I. Who are we and how can you reach us?
II. What data is processed when you visit our website?
III. What data is processed when you contact us, order a newsletter, open a user account?
IV. What rights do you have and how can you exercise them?

Thank you for visiting the websites of the Haufe Group. Protecting yourpersonal data is very important to us. The purpose of this privacy policystatement is to inform you about how your personal data is handled when youvisit our websites, and about your rights in this regard.

I. Who are we and how can you reach us?

We are the

Haufe Service Center GmbH

A Haufe Group Company
Munzinger Straße 9
79111 Freiburg


and as a “controller” in the sense of the GDPR, we are responsible forprotecting your personal data. Our data protection officer, Raik Mickler, willbe happy to assist you with any questions you may have about data processing,your rights, or this privacy policy statement. He can be reached at:

II. What data is processed when you visit our website?

A. Log files
Data collected:
When you visit our website, your browser automatically transmits the followingdata to us:

• Your IP address
• The website you are coming from
• Websites that you access from our site
• The pages you click on, and
• Time when the page was accessed
• Name of your Internet service provider
• Your browser type and version
• The operating system used on your device
• The date and duration of your visit.

Purposes for which the data is processed:
Temporary storage of this data is necessary to display the website on yourcomputer and to ensure that the website functions properly. We also use thisdata to compile statistics about how our websites are used. Another reason forcollecting this data is to track and prevent unauthorized access to the webserver and any improper use of the web pages, and to secure our informationtechnology systems.

Legal basis:
We temporarily store this data on the basis of legitimate interests (Art. 6(1)(f) GDPR). It is in our legitimate interest to achieve the purposesdescribed above.

Storage period and control options:
The data is deleted when it is no longer needed to achieve the describedpurposes. Log files are deleted after a maximum of 90 days.

B. General information about cookies and targeting technologies
Data collected:
Our website uses “cookies”, which are small text files that are stored on your device. Cookies typically contain a unique character sequence called thecookieID which can be used to identify your browser the next time you visit ourwebsite. We also use “tags”, i.e. small pieces of code with which we can measure ourusers’ behavior and determine the success of our advertising activities. Depending on the type of cookies or tags used, different types of data arecollected and processed after pseudonymization. We use both our own cookies and cookies from other providers (third-party cookies).The third-party cookies are described in detail below, in Section 2 C.

Purposes for which the data is processed:
Some cookies are technically necessary for the functioning of our websites.Certain functions used on our websites cannot be offered without the use ofcookies. Functionality cookies are used to make our websites more user-friendly and toensure that certain functionalities are available, e.g. the ability toconsistently display the shopping cart icon from one page to the next with thenumber of items in your cart, or storage of your login data so that you canhave access to the data and settings you have already entered when you returnto the page. Analysis cookies and tags enable us to generate overall statistics, e.g. thenumber of times a given page has been accessed, which areas of our pages aremost frequently viewed, and information on locations and the average amount oftime spent on each page. This helps us to improve the quality of our websitesand their content. Advertising cookies and retargeting technologies enable us to provide you withoffers and information tailored to your specific needs. This helps us toprovide you with a more interesting experience at our websites, and to reachout to you on other websites with personalized advertising based on yourinterests.

Legal basis:
We use technically necessary cookies and functionality cookies on the basis oflegitimate interests (Art. 6 (1)(f) GDPR). It is in our legitimate interest toensure that our websites function as intended and to provide optimal usabilityfor visitors to our websites. We use analytics cookies and advertising cookies, as well as tags andretargeting technologies on the basis of legitimate interests (Art. 6 (1)(f)GDPR, Recital 47). It is in our legitimate interest to tailor our websites toour customers’ specific interests.

Storage period and control options:
Some of the cookies we use are automatically deleted after closing the browser(so-called session cookies), while others are stored permanently on your deviceand enable us to recognize your browser (so-called persistent cookies). You have full control over the use of cookies and can delete cookies in yourbrowser, completely deactivate the storage of cookies, or selectively acceptcertain cookies. Use your browser’s help function to learn how you can changethese settings. Note that such changes may limit the functionality of ourwebsites.

