place on servers located within Germany or the EU. The stored data is deleted as soon as it is no longer necessary to achieve the purpose for which it was collected—for example, upon deletion or migration of the website—or after the expiration of statutory retention periods. Further information on data processing by Raidboxes is available at https://raidboxes.io/en/legal/privacy/ .
2.10 Legal Basis
The processing of personal data always requires a legal basis. Article 6(1), first sentence, of the GDPR provides for the following options:
- The data subject has given consent to the processing of personal data concerning him or her for
one or more specific purposes; - The processing is necessary for the performance of a contract to which the data subject is a party, or for the
implementation of precontractual measures taken at the data subject’s request; - The processing is necessary to fulfill a legal obligation to which the controller is subject;
- The processing is necessary to protect the vital interests of the data subject or another
natural person; - The processing is necessary for the performance of a task carried out in the public interest or in
the exercise of official authority vested in the controller; - The processing is necessary to safeguard the legitimate interests of the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject that
require the protection of personal data take precedence, particularly if the data subject is
a child.
In the following sections, we will specify the specific legal basis for each type of processing.
3. What Happens on Our Website
When you visit our website, we process your personal data.
To provide the best possible protection for this data against unauthorized access by third parties, we use SSL or TLS encryption. You can recognize this encrypted connection by the "https://" in your browser's address bar or by the padlock icon.
Below, you will learn what data is collected when you visit our website, for what purpose this is done, and on what legal basis.
3.1 Data Collection When Visiting the Website
When you visit the website, information is automatically stored in what are known as server log files. This information includes the following:
- Browser Type and Browser Version
- Operating system used
- Referrer URL
- Hostname of the connecting computer
- Time of the server request
- IP address
This data is required on a temporary basis so that we can ensure you can view our website consistently and without any issues. Specifically, this data is used for the following purposes:
- Website System Security
- Website System Stability
- Troubleshooting on the Website
- Establishing a Connection to the Website
- Website Layout
Data processing is carried out in accordance with Article 6(1)(f) of the GDPR and is based on our legitimate interest in processing this data, in particular our interest in the functionality and security of the website.
This data is stored in pseudonymized form whenever possible and deleted once the respective purpose has been fulfilled.
To the extent that the server log files allow for the identification of the data subject, the data will be stored for a maximum period of 14 days. An exception applies if a security-related incident occurs. In this case, the server log files will be stored until the security-related incident has been resolved and fully investigated.
Furthermore, this data is not combined with any other data.
3.2 Cookies
3.2.1 General Information
This website uses cookies. These are data records—pieces of information—that are stored in your device’s browser and are related to our website.
The use of cookies can, in particular, make it easier for visitors to navigate the website.
In our cookie consent tool, you'll find all the information about the cookies we use on our website (with your consent, where applicable).
3.2.2 Technically Necessary Cookies
We use technically necessary cookies on this website to ensure that it functions properly and in accordance with applicable laws. They help make the website user-friendly. Some features of our website cannot be displayed without the use of cookies.
Depending on the specific case, the legal basis for this is Article 6(1)(b), (c), and/or (f) of the GDPR.
3.3 Data Processing Through User Input
3.3.1 First-Party Data Collection
We offer the following services on our website: contact form, product inquiry form, job application form, and wish list form.
To this end, we collect the following data:
- Name
- Email address
- Address
- Phone number
The legal basis for this data processing is Article 6(1)(b) of the GDPR.
The data will be deleted as soon as the relevant purpose no longer applies and it is permissible to do so under applicable law.
3.3.2 Making Contact
a) Email
If you contact us via email, we will process your email address and, if applicable, any other data contained in the email. This data is stored on the mail server and, in some cases, on the respective end devices. Depending on the nature of your inquiry, the legal basis for this is typically Article 6(1)(f) of the GDPR or Article 6(1)(b) of the GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible to do so in accordance with legal requirements.
b) Phone
If you contact us by phone, the call data may be stored in pseudonymized form on the respective device and by the telecommunications provider used. Personal data collected during the phone call is processed exclusively for the purpose of handling your inquiry. Depending on the nature of your inquiry, the legal basis for this is typically Article 6(1)(f) of the GDPR or Article 6(1)(b) of the GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible to do so in accordance with legal requirements.
