Data Protection and Privacy Statement
Preamble
This text explains what types of personal data concerning you (also referred to herein as “data”) Dussmann processes for which purposes and in what scope. This Data Protection and Privacy Statement applies to the processing of personal data by Dussmann within the scope of implementation of voluntary internal company measures such as giveaways or prize drawings, surveys, awards and distinctions, photo and video competitions, summer and Christmas celebrations or similar events and activities that do not directly serve to establish, carry out, or terminate an employment relationship (collectively referred to as “employee activities”). Dussmann websites and external online sites such as the social media profiles of Dussmann and conference platforms such as Microsoft Teams (collectively referred to as “online services”) are used to carry out the employee activities.
It is important to note that Dussmann is not merely a single company. It is a group of companies consisting of Dussmann Stiftung & Co. KGaA and its affiliates. A list of these affiliates can be viewed here. Not every one of these companies carries out employee activities or processes your data. For ease of reference, the “Controller” section notes which company is responsible for processing your data. This means that where the text below refers to “us” or “we,” this means the responsible company of the Dussmann Group that is mentioned in the “Controller” section.
Please check back regularly to familiarize yourself with the content of our Data Protection and Privacy Statement. We adjust the text promptly as required by changes in the data processing we perform. We will let you know if and when these changes require any participatory action on your part (such as consent) or another form of individual notification is necessary.
Where we state the addresses and contact information of companies and organizations in this Data Protection and Privacy Statement, please note that these addresses may change over time and should be verified before you contact us.
Dussmann Stiftung & Co. KGaA
Friedrichstraße 90
10117 Berlin
Germany
e-mail address: hotline@dussmanngroup.com
Phone: +49 30 20 250
Dussmann Stiftung & Co. KGaA
Data Protection Officer
Friedrichstraße 90
10117 Berlin
Germany
+ 49 30 20250
The overview below summarizes the types of data we process and the purposes of processing thereof and indicates the data subjects.
Types of data processed
- Inventory data
- Employee data
- Payment data
- Contact information
- Content-related data
- Usage data
- Metadata, communication data, process data
- Images and/or video recordings
- Audio recordings
- Log data
Special categories of data
- Data concerning health
Categories of data subjects
- Employees
- Communication partners
- Users
- Persons depicted
Purposes of processing
- Implementation of employee activities
- Communication
- Security measures
- Feedback
- Provision of our online services and user friendliness
- Information technology infrastructure
Relevant legal bases pursuant to the GDPR: This section provides an overview of the legal bases under the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection and privacy specifications may apply in your or our country of residence or domicile. Should more-specific legal bases be relevant in the individual case, we will notify you of these in the Data Protection and Privacy Statement.
- Consent (point (a) of Article 6(1) GDPR) – The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
- Express consent (point (a) of Article 9(2) GDPR) – The data subject has given express consent to the processing of the specified personal data for one or more specific purposes.
- Legitimate interests (point (f) of Article 6(1) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations stipulated by the GDPR, there are national regulations governing data protection and privacy in Germany. This particularly includes the Act on Protection against the Misuse of Personal Data in Data Processing (German Federal Data Protection Act (BDSG)). In particular, the BDSG contains special provisions relating to the rights of access to information, of erasure, and to object; the processing of special categories of personal data; processing for other purposes; transfers; and automated decision-making in individual cases, including profiling. Furthermore, state data protection laws at the level of the individual states may also apply.
In accordance with the legal specifications and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include but are not limited to ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data and the data access concerning them, along with the entry, communication, and separation thereof and ensuring the availability of the data. We have also established procedures that ensure that the rights of data subjects are upheld, data are erased, and there is a response to any risk to the data. Furthermore, we take protecting personal data into account in the early stages of developing and/or selecting hardware, software, and procedures in keeping with the principle of data protection by design and by default.
Safeguarding online connections through TLS/SSL encryption technology (HTTPS): To protect the user data transferred via our online services against unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transferred between the website or app and the user’s browser (or between two servers), which protects the data against unauthorized access. TLS, a further developed and more-secure version of SSL, ensures that all data transmissions meet the very highest standards of security. If a website is safeguarded by an SSL/TLS certificate, “HTTPS” is displayed in the URL. This serves as an indicator for users that their data are being transferred securely and with encryption.