C. Third-party cookie and tracking technologies
1. Econda:

Data collected:
We use solutions and technologies from econda GmbH, Eisenlohrstraße 43, 76135Karlsruhe, Germany (“Econda”). Econda uses cookies to create pseudonymous userprofiles that persist across multiple pages. To do this, data is collected sothat your browser can be recognized. Your IP address will be madeunrecognizable immediately upon receipt to prevent it from being associatedwith user profiles.

Purposes for which the data is processed:
We use Econda to optimize our websites and adapt them to our users’ needs.

Legal basis:
We use Econda after you have given your consent. When you visit our website, weobtain your consent via the cookie banner at the bottom edge of the page.

Storage period and control options:
Econda stores this data and deletes it regularly. You can block Econda from collecting and processing your data by configuringyour browser settings accordingly, or through this link.

2. Facebook:
Facebook-Pixel and Facebook Custom Audience (Remarketing)

Data collected:

On our website we deploy the so-called "Facebook pixel" of the company"Facebook" (Facebook Ireland Ltd., 4 Grand Canal Square, Grand CanalHarbour, Dublin 2 Ireland). The Facebook pixel enables us to classify thevisitors to our website into specific target groups in order to be able todisplay corresponding advertisements ("ads") on Facebook. The datacollected (e.g. IP addresses, information about the web browser, the locationof the website, buttons clicked, pixel IDs if applicable and other features)cannot be viewed by us, but can only be used within the scope of the display ofcertain advertisements. Within the scope of using the Facebook pixel code,so-called cookies are also used. If you have a Facebook account and are signed in, your visit to this websitewill be associated with your Facebook user account. We also partly utilise the remarketing function "Custom Audiences" ofthe company "Facebook". This enables users of the Site to displayinterest-based ads ("Facebook Ads") when visiting Facebook or otherwebsites that also use this method. In this respect, we pursue your interest indisplaying advertisements that correspond to your interests in order to makeour website more appealing to you. In order to exchange the respective data, your browser automaticallyestablishes a direct connection with the Facebook server. We have no controlover the extent and further use of the data collected by Facebook through theuse of this tool and therefore inform you according to our state of knowledge:By integrating Facebook Custom Audiences, Facebook receives the informationthat you have accessed the corresponding website of our website or clicked onan advertisement from us. If you are registered with a "Facebook" service, "Facebook" may assign the visit to your account. Even if youare not registered with Facebook or have not logged in, it is possible for theprovider to trace and store your IP address and other identification features.
Insofar as you have consented to this, we may forward your telephone number ore-mail address to "Facebook" in order to be able to displayadvertisements corresponding to your interests.

To find out how Facebook pixel is deployed for advertising campaigns, pleasevisit

For more information about Facebook's privacy policy, please visit

For more information about Facebook's data processing practices, pleasevisit

Purposes for which the data is processed:
We employthese functions in order to be able to provide you with advertisingofferscorresponding to your interests.

Legal basis:
We processyour data on the basis that you have consented to this or that wehave alegitimate interest in processing the data pursuant to Art. 6 para. 1,sentence1 (a) and (f) GDPR.

Storage period and control options:
We storeyour data as long as we require it for the respective purpose (displayofinterest-based advertising) or provided you have not objected to the storageofyour data or revoked your consent.

The deactivation of the function "Facebook Custom Audiences" ispossible for logged in users at     

If you are logged in to Facebook you can adjust your ad settings in Facebook at

3. Google:
Data collected:
Google Remarketing and DoubleClick: We use Google Remarketing and Google DoubleClick. This technology uses cookies to track how you use our website,and to help us recognize your browser when you visit websites that are part ofthe Google advertising network. To do this, the Google Analytics tracking codeuses so-called DoubleClick cookies in addition to the usual Google Analyticscookies. DoubleClick cookies collect data about which third-party websites youhave visited in the Google Display Network, and which ads you have clicked on.Data from first-party cookies (e.g. Google Analytics cookies) is also linkedwith data from third-party cookies (e.g. Google cookies for displaypreferences). This allows us to evaluate how advertisements are displayed andhow you interact with them.