Contact Form
Bricksbuilder.io Contact Form
Our website uses the contact form feature provided by Bricksbuilder.io. Bricksbuilder.io is a service offered by Codeer Limited, Gladstonos 8046 Paphos, Cyprus. The contact form enables the collection and management of contact and inquiry forms submitted by users, including the transmission of entries directly via email or to third-party services, as well as the storage of data as part of automated workflows. When using the contact form, the following personal data is typically processed: Name, email address, phone number, custom text entries, file uploads, values from date selection fields, IP address, referrer (URL of the referring page), browser information, operating system, time of submission, user ID (if applicable, for logged-in users), and other (custom) fields requested in the forms. This data is processed to handle incoming inquiries, assign them to the appropriate parties, send notifications, and, where applicable, integrate with CRM or marketing tools, as well as to automate workflows and fulfill pre-contractual and contractual obligations. The legal basis for processing is Article 6(1)(b) of the GDPR, insofar as the communication is aimed at initiating or fulfilling a contract; otherwise, Article 6(1)(f) of the GDPR, as there is a legitimate interest in efficient and secure communication as well as in preventing spam. Bricksbuilder.io itself does not set any cookies as part of the form function; if integrations or third-party services (e.g., Mailchimp, Sendgrid) are used via the form, cookies may be set when these services are used; this occurs exclusively with consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Personal data is transferred to third countries only if services outside the EU are accessed via integrated features; in this case, the transfer is based on the European Commission’s Standard Contractual Clauses as an appropriate safeguard. Otherwise, no transfer to third countries takes place. The data collected via the form will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected, consent has been revoked, or statutory retention obligations have expired. The service’s current privacy policy can be viewed at https://bricksbuilder.io.
Resend
On this website, we use Resend to process and transmit contact form messages. Resend is an email API service provided by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, which is operated under the domain resend.com. Resend is a developer-oriented email delivery platform that enables website operators to reliably send transactional emails via a REST API or SMTP integration. In the context of this website’s contact form, Resend handles the technical delivery of incoming contact requests to the website operator’s registered email address. In addition, Resend provides detailed delivery logs and event data (e.g., delivery, bounce). When using Resend to process contact form submissions, the following personal data is processed: name, email address, and all other data entered in the contact form (e.g., message content, phone number), the IP address of the person making the inquiry, the timestamp of the transmission, and technical metadata related to the email delivery (e.g., delivery status, bounce information). The purpose of data processing is the technically reliable delivery of contact requests to the website operator and ensuring the traceability of email delivery through delivery logs. The legal basis for data processing is Art. 6(1)(b) GDPR, insofar as contact is established in the context of pre-contractual or contractual measures, as well as Art. 6(1)(f) of the GDPR (legitimate interest of the website operator in the reliable technical delivery of contact requests). Data processing takes place within the framework of a data processing agreement (Data Processing Addendum, DPA) in accordance with Article 28 of the GDPR. Resend does not set any cookies on the end devices of website visitors in the context of pure contact form processing. Data is transferred to a third country. According to its own statements, Resend stores and processes customer data in the United States. For data transfers to the United States, the Standard Contractual Clauses (SCCs) of the European Commission pursuant to Article 46(2)(c) of the GDPR serve as an appropriate safeguard and are incorporated into Resend’s Data Processing Addendum (DPA). The data processed in connection with the contact form submission is deleted after the inquiry has been handled, provided that no statutory retention requirements prevent this. According to Resend, transmission logs are retained for a period of seven days and then automatically deleted. Further information on data processing is available at: https://resend.com/legal/privacy-policy
3.4 Cookie Consent Tool
Cookie Script
