Skip to content

Privacy & security

Privacy policy for the website www.adebar.de and for the processing of personal data by adebar GmbH.

Last updated: 2 October 2026

This is a courtesy translation. Only the German version is legally binding.

We take the responsible handling of personal data very seriously. Below we explain clearly which data is processed when you visit our website and when we work together.

The key points in brief: Without your consent, our website sets no cookies and loads no third-party services. Only if you agree in the consent banner do we use Google Analytics to measure reach and the Microsoft Teams chat. You can change or withdraw your choice at any time via "Cookie settings" in the page footer. Only when you use an enquiry form or the newsletter sign-up is a security check (Cloudflare Turnstile) loaded to prevent abuse (sections 7, 12.2 and 14).

1. Controller

adebar GmbH Jagdhaus 7b 18375 Wieck a. Darß Phone: +49 38233 62518 Email: infoadebar.de represented by the Managing Director Anne Horstmann

For data protection enquiries, please contact: datenschutzadebar.de

Data protection officer: B. Golbs, who can be reached at datenschutzadebar.de

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.

2. General information on data processing

We process personal data exclusively within the framework of the statutory provisions of the Datenschutz-Grundverordnung (DSGVO, EU General Data Protection Regulation, hereinafter GDPR), the Bundesdatenschutzgesetz (BDSG, German Federal Data Protection Act) and, for access to your device, the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG, German Telecommunications and Digital Services Data Protection Act).

When you use our website, data is generally collected directly from you, so Art. 13 GDPR applies with regard to the information obligations. The information is provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language, as required by Art. 12 GDPR.

This privacy policy is divided into two parts. Part A describes data processing on this website. Part B describes the processing of personal data by adebar GmbH outside the website, for example for projects, events, newsletters and online meetings.

Part A: Data processing on this website

3. Hosting and provision of the website

This website is hosted by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp, Germany. The servers are located in a data centre in Germany. When you visit the website, the data listed in section 4 is processed on these servers.

We have concluded a data processing agreement with Mittwald in accordance with Art. 28 GDPR. Hosting does not involve any transfer to third countries.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in providing our website securely, quickly and reliably.

4. Server log files

Each time our website is accessed, our hosting provider automatically collects information and stores it in what are known as server log files. This includes:

  • IP address of the accessing device
  • date and time of access
  • URL accessed / page requested
  • HTTP status code / access status
  • amount of data transferred in each case
  • website from which the request comes (referrer URL)
  • browser type and browser version used
  • operating system

The temporary processing of this data is technically necessary to deliver the website to you, to ensure security (for example to fend off attacks) and to analyse errors. We do not store the content of enquiries you send via the enquiry assistant in log files.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the purposes stated.

Server log files are stored for a maximum of 30 days and then deleted or anonymised. Log files that need to be kept longer for evidential purposes are excluded from deletion until the incident in question has been finally resolved.

5.1 Consent management (consent banner)

On your first visit, a banner asks whether you agree to the use of statistics services (Google Analytics) and external media (Microsoft Teams chat). You can accept all services, allow only the technically necessary functions or make an individual selection. Without your consent, these services are not loaded.

We store your decision (selected categories, time and banner version) exclusively in your browser's local storage (localStorage, entry "adebar:consent"). This means the banner does not reappear on every page view and we can prove your choice. The banner is our own development and no data is transferred to third parties. The legal basis is § 25 (2) no. 2 TDDDG and Art. 6 (1) (c) GDPR in conjunction with Art. 7 (1) GDPR (proof of consent). The entry remains stored until you change your selection or delete the website data in your browser.

Withdrawal: You can withdraw or change your consent at any time with effect for the future via the "Cookie settings" link in the page footer. If you withdraw consent for statistics, we delete the Google Analytics cookies in your browser.

5.2 Google Analytics 4

With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics allows us to evaluate how our website is used (for example pages viewed, time spent, approximate location at country or region level, device and browser used, and where visits come from) and to derive improvements from this. We also measure certain interactions, such as sending an enquiry via the enquiry assistant, saving ideas, and clicks on the phone number, the email address or the link to SAMVARO. The content of your enquiry (for example name or email address) is not transmitted to Google.