Google AdWords Conversion Tracking: We use Google AdWordsConversion Tracking. This technology stores cookies when you interact with oneof our advertisements, e.g. by clicking on it. The cookies are then used toanalyze what happens after you interact with an ad, such as whether you boughtour product, accessed the ad from a cell phone, downloaded our app, or subscribedto a newsletter.

Google Tag Manager: Google Tag Manager is a solution that we use tomanage web page tags from an interface (allowing us to integrate f. e. GoogleAnalytics, or other Google marketing services, into our online offering). Thetag manager itself (which implements the tags) does not process personalinformation. With regard to the processing of personal data, reference is madeto the information relating to the respective Google services. The Google TagManager usage policy can be viewed here:

Purposes for which the data is processed:

Google Remarketing and DoubleClick: We use this technology to displayads relevant to your interests on other sites in the Google advertisingnetwork. These ads relate to content that you have previously viewed on ourwebsites.

Google AdWords Conversion Tracking: We use this technology toimprove our offerings.

Google Tag Manager: We use this service to create, deploy andmanage tags on our website.

Google Maps: We use Google Maps to make it easier for you to find our location, in which we have an interest. This is also the purpose of the data processing.

Legal basis:

We use the Google products listed above after you have given your consent. Whenyou visit our website, we obtain your consent via the cookie banner at thebottom edge of the page.

Storage period and control options:
The data that is collected by these Googlefunctions is stored and deleted regularly. You may prevent the use of cookies by configuring the appropriate settings onyour browser. You can also prevent Google from collecting and processing this data bydownloading and installing the browser add-on available at this link.

Google Dynamic Remarketing and DoubleClick: You can refuse the storage of cookies and the associateddata processing by deactivating personalized ads in your ad settings. You can deactivate the use of cookiesby third-party providers through the Network Advertising Initiative’s opt-out page. . Note that such changes may limit the functionality of our websites. For more information, see the Google Privacy Policy Statement.

4. LinkedIn Insights Tag:
Data collected:
On this website we use the LinkedIn Insight Tag. The LinkedIn Insight Tagcreates a LinkedIn „Browser Cookie“, which collects the following data:
- IP address,
- time stamp,
- page Activities,
- demographic data from LinkedIn, if the user is an active LinkedIn user.

Purpose of data processing:
We process your data to rate campaigns and gather information about websitevisitors who may have reached us through our LinkedIn campaigns.

Legal basis:
We process your data because you have consented to this or because we have alegitimate interest in processing the data, Art. 6 para. 1 sentence 1 lit. a.and f EU-GDPR.

Storage duration and control options:
We save your data as long as we need them for the respective purpose (campaignevaluation), as long as you have not objected to the storage of your data orhave revoked your consent. The collected data is encrypted. More information can be found here. Here you will find the LinkedIn privacy policy, as well the LinkedIn Opt-Out.

Lead forms:
If you submit a so-called lead form on the LinkedIn website, we process yourpersonal data in order to be able to provide the information you haverequested. Subject to your consent, we will transfer the information you enterin the lead form to our customer database (CRM system) and link it to any otherinformation you provide, in order to provide you with future offers that suityour preferences. If you have consented to this, you may revoke the relevantuse of your data at any time.You may revoke your consent at any time:
1. In respect of your LinkedIn data within 90 days click here;
2. In respect of the data stored at Haufe at any time by email to

5. Microsoft AdvertisingRemarketing:
Data collected:
We use Universal Event Tracking (“UET”), a service of Microsoft Corporation, One Microsoft Way, Redmond WA 98052-6399, USA (“Microsoft”). When you access our websites through ads provided by Microsoft Advertising Remarketing, a cookie is placed on your computer. In addition, a UET tag is integrated on our websites. A UET tag is a code that is used together with the cookie to store pseudonymized data about how the website is used. In combination with the cookie, the tag records pseudonymized data to track what actions you perform on our websites after clicking on an ad from Microsoft Advertising Remarketing. The data collected include the amount of time spent on the website, which areas of the website were viewed, and what ad led you to the website. In addition, Microsoft can use cross-device tracking to track your usage across multiple electronic devices. The information collected is transferred to a Microsoft server in the United States, where Microsoft is committed to maintaining an adequate level of data protection through the use of EU standard contractual clauses.