Our website uses the Cookie Script cookie consent tool, which is provided by Objectis, UAB, Laisvės St. 60, LT-05120 Vilnius, Lithuania. Cookie Script integrates a consent banner that allows website visitors to select and manage cookies. The service scans the website for cookies and scripts in use, categorizes them, automatically blocks non-essential cookies until consent is given, and logs all consent decisions to fulfill legal documentation requirements. In particular, the service processes visitors’ consent preferences (i.e., selected cookie settings), domain information, automatically collected lists of cookies found, and time-stamped consent logs including selected options. The purpose of data processing is to obtain, manage, and document data protection-related consents for cookie use in accordance with legal requirements, as well as to technically implement consent preferences. The legal basis for the processing is Article 6(1)(c) of the GDPR to fulfill legal obligations and, insofar as the setting of non-technically necessary cookies is concerned, Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG (consent). The storage and processing of technically necessary consent cookies are based on Article 6(1)(f) of the GDPR (legitimate interest in demonstrating and implementing data protection-compliant cookie management). Cookie Script uses a technically necessary cookie to store the consent preferences selected by visitors and to release additional cookies only after they have been explicitly selected. Furthermore, the service itself does not use any analytics or marketing cookies. No personal data is transferred to third countries when using Cookie Script; all processing takes place within the European Union. The stored consent data is deleted as soon as it is no longer required for documenting the consent process or once statutory retention periods have expired; in the event of a revocation, the corresponding logs are removed immediately, provided there is no legal obligation to retain them. Further information on data protection at Cookie Script is available at https://cookie-script.com/privacy-policy-generator .
3.5 Analytics and Tracking Tools
Fathom Analytics
This website uses the analytics and tracking service Fathom Analytics, provided by Conva Ventures Inc., 26 Bastion Square, Third Floor Burnes House, Victoria, British Columbia, V8W 1H9, Canada. Fathom Analytics enables privacy-friendly analysis of website visits by evaluating aggregated metrics such as page views, referrers, traffic sources (including UTM parameters), device types and browsers used, geographic origin (at the country level), conversion events, and real-time visitor counts—all without allowing any identification of individual persons. In particular, the following information is processed: the page visited, the referrer, the browser type and version, device type, country (based on a truncated IP address), UTM campaign parameters, and aggregated usage statistics; No personal identification or profiling takes place. The purpose of data processing is the statistical analysis and optimization of the website, as well as the measurement of the effectiveness of marketing measures in a privacy-friendly manner. The legal basis for the use of Fathom Analytics is Article 6(1)(f) of the GDPR; the legitimate interest lies in the needs-based design and statistical analysis of the website, whereby the rights and freedoms of visitors are safeguarded through the policy of not using cookies or identifying characteristics. Fathom Analytics does not set cookies and does not use comparable technologies for local storage on end devices. No personal data is transferred to third countries, as Fathom Analytics, according to its own statements, works exclusively with anonymized or aggregated data that does not contain any personal references; the identification of individual visitors is impossible. The stored data is deleted as soon as it is no longer required for analysis or the purpose for which it was collected no longer applies; this does not affect statutory retention obligations or a request for deletion by data subjects, which can be enforced at any time. Further information on Fathom Analytics and data processing can be found at: https://usefathom.com/legal/privacy
3.6 Third-Party Content
Cloudflare CDN