Google Analytics sets cookies (_ga, _ga_<ID>, stored for up to 2 years) to recognise your browser. According to Google, IP addresses are not logged or stored in Google Analytics 4. We use Google Consent Mode so that only analytics storage is permitted. Advertising and personalisation features are disabled. The event data stored in Google Analytics is automatically deleted after 2 months (Google Analytics default setting).

The legal basis is your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. A data processing agreement is in place with Google. A transfer of data to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR). Further information: policies.google.com/privacy (opens in a new tab) and support.google.com/analytics/answer/12017362 (opens in a new tab).

5.3 Microsoft Teams chat

For a live chat with our team, we use a chat service based on Microsoft Teams provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The chat is only loaded if you have consented to the "External media" category or actively start the chat using the "Chat" button. Technical data (including IP address and browser information) and the content of your chat messages are processed. Processing takes place in the Europe region.

The legal basis is your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. For responding to your concerns, the legal basis is Art. 6 (1) (b) or (f) GDPR. Information on transfers to third countries can be found in section 19 and at privacy.microsoft.com (opens in a new tab).

5.4 Fonts, video and public events

Fonts: The fonts used are delivered from our own server. No connection to servers of Google or other font providers is established when you access the website.

Video: Videos on our website are delivered from our own server. No video platforms (such as YouTube or Vimeo) are embedded.

Public events from SAMVARO: Where we display public events from our platform SAMVARO on our website, our server retrieves this general event information itself. No data about you is transmitted to SAMVARO.

6. Saved list ("Your event draft")

You can add ideas on our website to a saved list. The saved list is stored exclusively in your browser's local storage (localStorage) on your device. Only references to the saved content are stored (the ID, title and address of the page in question). The saved list is not transmitted to us or to third parties unless you add the saved ideas to an enquiry yourself (see section 7).

Storage on your device is based on § 25 (2) no. 2 TDDDG, as it is strictly necessary to provide the saved list you have expressly requested. Consent is not required for this.

The entries remain stored until you remove them from the saved list or delete the website data in your browser.

7. Enquiry assistant and quick enquiry

You can use our enquiry assistant to send us a non-binding enquiry for an event. We process the data you enter:

  • occasion, region, approximate number of participants and time period
  • optional: budget, additional services required, ideas from your saved list and a message
  • company, name and email address
  • optional: phone number

Alternatively, you can write to us using the quick enquiry on the enquiry and contact pages. There we process your name, email address and message as well as, voluntarily, your phone number, company and the ideas from your shortlist. The following information on procedure, storage and bot protection applies to the quick enquiry as well.

Mandatory fields are marked in the form. We cannot process your enquiry without this information. All other details are voluntary.

Process: Your enquiry is transmitted in encrypted form to our server and from there delivered as an email to our mailbox. We use Microsoft 365 from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, to send and store our emails. We have a data processing agreement with Microsoft in accordance with Art. 28 GDPR, and processing takes place in the EU within Microsoft's EU Data Boundary. If data is nevertheless transferred to the USA, this is based on the EU-US Data Privacy Framework (Art. 45 GDPR), under which Microsoft is certified. Your enquiry is not stored on the web server itself.

Protection against spam and bots: In the last step of the enquiry assistant and in the quick enquiry form we use Cloudflare Turnstile (for details see section 12.2). The service is only loaded there, not when you visit the rest of the website. We also use an invisible check field.

If delivery is temporarily not possible, the form offers you the option of sending the enquiry by email. Your own email program then opens with a pre-filled message, and section 8 applies.

Legal bases: Art. 6 (1) (b) GDPR, where your enquiry is aimed at concluding a contract with you (pre-contractual measures). If you make the enquiry on behalf of your company, as is usually the case, the legal basis for processing your data as a contact person is Art. 6 (1) (f) GDPR. Our legitimate interest lies in responding to enquiries, preparing offers and maintaining business relationships.

Storage period: We delete the data as soon as it is no longer needed to process your enquiry. If a contract is concluded, the periods set out in section 20 apply.

7.1 Offer room: viewing offers and invoices online, accepting offers

If you have sent us an enquiry or are negotiating a contract with us, we can make our offer available to you in a protected area of this website in addition to the email ("offer room", addresses under /angebot/). There you can view the offer, download it as a PDF, ask questions and accept it with binding effect. We deliver invoices the same way (PDF and, where available, an e-invoice in XML format); here too we log delivery, access and download.