Within the scope of our processing of personal data, it is possible that these data will be transferred or disclosed to other bodies, companies, legally independent organizational units, persons, or entities. Recipients of these data may include, for example, service providers commissioned to perform IT tasks or providers of services and content incorporated into a website. In such cases, we observe the legal specifications and, in particular, enter into relevant contracts and/or agreements that serve to protect your data with the recipients of your data.
Data transfers within the corporate group: We may transfer personal data to other companies within our corporate group or grant them access to these data. Where such disclosures take place for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and business administration interests or takes place to the extent necessary to fulfill our contract-related obligations or where the data subject has given consent or the disclosure is permitted by law.
Data processing in third countries: Where we process data in a third country (i.e., outside the European Union (EU) or European Economic Area (EEA)) or the processing takes place within the scope of our utilization of third-party services or of the disclosure or transfer of data to other persons or entities, bodies, or companies, this takes place solely in compliance with the legal specifications. Where the level of data protection in the third country has been acknowledged by an adequacy decision (Article 45 GDPR), this decision serves as the basis for the data transfer. In all other respects, data transfers take place only if the level of data protection has been safeguarded through other means, particularly standard contractual clauses (point (c) of Article 46(2) GDPR), express consent has been granted, or the transfer is required based on the provisions of a contract or by law (Article 49(1) GDPR). In all other respects, we communicate to you the bases for the third-country transfer in the case of the individual third-country providers; the adequacy decisions take precedence as bases. For information on third-country transfers and existing adequacy decisions, please consult the information provided by the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
Transatlantic EU–U.S. data privacy framework: Within the scope of the Data Privacy Framework (DPF), the European Commission acknowledged the level of data protection provided by certain companies based in the United States as secure under the adequacy decision dated July 10, 2023. The list of certified companies and further information relating to the DPF is available from the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/.
We erase personal data that we process in accordance with the statutory provisions once the underlying consent has been withdrawn or there are no further legal bases for the processing thereof. This applies to cases in which the original purpose of processing ceases to apply or the data are no longer required. Exceptions to this provision apply if statutory obligations or particular interests require that the data be retained or archived for a longer period.
In particular, data that must be retained for reasons of commercial or tax law or whose storage is necessary in order to pursue legal claims or protect the rights of other natural persons or legal entities must be archived accordingly.
We process data that are no longer retained for the originally intended purpose, but rather based on legal specifications or other reasons, exclusively on the bases that justify the retention thereof.
Should you wish your data to be erased or withdraw consent to data processing, the data will be erased as soon as possible unless there is an obligation to store them.
Further information on processing operations, procedures, and services:
- Retention and erasure of data: The following general time limits apply to retention and archiving pursuant to German law:
- Ten years – retention period for accounts and records, annual financial statements, inventories, management or situation reports, the opening balance sheet as well as the operating instructions and other organizational documents needed for their comprehension (Sec. 147 (3) in conjunction with (1) No. 1 of the German Fiscal Code (AO), Sec. 257 (1) No. 1 and (4) of the German Commercial Code (HGB)).
- Eight years – accounting records and invoices (Sec. 147 (3) in conjunction with (1) No. 4 AO, Sec. 14b (1) of the German Value-Added Tax Act (UStG), Sec. 257 (1) No. 4 and (4) HGB).
- Six years – other business documents: trade or business letters received, reproductions of trade or business letters sent, other documents to the extent that these are of relevance for taxation, such as hourly wage slips, operating expense sheets, calculation documents, pricing materials, but also payroll documents, where these do not already constitute accounting records, and cash register tapes (Sec. 147 (3) in conjunction with (1) Nos. 2, 3, and 5 AO, Sec. 257 (1) Nos. 2 and 3 and (4) HGB).
- Three years – data that are required in order to take potential warranty claims and claims for damages or similar contractual claims and rights into account and to process inquiries associated therewith, based on past business experience and customary industry practices, are stored for the duration of the regular statutory limitation period of three years (Sec. 195 and 199 BGB).
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, particularly based on Articles 15 through 21 GDPR:
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (f) of Article 6(1) GDPR, including profiling based on those provisions.
- Right to withdraw consent: You have the right to withdraw your consent at any time.
- Right of access to information: You have the right to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to information about the personal data and to further information and copies of the data in accordance with the legal specifications.
- Right to rectification: In accordance with the legal specifications, you have the right to have the data concerning you completed if they are incomplete or rectified if they are inaccurate.