Our website uses the Content Delivery Network (CDN) provided by Cloudflare, a service offered by Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA. Cloudflare CDN is used for the global delivery of website content, performance optimization (reducing latency, increasing load speed), and enhancing security through protection against DDoS attacks, bot defense, and other security features. In this process, requests are routed through Cloudflare’s servers, and content is delivered from a network of globally distributed data centers. In doing so, Cloudflare processes the IP addresses of website visitors, header data, timestamps, request and response logs, technical usage data (e.g., browser information), and—as part of temporary caching—copied website content, which may contain personal data under certain circumstances. Furthermore, cookies such as “__cf_bm” or “cf_clearance” are set for certain security functions; these are necessary for identifying and defending against bots, as well as for preventing misuse. The purpose of this processing is the technical delivery of the website, the improvement of loading times worldwide, protection against attacks and misuse, and the overall reliability of the service. The legal basis is Article 6(1)(f) of the GDPR (legitimate interest in the secure and high-performance provision of the online service). To the extent that consent is required for certain security-related cookies, their use is based solely on Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. The cookies used primarily serve functional and security-related purposes; analysis or marketing purposes are not the primary focus. Since Cloudflare Inc. is based in the United States, personal data is transferred to a third country. To protect personal data, the EU Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR are applied. As a general rule, Cloudflare stores the data only for as long as is necessary for the purposes of transmission and security; IP addresses and technical logs are typically deleted or anonymized shortly thereafter, unless longer retention periods are required by law or serve to prevent misuse and attacks. The data will be deleted in the event of a valid objection or if the purpose no longer applies. Further information can be found in Cloudflare’s Privacy Policy: https://www.cloudflare.com/privacypolicy/
CloudConvert
Our website uses CloudConvert to provide automated file conversion and processing features. CloudConvert is a service provided by Lunaweb GmbH, Nördliche Münchner Straße 47, 82031 Grünwald, Germany. The service enables server-side conversion, compression, and optimization of a wide variety of file formats (e.g., documents, images, audio files, videos), as well as the creation of website screenshots and PDF conversions. When using CloudConvert, IP addresses, HTTP referrers, browser versions, access times, and, where applicable, information such as email addresses, names, addresses, company names, and VAT ID numbers are regularly processed—particularly when using accounts, contact forms, or during payment processing; when logging in via social networks, pseudonyms and profile photos may also be processed. This processing is carried out for the purposes of technical provision, error-free operation, and optimization of file conversions, as well as for user management and, where applicable, billing. The legal bases are Article 6(1)(f) of the GDPR (legitimate interest in a functional and efficient website as well as in IT security); for contractual services and billing, Article 6(1)(b) of the GDPR; and, with user consent, Article 6(1)(a) of the GDPR. CloudConvert uses cookies for certain functions, in particular functional cookies for session management and, if enabled, optional cookies for audience measurement or analysis. The legal basis for the use of non-essential cookies is consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. No personal data is transferred to third countries, as all data processing is carried out within the EU. Personal data is deleted as soon as the purpose of the processing no longer applies or consent is revoked, provided that there are no statutory retention obligations or longer retention periods are necessary for contractual reasons. Further information can be found at: https://cloudconvert.com/privacy
Bricks Builder
We integrate Bricks Builder into our website, a WordPress tool for creating and designing websites offered by Codeer Limited, Gladstonos, 8046 Paphos, Cyprus. Bricks Builder is a specialized tool within the WordPress ecosystem that focuses on visual design and high performance. In particular, the following data is processed: IP addresses, browser type, device information, license data, and other technical information necessary for providing the service. The purpose of this processing is to ensure a user-friendly design and to optimize our website. The legal basis is Article 6(1)(f) of the GDPR, based on our legitimate interest in a technically sound and user-oriented website design. If consent is required, we rely on Article 6(1)(a) of the GDPR. Bricks Builder itself does not set any cookies. Since Bricks Builder is operated by a U.S. provider, data may be transferred to a third country; the Standard Contractual Clauses (SCCs) of the European Commission are used as safeguards for this purpose. The data will be deleted as soon as it is no longer necessary to achieve the purpose and there are no statutory retention periods that prevent this. Further information on data processing by Bricks Builder can be found at https://bricksbuilder.io/privacy-policy.