Access: Access is tied to the email address to which we sent the offer. After you enter this address, we send you a six-digit one-time code by email (valid for 15 minutes). After successful verification, your browser stores a technically necessary session cookie (adebar_angebot, at most 12 hours, only for this offer). No consent is required for this cookie (§ 25 (2) no. 2 TDDDG), because it is strictly necessary for the service you have expressly requested.

Data processed: Name, company and email address of the contact person, the offer and invoice documents, your questions and our answers, your declaration of acceptance with the name you entered, and for each of these actions the date and time, IP address and browser identifier. We record this information in an unalterable log (chained checksums) so that delivery, questions and acceptance of the offer can be traced and proven later.

Storage location and dispatch: The data is stored on our web server in Germany (section 3). Emails from the offer room (offer, one-time code, answers, confirmations) are sent via Microsoft 365 (section 7).

Legal bases: Art. 6 (1) (b) GDPR (initiation and performance of a contract). For logging access, questions and acceptance, Art. 6 (1) (f) GDPR; our legitimate interest is proof of delivery and conclusion of the contract as well as protection against misuse. If you act on behalf of your company, the legal basis for your data as a contact person is Art. 6 (1) (f) GDPR.

Storage period: We retain the offer and the log as commercial and business correspondence until the statutory periods expire (§ 257 HGB, § 147 AO), accepted offers as contract documents for up to ten years. Offers that are not accepted are deleted no later than three years after their validity expires. One-time codes are deleted after they expire, sessions after twelve hours at the latest.

8. Contact by email and phone

If you contact us by email or phone, we process the personal data you provide in order to deal with your request. This includes in particular:

  • name
  • contact details (for example email address, phone number)
  • company / organisation stated (if provided)
  • content of your enquiry and any other information you provide

The legal bases are:

  • Art. 6 (1) (b) GDPR, where the communication is aimed at concluding or performing a contract
  • Art. 6 (1) (f) GDPR, where our legitimate interest lies in responding to enquiries, documenting communication and maintaining business relationships

The data is deleted as soon as it is no longer required for the purpose for which it was collected, unless statutory retention obligations prevent this.

Microsoft Teams and Microsoft Bookings: On our team's profile pages you can call or message staff members via Microsoft Teams using a link, and book an appointment via Microsoft Bookings. The booking calendar is only loaded in a window on our website after you click “Book a meeting” (without consent to “External media”, only after a further click on “Load calendar”). Teams links open Microsoft Teams in a new window. Communication and bookings run through services of Microsoft Ireland Operations Limited (Dublin, Ireland), with which we have concluded a data processing agreement. The data you enter there is processed (e.g. name, email address, preferred appointment, content of conversations). The legal bases are Art. 6 (1) (b) and (f) GDPR as above. For Teams calls and chats, the terms of your own Teams account also apply. For possible transfers to third countries, see section 19.

SAMVARO: In the "My events" area and on the page for participants, we link to SAMVARO, our platform for participant management (samvaro.de (opens in a new tab)). SAMVARO is a separate service that is not embedded in this website. You are only redirected to SAMVARO when you follow a link. The only exception is the small verification window of the newsletter sign-up, which is loaded only after you click into the sign-up field (section 14). The SAMVARO privacy notice (opens in a new tab) applies to data processing there.

Social networks: On our website we link to our profiles on LinkedIn, Instagram and Facebook. These are simple links, not embedded plugins. No data is therefore transmitted to these networks when our website loads. Only when you click a link are you taken to the page of the provider in question, where its own privacy provisions apply (see also section 16).

Other websites: Our website may contain links to other external websites, for example to partners. When you click on them, you leave our website. The operators of the linked pages are solely responsible for any further processing of personal data there. Please refer to the privacy notices on those sites.

10. Data security / TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses TLS encryption (often still called "SSL"). You can recognise an encrypted connection by "https://" in your browser's address bar.

We also use appropriate technical and organisational measures to protect the personal data we store against unauthorised access, loss or misuse.

Part B: Data processing by adebar GmbH outside this website

11. Processing of personal data in connection with enquiries, contractual relationships, projects and events

When making contact, working together, performing contracts and delivering projects, productions and events, adebar GmbH processes personal data of prospective customers, customers, business partners, service providers and participants.