- Right of erasure and restriction of processing: In accordance with the legal specifications, you have the right to have the data concerning you erased without undue delay or, alternatively, to have the processing of these data restricted in accordance with the legal specifications.
- Right to data portability: You have the right to receive the data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format or to have those data transmitted to another controller in accordance with the legal specifications.
- Complaint to a supervisory authority: In accordance with the legal specifications and without prejudice to any other administrative or judicial remedy, you moreover have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence or the supervisory authority responsible for your place of work or the place of the alleged infringement, if you consider that the processing of the personal data relating to you infringes the GDPR.
As part of our personnel and corporate culture, we regularly conduct employee activities such as giveaways or prize drawings, surveys, awards and distinctions, photo and video competitions, summer and Christmas celebrations or similar events and activities that do not directly serve to establish, carry out, or terminate an employment relationship. To do this, we process employees’ personal data. This data processing facilitates the organization and implementation of the employee activities, communication before and after the employee activities, and documentation. In addition, the data serve the controller’s legitimate interests. Our legitimate interest lies in fostering a good climate within the organization, team building, and employee loyalty and retention.
During the employee activities, photos and videos may be taken and used for internal communication (e.g., on the intranet) or – if the employee has consented accordingly – for external presentation (e.g., social media). Before the activity, we notify employees of the nature and purpose of the images and obtain their consent.
Personal data may be shared with third parties to the extent that this is necessary in order to fulfill the aforementioned purposes. The data are erased when statutory retention time limits expire or the purpose of processing ceases to apply. This also includes data that must be stored for longer based on the evidentiary obligations of tax law and other laws.
Within the scope of the employee activities, we also conduct surveys for which we use the services of third parties. Please note that user data may be processed outside the European Union in this context. This may give rise to risks to employees, as it could make enforcing their rights as data subjects more difficult, for example. Please feel free to contact us at any time if you have any questions regarding this.
For a detailed discussion of the specific forms of processing, please see the data protection and privacy statements and information provided by the operators of the relevant services.
- Types of data processed: Inventory data (e.g., full name, home address, contact information, business unit, country of origin, title/position, employee ID number, etc.); payment information (e.g., bank account details); contact information (e.g., e-mail addresses or phone numbers); content data (e.g., messages and posts in text or image form and the information concerning them, such as information on authorship or the time of creation); metadata, communication data, and procedural data (e.g., IP addresses, timestamps, ID numbers, persons involved); log data (e.g., log files concerning logins or the retrieval of data or access times); images and/or video recordings (e.g., photographs or video recordings of a person); employee information (information on employees and other persons within an employment relationship); and information on diet and nutrition, allergies, and/or apparel size or staff ID data.
- Data subjects: Employees (e.g., permanent and temporary employees and others).
- Purposes of processing: Implementation of employee activities.
- Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure.”
- Legal bases: Consent (point (a) of Article 6(1) GDPR); legitimate interests (point (f) of Article 6(1) GDPR). Where health data are concerned (e.g., information on diet and nutrition or allergies), the processing takes place on the basis of point (a) of Article 9(2) GDPR (express consent).
Further information on processing operations, procedures, and services:
- Microsoft Forms: Creation of online forms for purposes including to conduct surveys; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://forms.office.com/; privacy statement: https://privacy.microsoft.com/en-us/privacystatement, security information: https://www.microsoft.com/en-us/trustcenter. Basis for third-country transfers: Data Privacy Framework (DPF).
We maintain our own websites, which employees can use and access. Within the scope of implementing employee activities, we process employee data to communicate with the employees active there and to publish information about employee activities internally within the group of companies.
- Types of data processed: Inventory data (e.g., full name, etc.); contact information (e.g., e-mail addresses or phone numbers); content data (e.g., messages and posts in text or image form and the information concerning them, such as information on authorship or the time of creation); usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); images and/or video recordings (e.g., photographs or video recordings of a person); audio recordings. Log data (e.g., log files concerning logins or the retrieval of data or access times).
- Data subjects: Employees.
- Purposes of processing: Implementation of employee activities, communication; feedback (e.g., collecting feedback via online form).
- Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure.”
- Legal bases: Legitimate interests (point (f) of Article 6(1) GDPR).