Advanced Custom Fields PRO
To manage custom content fields on our website, we use Advanced Custom Fields PRO, a plugin from WP Engine, Inc., 504 Lavaca St, Ste 1000, Austin, TX 78701, United States. The plugin enables the flexible creation and organization of custom field groups, reusable content, galleries, and custom layouts in the WordPress backend to optimize content management and editorial workflows. When using Advanced Custom Fields PRO, content and media entered by website users or administrators—including text, images, and custom structural data—are stored directly in the local WordPress database. In addition, when a PRO license is activated or updated, technical metadata such as page name, URL, WordPress and plugin versions, language, and time zone may be transmitted to WP Engine. The purpose of this processing is to provide and optimize custom content structures for website operation, as well as to manage license information. The legal basis for storing and processing the entered content is Article 6(1)(f) of the GDPR, based on our legitimate interest in the efficient administration of individual website content; for any transmissions made as part of the license verification process, consent is provided pursuant to Article 6(1)(a) of the GDPR. The plugin itself does not set any cookies and does not process any personal data or usage information from website visitors for analysis, marketing, or tracking purposes. During license updates, the aforementioned metadata may be transferred to the United States (to WP Engine, Inc.); the EU Standard Contractual Clauses are used as an appropriate safeguard in this context. The stored content data generally remains in the WordPress database until it is deleted by the administration, the respective purpose of use ceases to exist, or statutory retention periods expire; in the case of an activated PRO license, transmitted license data is deleted upon termination of the license relationship or revocation of consent, provided that no legal obligations preclude this. Further information can be found at: https://wpengine.com/legal/
Google Maps
Our website uses the Google Maps mapping service, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Maps provides interactive maps, displays locations and directions, and enables the integration of Street View and other mapping features. When using this service, personal data such as IP address, device and browser information, location data (if authorized by the device), and interaction data (e.g., search terms, zoom level, locations clicked on) are processed. This data is processed for the purposes of geographic display, navigation, displaying business locations, and improving the user-friendliness of our website. The legal basis is generally Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG, provided that consent is obtained via the cookie banner. If consent is not provided, Google Maps will not be activated. If cookies are used, they are functional and, where applicable, analytical cookies that are set only with express consent. Personal data may be transferred to a third country, in particular to the United States. For such transfers, Google uses the Standard Contractual Clauses approved by the European Commission as appropriate safeguards. Personal data will be deleted as soon as the purpose of the processing no longer applies or consent is revoked, provided that no statutory retention obligations preclude this. Further information on data protection can be found at: https://policies.google.com/privacy
Cloudflare DNS
This website uses Cloudflare DNS, a service for Domain Name System (DNS) management and website performance optimization, operated by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare DNS enables the management of DNS records and routes traffic through Cloudflare’s global anycast network to provide protection against DDoS attacks, routing optimization, and additional security (e.g., DNSSEC). During use, data such as the source IP address, the requested domain names, the type and code of the DNS query, the responsible data center, the destination IP address, the protocol, and the IP version are typically processed. The purpose of data processing is to reliably and securely provide DNS services, defend against attacks, and optimize access times to the web content provided. The legal basis is Article 6(1)(f) of the GDPR, as there is a legitimate interest in the secure, high-performance, and uninterrupted provision of web services. As of the present time, Cloudflare DNS does not set cookies on end devices as part of its DNS services. Personal data, in particular the IP address, is transferred to third countries, specifically the United States. This is based on the European Commission’s Standard Contractual Clauses to ensure an adequate level of data protection. The data is deleted as soon as it is no longer necessary for the stated purposes or valid consent is revoked, provided there are no statutory retention obligations; In the case of 1.1.1.1 queries, data is stored for a maximum of 24 hours; for general DNS services, an approach that is at least as restrictive applies. Further information can be found at: https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile
Our website integrates the anti-bot solution Cloudflare Turnstile, a service designed to prevent spam and abuse and to secure forms. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare Turnstile analyzes interactions by website visitors to detect automated access attempts and allow legitimate access. Turnstile is primarily used to protect forms—such as those for logins, registrations, and contact requests—without relying on traditional CAPTCHAs. The data processed includes, among other things, the IP address, the user agent, browser- and device-specific identification signals, TLS fingerprints, the site key used, and the origin of the request. Data processing is carried out for the purpose of preventing misuse, protecting against spam, and ensuring the functionality and security of the website. The legal basis for this use is Article 6(1)(f) of the GDPR, based on the legitimate interest in the technical security of the website, as well as Section 25(2)(2) of the TDDDG, provided that information necessary for secure operation is processed on the end device. Cloudflare Turnstile does not use any tracking or marketing cookies itself; only technically necessary cookies are used, the use of which is necessary for the protection of the website. The legal basis for this is Article 6(1)(f) of the GDPR in conjunction with Section 25(2) of the TDDDG. Personal data may be transferred to third countries, in particular to the United States. For this transfer, the EU Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR are used as appropriate safeguards. Personal data is stored for as long as it is necessary for the stated purposes or as long as statutory retention periods apply. Upon revocation or cessation of the purpose of processing, the data will be deleted, provided that no other legal obligations preclude this. Further information can be found in Cloudflare’s Privacy Policy at https://www.cloudflare.com/privacypolicy/ and in the Turnstile-specific privacy notice at https://www.cloudflare.com/de-de/cloudflare-customer-dpa/addendum-turnstile/ .