The following personal data in particular may be processed:

  • first name and surname
  • company / organisation
  • address
  • phone number
  • email address
  • content of communications and information provided
  • contract, project and booking data
  • invoicing and payment data (for example bank details)
  • participant and organisational data
  • information provided voluntarily, for example job titles or organisational information
  • in individual cases, dates of birth, where required for contractual or organisational purposes

Processing takes place in particular for the following purposes:

  • handling enquiries
  • communicating with prospective customers, customers, project participants and business partners
  • preparing offers and performing contracts
  • planning, organising and delivering projects, productions and events
  • participant administration and participant communication
  • coordinating organisational processes
  • invoicing and payment processing
  • documenting business transactions
  • fulfilling statutory retention and documentation obligations
  • safeguarding legitimate interests in connection with proper business organisation and customer care

For registering and managing participants, we use our platform SAMVARO, among other tools. Details can be found in the SAMVARO privacy notice (opens in a new tab).

11.1 Processing of special categories of personal data (health data)

In the course of projects, events, productions or other organisational processes, special categories of personal data may also be processed on a voluntary basis, where this is necessary for planning, organisation or safe delivery. This may include in particular information on:

  • food intolerances
  • allergies
  • health restrictions
  • support needs

Where we collect such information, this is done voluntarily and on the basis of your explicit consent in accordance with Art. 9 (2) (a) GDPR.

You can withdraw your consent at any time with effect for the future. You can declare your withdrawal in particular by email to datenschutzadebar.de. This does not affect the lawfulness of processing carried out before the withdrawal.

Health-related information is used exclusively for the specific planning and delivery of the project, event or production in question and is only disclosed to those who absolutely need it (for example caterers, accommodation, event organisation).

As a rule, this data is deleted or anonymised immediately after the end of the event in question or once the purpose no longer applies, unless mandatory statutory retention obligations prevent this. It is not stored for longer periods.

11.2 Legal bases and storage period

The legal bases for processing are:

  • Art. 6 (1) (b) GDPR (contract or pre-contractual measures)
  • Art. 6 (1) (c) GDPR (legal obligations, for example retention obligations under tax and commercial law)
  • Art. 6 (1) (f) GDPR (legitimate interest in proper business organisation and communication)
  • Art. 9 (2) (a) GDPR (consent) for health data

The data is only stored for as long as necessary to fulfil the respective purposes or for as long as statutory retention periods apply. Commercial and tax law requirements may provide for retention periods of up to ten years.

11.3 Applications and event staff (set card)

If you would like to work at our events, you can send us our set card. It contains contact details, personal details relevant to your deployment (e.g. clothing size), information on qualifications and availability as well as tax and bank details. A photo is voluntary.

We use this data to check and plan your deployment at events and, if you are engaged, to process the engagement and payment. The legal bases are Art. 6 (1) (b) GDPR (pre-contractual measures and contract) and, for tax and bank details, Art. 6 (1) (c) GDPR (statutory obligations). We use the data internally only and pass it on only where this is necessary for payment or required by law (e.g. to tax authorities).

If no engagement takes place, we delete your details no later than six months after receipt, unless you agree to longer storage. If you are engaged, the statutory retention periods apply (up to ten years for documents relevant to tax).

12. Websites for our clients' events

12.1 Vercel

Websites that we operate for our clients' events (client websites) run on Vercel. Processing in European regions (Frankfurt, Dublin, Malmö) is enforced for server-side functions. Static content is delivered via a content delivery network (CDN) to ensure stable and fast availability. The provider is Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. We have a data processing agreement with Vercel in accordance with Art. 28 GDPR. Vercel is certified under the EU-US Data Privacy Framework. Transfers to the USA are based on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR), supplemented by EU standard contractual clauses (Art. 46 (2) (c) GDPR).

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in operating websites for our clients securely and efficiently).

Log data generated when the client websites are provided via Vercel and the CDN used is only stored for as long as necessary to ensure stability and security and to analyse errors, and is then deleted or anonymised. This usually takes no more than 30 days.

12.2 Cloudflare Turnstile (bot protection)

To protect against abusive and automated requests (bots), we use Cloudflare Turnstile on forms on the websites for our clients' events and on www.adebar.de in the enquiry assistant and the quick enquiry (section 7) as well as for the newsletter sign-up (section 14, via a verification window from samvaro.de). Turnstile uses technical characteristics to check whether a request comes from a human and only shows a checkbox if in doubt. No cookies are set for advertising or analytics purposes. Storing or accessing information on your device is strictly necessary for sending the enquiry you requested (Section 25 (2) No. 2 TDDDG).