Purposes for which the data is processed:
UET enables us to track your activities on our websites when you have accessed our websites via ads from Microsoft Advertising Remarketing; this, inturn, enables us to improve our online offerings. Cross-device tracking enables Microsoft to display personalized advertising.

Legal basis:
We use Microsoft Advertising Remarketing after you have given your consent. When you visit our website, we obtain your consent via the cookiebanner at the bottom edge of the page.

Storage period and control options:
Microsoft stores the data for a period of no more than 180 days. You can prevent your data from being collected and processed by deactivating the use ofcookies. Note that such changes may limit the functionality of the websites inquestion. You can use this link to deactivate cross-device tracking. For more information on Microsofts analytics services, please visit this website. For more information on data privacy at Microsoft see the Microsoft Privacy Statement.

6. Salesviewer:
Data collected:
We use solutions and technologiesprovided by SalesViewer GmbH, Bongardstraße 29, 44787 Bochum, Germany. As partof SalesViewer®, a JavaScript-based tracking code is used on the Haufe Groupwebsite, which is used to determine the following information:

- Name, origin and industry of thevisiting company
- Referrer
- Keyword (search terms on our website)
- Visitor behavior (e.g. subpages visited, time of visit, duration of visit)

No cookies or similar files are storedon the end devices of the website visitors. With the help of SalesViewer®, weonly identify the company from which our website is visited. Instead, thevisiting company is identified by matching it with generally accessibleinformation. For this purpose, the online identifier of the website visitor isencrypted using a non-reversible one-way function (hashing) and, after apre-selection process that filters out private access, is transferred to theprovider in pseudonymized form. These online identifiers are compared by theprovider with a database restricted to company-related data. Insofar ascompany-related accesses can be identified within the scope of this procedure,the Haufe Group is provided with corresponding company-related data about thewebsite visit on an Internet platform of SalesViewer. On the platform, it isalso possible to research further generally accessible data (e.g. address andcontact data) about the visiting companies.

Purposes of dataprocessing: We use SalesViewer® to compilestatistics on visitor behavior to gain insights into the use and visitor groupson our websites.

Legal basis: We process your personal data on thebasis of your consent (Art. 6 para. 1 a) DSGVO). We obtain your consent whenyou call up our websites via the cookie banner.

Storage period andcontrol options: You can informally revoke your consentat any time with effect for the future. You can do this by deleting the cookiesin your browser history and making your cookie decision again via our cookiebanner. In addition, you can also unsubscribe from tracking by SalesViewer® viathis link [].Your data will be stored until you revoke your consent.

7. Eloqua (Oracle):
Data collected: We use the service Eloqua of the provider ORACLE Deutschland B.V. & Co.KG, Riesstrasse 25, 80992 Munich. Eloqua sets a permanent cookie on yourbrowser on the respective registration website.

Purposes for which the data is processed: We use Eloqua to analyze the use of our websites so that we can continually improve them.

Legal basis: We use Eloqua if you have consented to this. We obtain your consent whenyou call up our websites via the cookie banner, Art. 6 para. 1 lit. a DSGVO.

Storage period and control options: Eloqua stores your data and this is deleted regularly. You can prevent thecollection and processing of data by Eloqua by making the appropriate settingin your browser or via the following link.For more information, see Oracle's privacy policy.

Social plugins:
We use social plugins from the following social media sites:
• Facebook, which is operated by Facebook Inc, 1601 S. California Ave, PaloAlto CA 94304, USA (“Facebook”).
• Twitter, which is operated by Twitter Inc, 795 Folsom St., Suite 600, SanFrancisco CA 94107, USA (“Twitter”).
• LinkedIn, which is operated by LinkedIn Corporation, 1000 W. Maude Ave,Sunnyvale, California 94085, USA ("LinkedIn").XING, which is operated as aproduct of New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany.

When you visit a website that contains one of these plugins, your browserestablishes a direct connection to the servers of the associated social mediasite. This integration provides the social media site with information aboutthe website you have visited, even if you do not have a user profile or are notcurrently logged in. If you are logged in, Facebook can associate the websitevisit to your Facebook account. When you interact with the plugins, theassociated information is sent to the social media site and stored there. YourIP address is stored in shortened form. Once collected, the data is transmitteddirectly from your browser to one of the social media site’s servers in the United States and stored there.

