Information on the handling of personal data
We are very pleased about your interest in our website — and thus in our company. The protection of your private rights and freedoms is very important to us; we only use your data for the purposes intended. Since it is important to us that you are aware at all times of the extent to which we collect, use and, if necessary, transfer your data to third parties, we will provide you with the following comprehensive information on the processing of your personal data collected by us or stored by us.
Visiting our website is generally possible without providing (personal) data; if there are exceptions to this for selected services, we will explain these in the following chapters. When processing personal data, we strictly adhere to the requirements of the EU General Data Protection Regulation (GDPR) and any other data protection regulations.
Name and address of the controller
Willy-Brandt-Straße 59–65
20457 Hamburg, Germany
akeno GmbH
Phone: –
E-mail: contact@akeno.ai
Contact details of the data protection officer
Cortina Consult GmbH
Jörg ter Beek
Hafenweg 24
48155 Münster, Deutschland
Data Protection Team for General Data Protection Inquiries:
E-Mail: dsb.akeno@cortina-consult.de
Website: https://www.cortina-consult.com
Rights of the data subject
The General Data Protection Regulation (GDPR) guarantees every data subject certain rights in relation to their personal data. These include:
The right of access: every data subject has the right to obtain from us confirmation as to whether or not personal data concerning them are being processed, and access to those data, as well as further information and copies of those data.
The right to rectification: Every data subject has the right to request the rectification of inaccurate personal data without undue delay.
The right to erasure ("right to be forgotten"): Every data subject has the right to request the erasure of their personal data without undue delay.
The right to restriction of processing: Every data subject has the right to request the restriction of the processing of their personal data.
The right to data portability: Every data subject has the right to receive the personal data concerning them, which they have provided to us, in a structured, commonly used and machine-readable format.
Right to object: Every data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1) GDPR. If we process personal data concerning the data subject for the purpose of direct marketing, the data subject may object to this processing pursuant to Art. 21 (2) and (3) GDPR.
Right to Withdraw Consent to Data Processing: Every data subject has the right to withdraw their consent to the processing of personal data at any time.
The data subject also has the right to lodge a complaint with a supervisory authority if they consider that the processing of their personal data infringes the GDPR.
The supervisory authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
General information on the legal basis for data processing
"Personal data" is all information that relates to a specific person. We process this data in accordance with the applicable data protection laws, in particular the GDPR and the BDSG. We may only process personal data if one of the following legal permissions applies:
Permissive element
Requirement of the GDPR
Informed consent
Art. 6 para. 1 a
Fulfilment of a contract
Art. 6 para. 1 b
Performance of pre-contractual measures
Art. 6 para. 1 b
Fulfilment of legal obligations
Art. 6 para. 1 c
Protection of vital interests
Art. 6 para. 1 d
Safeguarding our legitimate interests
Art. 6 para. 1 f
Storage duration of personal data
We only store your data for as long as is necessary to achieve the purpose of the processing or to fulfill our contractual or legal obligations, unless otherwise stated in the following information. Statutory retention obligations may arise from commercial or tax regulations. After the end of the calendar year in which we collected the data, we will retain personal data contained in our accounting records for ten years and personal data contained in business letters and contracts for six years. Furthermore, we will retain data in connection with consents requiring proof as well as complaints and claims for the duration of the statutory limitation periods. Data stored for advertising purposes will be deleted if you object to processing for this purpose.
Collection of general data and information
Data collected
Purpose of the collection
Browser types and versions used
correct display of the page content
Operating system used, visitor origin (referrer, e.g. Google), subpages clicked on
Date and time of access to the website as well as IP address and internet service provider of the visitor
Ensuring the permanent functionality of our IT systems (for the operation of the website) and prevention of misuse
Other data and information for security purposes in the event of attacks
Provision of relevant information for law enforcement authorities in the event of a cyber attack
Actuality of Our Privacy Policy
To ensure that our privacy policy information is always up to date in connection with the services of our website, we use the CLOUD DSE service provided by Cortina Consult GmbH, Hafenweg 24, 48155 Münster, Germany.
The content of our privacy policy is hosted on Cortina Consult's servers and centrally managed. Necessary changes are promptly implemented by Cortina Consult and immediately displayed through direct integration on our website.
The legal basis for this processing is the legal obligation pursuant to Art. 6 (1) (c) of the General Data Protection Regulation (GDPR) as well as our legitimate interest according to Art. 6 (1) (f) in maintaining an up-to-date privacy policy at all times.
The duration of data storage is based on the general time limits for data deletion. Data is not transferred to a third country and such transfer is not planned.
The data is usually provided by the data subject but may also come from third parties.
The data collected includes metadata and communication data (IP address, log data).
Framer
We use Framer for hosting the website.
The legal basis for this processing is our legitimate interest pursuant to Article 6(1)(f) of the General Data Protection Regulation (GDPR).
Data may be transferred to Framer B.V., Rozengracht 207B, Amsterdam, 1016 LZ, Netherlands.
The data usually comes from the data subject but may also come from third parties. Collected data includes IP address, log files, page views, and interaction data.