Further information on processing operations, procedures, and services:
- Intranet: Internal network within the group of companies that enables provision of documents, sharing of photos and videos, commenting and liking posts, sending messages, following profiles and pages; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://intranet.dussmanngroup.com/.
- MyDussmann: Internal network within the group of companies that enables provision of documents, sharing of photos and videos, commenting on posts, sending messages; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://my.dussmann.com/.
Within the scope of implementing employee activities, we use platforms and applications of other providers (“conference platforms”) for purposes of holding video and audio conferences, webinars, and other types of video and audio meetings (collectively “conferences”). We observe the legal specifications in selecting conference platforms and their services.
Data processed by conference platforms: In the context of participation in a conference, the conference platforms process the personal data of participants as mentioned below. The scope of the processing depends on factors including which data are specifically required in the context of a concrete conference (e.g., provision of login information or real names) and which optional information is provided by participants. In addition to processing to hold the conference, the participants’ data may also be processed by the conference platforms for security purposes or to optimize services. The data processed include personal information (first name, last name), contact information (e-mail address, phone number), login information (login codes or passwords), profile pictures, information about the person’s professional position/title or role, the IP address of the Internet access, information on participants’ devices, operating system, browser, and technical and language settings, information on content-related communication procedures, i.e., entries in chats and audio and video data, along with the use of other available features (such as surveys or polls). The content of the communications is encrypted to the extent provided in technical terms by the conference providers. If the participants are registered with the conference platforms as users, then additional data may be processed as agreed with the relevant conference provider.
Logging and recordings: If text entries, results of participation (e.g., in surveys or polls) and video or audio recordings are logged, this is communicated transparently to the participants in advance, and they are asked to consent where necessary.
Data protection measures of participants: With regard to the details of the processing of your data by the conference platforms, please note the latter’s data protection and privacy information and select the security and data protection and privacy settings that are optimal for you within the scope of the conference platform settings. Furthermore, please ensure data protection and privacy in the background of your images or recordings for the duration of a videoconference (e.g., by notifying others with whom you live, closing doors, and using any available technical features to blur your background). Links to conference rooms and login information must not be disclosed to unauthorized third parties.
Information on legal bases: Where we also process users’ data in addition to the conference platforms and request consent from users to the use of the conference platforms or certain features (e.g., consent to the recording of conferences), the legal basis of processing is this consent. Furthermore, our processing may be necessary in order to fulfill our contractual obligations (e.g., in participant lists, in the case of processing of the results of discussions or meetings, etc.). In all other respects, user data are processed on the basis of our legitimate interests in efficient and secure communication with the other parties to communications with us.
- Types of data processed: Inventory data (e.g., full name, etc.); contact information (e.g., e-mail addresses or phone numbers); content data (e.g., messages and posts in text or image form and the information concerning them, such as information on authorship or the time of creation); usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); images and/or video recordings (e.g., photographs or video recordings of a person); audio recordings. Log data (e.g., log files concerning logins or the retrieval of data or access times).
- Data subjects: Other parties to communication; users (e.g., website visitors, users of online services). Persons depicted. Employees.
- Purposes of processing: Implementation of employee activities; communication.
- Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure.”
- Legal bases: Legitimate interests (point (f) of Article 6(1) GDPR).
Further information on processing operations, procedures, and services:
- Microsoft Teams: Audio and videoconferences, chat, electronic file sharing, integration with Office 365 applications, real-time collaboration on documents, calendar features, task management, screen sharing, optional recording; service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://www.microsoft.com/en-us/microsoft-teams/; privacy statement: https://privacy.microsoft.com/en-us/privacystatement, security information: https://www.microsoft.com/en-us/trustcenter. Basis for third-country transfers: Data Privacy Framework (DPF).
We maintain an online presence within social networks and, in this context, process user data to communicate with the users active there, offer information about us, or visualize employee activities externally.
Please note that user data may be processed outside the European Union in this context. This may give rise to risks to users, as it could make enforcing user rights more difficult, for example.
Furthermore, user data are typically processed within social networks for market research and advertising purposes. In this way, for example, use profiles can be created based on a user’s usage behavior and the user interests it indicates. These profiles may in turn be used, for example, to serve ads that are likely to match users’ interests within and outside these networks. Therefore, cookies are typically stored on users’ computers, storing their usage behavior and interests. In addition, data may also be stored in the usage profiles independently of the devices used by the users (especially if users are members of the relevant platforms and are logged in there).