Purposes for which the data is processed:
The social plugins allow you to share website content on social media sites.

Legal basis:
We use social plugins after you have given your consent. When you visit ourwebsite, we obtain your consent via the cookie banner at the bottom edge of thepage.

Storage period and control options:
You can block social media sites from collecting and processing your data byconfiguring your browser settings accordingly.
If you do not want social media sites to directly associate the informationcollected through our websites with your user profile, you must log out beforevisiting our websites. For more information, see the Facebook, Twitter and LinkedIn privacy policy statements.

8. Usercentrics:
Data collected:

We use the consent management service Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany ("Usercentrics"). Usercentrics is used on the website as a processor for the purpose of consent management. The following data is collected: opt-in and opt-out data, referrer URL, user agent, user settings, consent ID, time of consent, consent type, template version, banner language.

Purposes for which the data is processed:
We use Usercentrics to comply with the legal obligations of consent storage.

Legal basis:
We use Usercentrics to comply with our legal obligation, Art. 6 para. 1 p. 1 lit. c DSGVO.

Storage period and control options:
The consent data (consent and revocation of consent) is stored for three years. The data will then be deleted immediately.For more information, please see the Usercentrics privacy policy.

9. Capterra:
a) Data collected:
Our websites use the service of Capterra Inc, 56 Top GallantRoad Stamford, CT 09602, United States of America (hereinafter"Capterra"). Capterra uses cookies, which helps the user to find theappropriate software in a search query. The information generated by the cookieabout your use of this website and your IP address are transmitted to aCapterra server and stored there. For more information about the cookies used,please see this link.

b) Data processing purposes: We use Capterra to enable you to find suitable software.

c) Legal basis: We use Capterra if you have consented to it. We obtain yourconsent when you call up our websites via the cookie banner, Art. 6 para. 1lit. a DSGVO.

d) Storage period and control options: Capterra stores your data and it is deleted regularly. Youcan prevent the storage of cookies by setting your browser software accordinglyor delete them. In addition, you can object to the collection of the datagenerated by the cookie and related to your use of the website (including yourIP address) to Capterra as well as the processing of this data altogether underthis link.

Details on the handling of your personal data can be foundunder the following link

III. What data is processed when you contact us, order a newsletter and open a user account?

This sections explains what data is collected and processed when youcontact us, order a newsletter or open an account; for what purposes and bywhich recipients it is processed; on what legal basis the data is processed;and when the data is deleted.

A. Contacting us
Data collected:
When you contact us through a contact form or via email, we collect and processthe data you provide, such as your contact information, your name and yourrequest. All data that you share with us is transmitted from your browser toour server in encrypted form.

Purposes for which the data is processed:
Data processing is performed by our customer service department or by serviceproviders working on our behalf, exclusively on the basis of your request andin order to process that request.

Legal basis:
We process your data for the implementation of precontractual and contractualmeasures that are performed at your request (Art. 6 (1)(b) GDPR).

Storage period:
We store your data for as long as we need it for the specific processingpurpose, or to guarantee or comply with statutory retention periods.

Transfers to third countries:
We deploy, among others, the service provider EMEA Limited, Company No. 05094083, registered in England;Floor 26 Salesforce Tower, 110 Bishopsgate, EC2N 4AY London; UK) for theadministration of your data. In principle Data is processed in European data centres, data mayalso betransmitted to third countries such as the USA whilst undertaking maintenanceand support measures. In order to ensure that your data is adequately protectedin such cases, we have obligated the service provider Salesforce Inc. to adhere to a data protection level that complies with EU law, using thecorresponding EU standard contractual clauses for the transfer of personal datato processors established in third countries.