4. Other Important Information
In closing, we would like to provide you with comprehensive and detailed information about your rights and let you know how you will be notified of changes to data protection requirements.
4.1 Your Rights in Detail
4.1.1 Right of Access under Article 15 of the GDPR
You may request information regarding whether your personal data is being processed. If so, you may request further information regarding the nature and manner of the processing. A detailed list can be found in Article 15(1)(a) through (h) of the GDPR.
4.1.2 Right to Rectification under Article 16 of the GDPR
This right includes the correction of inaccurate data and the completion of incomplete personal data.
4.1.3 Right to erasure under Article 17 of the GDPR
This so-called “right to be forgotten” gives you the right, under certain conditions, to request that the data controller erase your personal data. This generally applies when the purpose of the data processing no longer applies, when consent has been withdrawn, or when the initial processing took place without a legal basis. A detailed list of grounds can be found in Article 17(1)(a) through (f) of the GDPR. This “right to be forgotten” also corresponds to the data controller’s obligation under Article 17(2) of the GDPR to take appropriate measures to ensure the general erasure of the data.
4.1.4 Right to Restriction of Processing under Article 18 of the GDPR
This right is subject to the conditions set forth in Article 18(1)(a) through (d).
4.1.5 Right to Data Portability under Article 20 of the GDPR
This section governs the fundamental right to receive one’s own data in a commonly used format and to have it transferred to another controller. However, this applies only to data processed on the basis of consent or a contract pursuant to Article 20(1)(a) and (b), and to the extent that this is technically feasible.
4.1.6 Right to Object under Article 21 of the GDPR
You generally have the right to object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the controller’s legitimate interest in the processing and if the processing relates to direct marketing and/or profiling.
4.1.7 Right to “case-by-case decision” under Article 22 of the GDPR
You generally have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. However, this right is also subject to restrictions and additional provisions set forth in Article 22(2) and (4) of the GDPR.
4.1.8 Other Rights
The GDPR provides for comprehensive rights regarding the notification of third parties as to whether or how you have exercised your rights under Articles 16, 17, and 18 of the GDPR. However, this applies only to the extent that it is possible or feasible with reasonable effort.
We would like to take this opportunity to remind you once again of your right to withdraw your consent pursuant to Article 7(3) of the GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.
In addition, we would also like to inform you of your rights under Sections 32 et seq. of the BDSG; however, these rights are largely identical in substance to those just described.
4.1.9 Right to File a Complaint Under Article 77 of the GDPR
You also have the right to file a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates this Regulation.
5. What if the GDPR is repealed tomorrow or other changes take place?
The current version of this Privacy Policy is dated June 12, 2026. From time to time, it may be necessary to update the content of the Privacy Policy to reflect factual and legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the updated version in the same location and recommend that you review the Privacy Policy regularly.


Our Services
Do you need help choosing products or planning a playground?
Find your personal sales representative for your region. They are available to assist you by phone or in person - free of charge and with no obligation. Alternatively, you can also contact our office staff.