When forms are used, the following technical data in particular may be processed:

  • IP address
  • browser and device information
  • operating system
  • referrer URL
  • date and time of access
  • other technical information required to verify legitimate access

Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA

We use EU-oriented Cloudflare configurations to keep processing within the EU or EEA as far as possible.

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in ensuring the security and stability of the websites and in preventing misuse and spam).

Cloudflare generally stores the technical data collected via Turnstile for a short period of a few days up to a maximum of several weeks. Longer-term storage only takes place in aggregated or anonymised form.

Where personal data is transferred to a third country (in particular the USA), this takes place on the basis of appropriate safeguards in accordance with Art. 46 GDPR (in particular EU standard contractual clauses) and additional technical and organisational measures (see section 19).

13. Booking and payment processing

Bookings and payments for events, such as tickets for public events, are processed via SAMVARO. Stripe is used as the payment service provider for this (see section 13.1).

As part of the ordering process (for example when booking services), we collect and process the following data:

  • name and address
  • email address
  • other contact details, if applicable
  • payment data (for example selected payment method, payment status)

The data is processed to handle your order and perform the respective contract. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).

13.1 Stripe (payment service provider)

For online payments, we use Stripe as our technical payment service provider.

Provider: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

The following personal data in particular is processed as part of payment processing:

  • name
  • email address
  • billing and delivery address (if required)
  • payment information (for example credit card type and expiry date, but not full credit card details in our system)
  • transaction ID
  • payment status
  • payment reference / product reference

When you open the payment page, a connection to Stripe's servers is established. Your payment data is stored by Stripe for billing purposes and transmitted to the credit institutions and payment service providers involved.

You can find more information about how Stripe processes your data at: stripe.com/de/privacy (opens in a new tab)

The legal bases are Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in secure and reliable payment processing).

Where data is transferred to third countries (in particular the USA) as part of payment processing, this takes place on the basis of appropriate safeguards in accordance with Art. 46 GDPR (in particular EU standard contractual clauses) and additional safeguards (see section 19).

14. Newsletter (“adebar Impulse”)

Sign-up on this website: You can subscribe to our newsletter “adebar Impulse” in the page footer. For this we need your email address. Providing your first name is optional. Only when you click into the sign-up field does the website load the form details and a small verification window from samvaro.de. No connection to SAMVARO is made before that. The verification window uses Cloudflare Turnstile to protect against automated sign-ups (section 12.2). Your details are transmitted in encrypted form directly to SAMVARO and are not stored on the server of this website.

Management and sending via SAMVARO: Sign-up, management and sending of our newsletter take place via SAMVARO (samvaro.de (opens in a new tab)). SAMVARO is a product of Waterkant.Hamburg, a business unit of adebar GmbH, so the processing is carried out by us. SAMVARO is operated in data centres in Frankfurt am Main. To send emails, SAMVARO uses the Amazon Simple Email Service of Amazon Web Services (AWS) in the Frankfurt am Main region (eu-central-1). A data processing agreement in accordance with Art. 28 GDPR is in place with AWS as part of the AWS Service Terms. Should access from a third country occur in individual cases, the EU Standard Contractual Clauses contained therein apply (Art. 46 (2) (c) GDPR).

The following data in particular is processed in connection with sign-up and sending:

  • email address
  • first name, if you provide it
  • time of sign-up and confirmation, source of the sign-up and version of the consent text
  • technical sending information, in particular the time and identifier of the sending as well as feedback on deliveries, undeliverable messages, complaints and unsubscribes

Performance measurement: We analyse whether our newsletters are opened and which links in them are clicked. For this purpose, the newsletter contains an invisible tracking pixel and links that are redirected via SAMVARO. This analysis can be attributed to you as a recipient and helps us improve the content of our newsletter and tailor it to your interests. It is part of your consent to receive the newsletter. You can object to it at any time by unsubscribing. If your email program does not load images automatically, opening is usually not recorded.