For a detailed discussion of the relevant forms of processing and the options for objecting (opting out), please see the data protection and privacy statements and policies and other information provided by the operators of the relevant networks.
Please note that requests for access to information and assertion of the rights of data subjects are also most effectively addressed to these providers. Only the latter have access to the user data in each case and can take relevant action and provide information directly. Should you still need help, feel free to contact us.
- Types of data processed: Contact information (e.g., mailing and e-mail addresses or phone numbers); content data (e.g., messages and posts in text or image form and the information concerning them, such as information on authorship or the time of creation). Usage data (e.g., page impressions and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Communication; feedback (e.g., collecting feedback via online form).
- Retention and erasure: Erasure in accordance with the information contained in the section titled “Information on data storage and erasure.”
- Legal bases: Legitimate interests (point (f) of Article 6(1) GDPR).
Further information on processing operations, procedures, and services:
- Instagram: Social network, enables sharing of photos and videos, commenting and liking posts, sending messages, following profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://www.instagram.com; privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
- Facebook pages: Profiles within the Facebook social network – We are jointly responsible as controllers with Meta Platforms Ireland Limited for the collection (but not the further processing) of data of visitors to our Facebook page (known as a fan page). These data include information on the types of content that users view or with which they interact or the actions taken by them (see “Things you and others do and provide” in the Facebook Data Policy: https://www.facebook.com/privacy/policy/), and information about the devices used by users (such as IP addresses, operating system, browser type, language settings, cookie data; see “Device Information” in the Facebook Data Policy: https://www.facebook.com/privacy/policy/). As explained in the Facebook Data Policy under “How do we use this information?,” Facebook also collects and uses information to provide analytical services known as “page insights” for page operators so the operators can gain insight into how people interact with their pages and the associated content. We have entered into a specific agreement with Facebook (“Information about Page Insights,” https://www.facebook.com/legal/terms/page_controller_addendum), which sets out provisions, in particular, on which security measures Facebook is obligated to observe and in which Facebook has declared its willingness to fulfill the rights of data subjects (meaning, for example, that users can address requests for access to information or erasure requests to Facebook directly). The rights of users (particularly the rights of access to information, the right to erasure, and the rights to object and lodge a complaint with the supervisory authority with jurisdiction) are not restricted by the agreements with Facebook. Further information is found in the "Information about Page Insights Data” (https://www.facebook.com/legal/terms/information_about_page_insights_data). The joint controller status is limited to the collection by and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which particularly concerns the transfer of the data to the parent company Meta Platforms, Inc., in the United States; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
- LinkedIn: Social network – We are jointly responsible as controllers with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data of visitors which are generated for purposes of creating the “Page Insights” (statistics) concerning our LinkedIn profiles.
These data include information on the types of content that users view or with which they interact or the actions taken by them and information about the devices used by users (such as IP addresses, operating system, browser type, language settings, cookie data) and information from users’ profiles, such as professional role or title, country, industry, level of the hierarchy, company size, and employment status. For data protection and privacy information concerning the processing of user data by LinkedIn, please see the LinkedIn privacy policy: https://www.linkedin.com/legal/privacy-policy.
We have entered into a specific agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum,” (the “Addendum”)), https://legal.linkedin.com/pages-joint-controller-addendum), which sets out provisions, in particular, on which security measures LinkedIn is obligated to observe and in which LinkedIn has declared its willingness to fulfill the rights of data subjects (meaning, for example, that users can address requests for access to information or erasure requests to LinkedIn directly). The rights of users (particularly the rights of access to information, the right to erasure, and the rights to object and lodge a complaint with the supervisory authority with jurisdiction) are not restricted by the agreements with LinkedIn. The joint controller status is limited to the collection by and transfer of data to Ireland Unlimited Company, a company based in the EU. The further processing of the data is the sole responsibility of Ireland Unlimited Company, which particularly concerns the transfer of the data to the parent company LinkedIn Corporation in the United States; service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://www.linkedin.com; privacy policy: https://www.linkedin.com/legal/privacy-policy; basis for third-country transfers: Data Privacy Framework (DPF). Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - X: Social network; service provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; legal bases: legitimate interests (point (f) of Article 6(1) GDPR); website: https://x.com. Privacy policy: https://x.com/de/privacy.