B. Customer surveys
Data collected:
For online surveys, we use the services of Netigate Deutschland GmbH,Untermainkai 27-28, 60329 Frankfurt am Main, Germany. Netigate processes theinformation provided by users for the sole purpose of evaluating surveys on ourbehalf, and as long as no personal data is requested, such as names or emailaddresses, it stores the information anonymously, i.e., in particular, withoutthe users’ IP addresses. If personal data (e.g. name, mailing address, company,etc.) that goes beyond the topic of the survey is also requested in connectionwith the survey, we point out separately in connection with the survey that thedata in question is additional, voluntarily provided data that we collect anduse.
Purposes for which the data is processed:
We use Netigate to optimize our products and services and adapt them to ourusers’ needs.

Legal basis:
We use Netigate when you complete a questionnaire that uses this service. Bysubmitting your answers, you give your consent.

Storage period:
For surveys with personal data, the personal data is automatically deletedafter 13 months.

C. Newsletters
Data collected:
When you subscribe to our newsletter, we collect and process the data youprovide, such as your name and email address.
Newsletters that contain Eloqua technologies use tracking technologies. Thesetechnologies are used to collect information about whether our emails areopened and which links you click on.
Purposes for which the data is processed:
We process the data so that we can deliver the newsletter to you.
We use the data collected through Eloqua to find out which topics are ofinterest to you. We then use this information to improve the emails that wesend you and the services we provide, and to link them to existing tracking orprofiling information.
Legal basis:
After you register for a newsletter on one or more particular topics, weprocess your data with your consent so that we can keep you informed about theselected topics via email, as well as sending you relevant ads. Our approachhere is based on the double opt-in principle, i.e. when you order a topicnewsletter on our website, we send you a confirmation email with a registrationlink. Only after clicking on this link will you be added to our newsletterlist.
We use Eloqua with your consent.
If we have obtained your email address in connection with the sale of aproduct, we use it to send you information about similar products on the basisof legitimate interests (Art. 6 (1)(f) GDPR). It is in our legitimate interestto address you directly with our advertising.
Storage period:
We store your data for as long as we need it for the specific processingpurpose.

IV. What rights do you have and how can you exercise them?

A. Revocation of consent
If you have consented to the processing of your personal data, you can revokethat consent at any time with future effect. Note that such revocation has noeffect on the legality of previous data processing, and that it does not extendto data processing for which a statutory justification exists, and which maytherefore take place even without your consent.
B. Additional rights of data subjects
In addition, you have the following rights as a data subject under Articles 15to 21 and 77 of the EU General Data Protection Regulation (GDPR), provided thatthe statutory requirements are met:
You can request at any time that we provide you with information as to which ofyour personal data we process and how, and that we provide you with a copy ofthe stored personal data that relates to you, Art. 15 GDPR.
You can request the correction of incorrect personal data and the completion ofincomplete personal data, Art. 16 GDPR.
Regarding the deletion of your personal data: Please note that the right todeletion excludes data that we require for the execution and processing ofcontracts, and for the assertion, exercise and defense of legal claims, as wellas data for which statutory, regulatory or contractual retention requirementsapply, Art. 17 GDPR.
Restriction of processing:
Under certain circumstances, you may request that processing be restricted,e.g. if you believe that your data is incorrect, that the processing of yourdata is unlawful, or if you have objected to the processing of your data. Theresult of such a request is that your data may only be processed to a verylimited extent without your consent, e.g. for the assertion, exercise anddefense of legal claims or to protect the rights of other natural and legalpersons, Art. 18 GDPR.
Objection to data processing:
You have the option to object at any time to data processing for purposesof direct advertising. In addition, if special reasons apply, you can object atany time to data processing on the basis of a legitimate interest, Art. 21GDPR.
Data portability:
You have the right to receive the data that you have provided to us, and thatwe process based on your consent or in order to fulfill a contract, in acommon, machine-readable format and, to the extent that this is technicallyfeasible, to request that this data be transmitted directly to third parties,Art. 20 GDPR.
C. How to contact us
You can exercise your rights via the following contact channels:
Haufe Group
Mr. Raik Mickler
Data protection officer
Munzinger Straße 9
79111 Freiburg (Germany)
You can also revoke your consent to receive the newsletter at any time byclicking the corresponding link in each newsletter.
D. Right of appeal to a regulatory authority
If you believe, for example, that our data processing is unlawful or that wehave not protected the rights described above to the required extent, you havethe right to file a complaint with the competent data protection authority.
Revision: March 2021