Sign-up uses the double opt-in procedure. After signing up, you will receive an email asking you to confirm your subscription. Only after this confirmation do we add you to the mailing list. Sign-up and confirmation are logged so that your consent can be proven.

Processing is based on your consent in accordance with Art. 6 (1) (a) GDPR. For protection against abuse during sign-up, Art. 6 (1) (f) GDPR also applies (legitimate interest in the security of the form).

The data processed for the newsletter is stored for as long as the subscription exists. After you unsubscribe, the data used for sending the newsletter is deleted. This does not apply to information we need to prove your earlier consent or to prevent the newsletter from being sent again, or to statutory retention obligations.

You can unsubscribe from the newsletter at any time via the unsubscribe link in every newsletter email or by sending us a message. In doing so, you withdraw your consent with effect for the future.

15. Online meetings (Microsoft Teams)

For online meetings, video conferences and digital communication, we use Microsoft Teams, a service provided by

Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA

or by the relevant European group company.

The following personal data in particular may be processed when Microsoft Teams is used:

  • name and contact details (for example email address)
  • profile information (where provided by you)
  • communication content (audio, video, chat content)
  • chat and file content shared in the meeting
  • meeting metadata (for example time, duration, participant information, IP address, device information)

Processing takes place in order to hold meetings, coordinate projects, communicate with clients and handle internal organisational processes.

The legal bases are:

  • Art. 6 (1) (b) GDPR (contract or pre-contractual measures)
  • Art. 6 (1) (f) GDPR (legitimate interest in efficient communication and collaboration)

Meetings are only recorded after the persons concerned have been informed in advance and, where required, have given their consent.

As a rule, personal data processed in Microsoft Teams is only stored for as long as necessary to carry out, document and follow up on the communication, meeting or project in question. The specific storage period depends on the retention and deletion policies applicable within the Microsoft 365 environment used and on any statutory retention obligations.

A transfer of data to the USA cannot be ruled out. The transfer takes place on the basis of the EU-US Data Privacy Framework and the EU standard contractual clauses used by Microsoft, together with additional safeguards (see section 19).

Further information on data protection at Microsoft: privacy.microsoft.com/de-de/privacystatement (opens in a new tab)

16. Social media presence

16.1 Our profiles

We maintain publicly accessible profiles on the following social networks:

  • Instagram
  • LinkedIn
  • Facebook

When you visit our profiles on these platforms, personal data is collected and processed by the respective platform operators. This may also happen if you do not have a profile on the platform yourself or are not logged in.

We do not have full influence over data processing by the platform operators. For details of the respective data processing, please refer to the privacy notices of the platforms:

16.2 Joint controllership

When operating our social media pages, there may be joint controllership with the respective platform operator within the meaning of Art. 26 GDPR. In this context, we receive statistical evaluations (insights) from the platform operators about the use of our profiles in particular.

For data processing on these platforms, we recommend that you primarily address data protection enquiries directly to the respective platform operator. However, you can in principle also assert your rights as a data subject against us.

17. Use of AI-supported systems

adebar GmbH may use AI-supported applications in internal work, organisational and communication processes, for example to support:

  • writing texts
  • internal documentation
  • research
  • organisation
  • project planning and internal communication

Where personal data is processed in this context, this is done exclusively:

  • for purposes permitted under data protection law,
  • in line with the principle of data minimisation and
  • on an appropriate legal basis in accordance with Art. 6 GDPR (in particular performance of a contract, legitimate interest or consent).

If external or cloud-based AI services are used, we ensure that:

  • appropriate contractual bases are in place (in particular data processing agreements under Art. 28 GDPR and, where applicable, EU standard contractual clauses),
  • an adequate level of protection is guaranteed for any data transfers to third countries and
  • appropriate technical and organisational measures (for example access restrictions, encryption, logging) are implemented.

Where possible and reasonable, personal data is anonymised or pseudonymised before AI services are used, in order to reduce the personal reference.

Part C: Common provisions

18. Recipients / categories of recipients

Depending on the processing operation, we pass on personal data to the extent necessary to the following categories of recipients:

  • IT service providers, hosting providers and infrastructure operators (Mittwald for hosting this website, Cloudflare for bot protection, Vercel for client event websites)
  • SAMVARO for the newsletter sign-up and participant management
  • Email and communication services (Microsoft 365, among other things for delivering enquiries)
  • payment service providers and banks (for example Stripe)
  • service providers for sending the newsletter (Amazon Simple Email Service via SAMVARO)
  • providers of communication and collaboration services (for example Microsoft Teams, Microsoft Teams chat)
  • providers of reach measurement, only with your consent (Google Analytics)
  • service providers in connection with projects, productions and events (for example hotels, caterers, event venues, technical service providers)
  • external advisers and service providers (for example tax advisers)
  • operators of social media platforms and review portals

Where we use external service providers as processors within the meaning of Art. 28 GDPR, processing takes place exclusively on the basis of corresponding data processing agreements.

19. Data transfers to third countries

Where personal data is transferred to countries outside the European Union (EU) or the European Economic Area (EEA), we ensure that an adequate level of data protection within the meaning of Art. 44 et seq. GDPR is in place.

This is achieved in particular by:

  • using services for which there is an adequacy decision by the European Commission (for example companies certified under the EU-US Data Privacy Framework), and/or
  • concluding EU standard data protection clauses (Standard Contractual Clauses, SCC) with additional technical and organisational measures.

These measures include in particular:

  • encryption and pseudonymisation of personal data where possible,
  • data minimisation and limiting the data transferred to what is necessary,
  • implementing access restrictions and authorisation concepts,
  • regularly reviewing the service providers used for compliance with the agreed level of data protection.

Should a transfer to a third country take place without an adequacy decision and without appropriate safeguards, this will only happen in the exceptional cases permitted by law under Art. 49 GDPR (for example on the basis of your explicit consent or to perform a contract).

20. Storage period

We only store personal data for as long as necessary to achieve the purposes for which it was collected or as required by statutory retention obligations.

Data collected for the performance of a contract is deleted once the statutory retention periods have expired. Where customer data is not subject to retention obligations, it is deleted once the purpose has been achieved.

In practice, this means in particular:

  • Contract, invoicing and payment data is generally retained until the statutory retention periods expire (in particular under § 147 Abgabenordnung (AO, German Fiscal Code) and § 257 Handelsgesetzbuch (HGB, German Commercial Code), 6, 8 or 10 years depending on the type of document).
  • Data from enquiries and general correspondence is deleted as soon as it is no longer needed to process your enquiry, unless statutory retention obligations or legitimate documentation interests prevent this.
  • Health data collected in connection with events is deleted immediately once the purpose no longer applies (see section 11.1).
  • Offer room (section 7.1): offers and logs until the statutory retention periods expire, offers that are not accepted no later than three years after their validity expires.
  • Server log files: see section 4. Saved list: see section 6.

21. Your rights as a data subject

Under the applicable data protection laws, you have the following rights with regard to personal data concerning you:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent given (Art. 7 (3) GDPR)

Right to object under Art. 21 GDPR: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6 (1) (f) GDPR. We will then no longer process the data, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

If we process personal data for direct marketing purposes, you have the right to object at any time to processing for the purposes of such marketing. In that case, the personal data will no longer be processed for these purposes.

If data processing is based on your consent, you can withdraw this consent at any time with effect for the future. This does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

To exercise your rights, simply send a message to: datenschutzadebar.de

22. Right to lodge a complaint with a supervisory authority

If you believe that the processing of your personal data infringes data protection law, you have the right under Art. 77 (1) GDPR to lodge a complaint with a data protection supervisory authority. This may in particular be the supervisory authority in the member state of your habitual residence, your place of work or the place of the alleged infringement.

The supervisory authority responsible for adebar GmbH is:

Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern (State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania) Schloss Schwerin, Lennéstraße 1, 19053 Schwerin Phone: +49 385 59494-0 Email: infodatenschutz-mv.de Website: www.datenschutz-mv.de (opens in a new tab)

In addition, people who live in Hamburg or are in contact with Hamburg bodies can also contact the following supervisory authority:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (Hamburg Commissioner for Data Protection and Freedom of Information) Ludwig-Erhard-Straße 22, 20459 Hamburg Phone: +49 40 428 54-4040 Email: mailboxdatenschutz.hamburg.de

23. Automated decision-making

We do not use automated individual decision-making, including profiling, within the meaning of Art. 22 (1) and (4) GDPR.

24. Currency and amendment of this privacy policy

Status: 30 September 2026

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to reflect changes to our services. The current version will then apply to your next visit.