You can contact the data protection officer of Framer B.V. at: compliance@framer.com
Google Tag Manager
The Google Tag Manager is used to simplify the management of analytical tools by centrally controlling and managing the collected analysis mechanisms. The processing of associated personal data is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG.
If necessary, the data may be forwarded to Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, and may be transferred, stored, and processed in the USA. The data transfer is based on the standard contractual clauses of the EU Commission, and Google LLC is certified under the EU-US Data Privacy Framework (DPF).
The duration of data storage is subject to the general deadlines for data deletion.
The data usually comes directly from the data subject. Possible categories of personal data include click behavior, anonymized IP addresses, referrer information, visited subpages, duration of stay on the website, frequency of visits, date, access location, and time of visit.
Information on opt-out can be found under cookie settings. The data protection officer of the provider can be contacted via https://support.google.com/policies/contact/general_privacy_form.
For more information about Google's data processing practices, please visit https://business.safety.google/privacy/
Google Analytics
We process personal data of our website visitors for the purpose of creating usage profiles to optimize the cost-benefit factor on our website. The legal basis for this is consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. If necessary, the data may be forwarded to Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, and may be transferred, stored, and processed in the USA.
We have concluded a contract for order processing with the recipient to ensure that the personal data of our website visitors are processed only in accordance with our instructions.
The duration of data storage is determined by the general deadlines for data deletion.
The data usually come directly from the data subject.
The categories of personal data include click behavior, anonymized IP addresses, referrer information, visited subpages, duration of stay on the website, frequency of visits, date, access location and time of visit, as well as the user agent.
To opt out of this processing, a browser plugin can be installed, available at https://tools.google.com/dlpage/gaoptout.
The data protection officer of the provider can be contacted via https://support.google.com/policies/contact/general_privacy_form. For more information about Google's data processing practices, please visit https://business.safety.google/privacy/
Google Ads Conversion Tracking
We use Google Ads Conversion Tracking. This service records what happens after a user clicks on an ad placed by us through Google Ads and then visits our website. Conversions measure whether users perform a specific, predefined action on the website after clicking on an ad served through Google Ads (e.g., ordering services). This allows us to determine which keywords, ads, ad groups, or campaigns lead to the desired user interaction.
The legal basis for this processing is your informed consent pursuant to Article 6(1)(a) of the General Data Protection Regulation (GDPR).
Data may be transferred to Google Ireland Ltd in Ireland and possibly transmitted, stored, and processed in the USA. This data transfer is based on the EU-U.S. Data Privacy Framework, under which Google LLC is certified.
Data generally comes from the data subject but may also originate from third parties. Collected data includes click behavior, anonymized IP addresses, referrers, visited subpages, time spent on the site, frequency of visits, date, access location, visit time, and user-agent.
You can contact Google's data protection officer at: https://support.google.com/policies/contact/general_privacy_form For more information about Google's data processing practices, please visit https://business.safety.google/privacy/
Meta Pixel (formerly Facebook Pixel)
Our website uses the Visitor Action Pixel from Meta (formerly Facebook) for conversion tracking. This allows us to track the behavior of website visitors who arrive on our website by clicking on a Facebook advertisement. This enables us to analyze the effectiveness of Facebook advertisements for statistical and market research purposes and optimize them for future advertising campaigns. The legal basis for this processing is your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG.
Please note that we, together with Meta Platforms Ireland Ltd., are jointly responsible for the collection and transmission of data to Facebook (Art. 26 GDPR). We emphasize that our responsibility concerns solely the collection and transmission of data, while further processing is carried out by Facebook. The agreement on joint processing can be viewed here: Link to the agreement.
Data transfer may occur to the USA, with Meta Platforms relying on the EU-US Data Privacy Framework and applying the standard contractual clauses of the EU Commission.
The data usually come from the data subject and may include browser information, accessed content, device information, geographical location, interactions with advertisements and products, IP address, pixel ID, referrer URL, usage data, user behavior, Facebook user ID, device operating system, device ID, HTTP headers, clicked elements, accessed pages, Facebook cookie information, page/click behavior, user agent, and browser type.
Further information can be found in Meta's privacy policy at Link to the privacy policy. For any further questions, you can contact the provider's data protection officer via this link.
Reddit Pixel
Our website uses the visitor action pixel from Reddit for conversion measurement. This enables the tracking of the behavior of website visitors who arrive on our website by clicking on a Reddit advertisement. This allows us to analyze the effectiveness of Reddit advertisements for statistical and market research purposes and optimize future advertising measures. The legal basis for this processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG.
The data transfer may take place to the USA, whereby Reddit, Inc., 548 Market St, Ste 16093, San Francisco, CA 94104, relies on the EU-US Data Privacy Framework and applies the EU Commission’s Standard Contractual Clauses.
The data generally originates from the data subject and may include browser information, accessed content, device information, geographic location, interactions with advertisements and products, IP address, pixel ID, referrer URL, usage data, user behavior, Facebook user ID, device operating system, device ID, HTTP headers, clicked elements, accessed pages, Reddit cookie information, page/click behavior, user agent, and browser type.
For further information, please refer to Reddit’s privacy policy at link to the privacy policy. If you have any additional questions, you can contact the provider’s data protection officer at dpo@reddit.com.
Microsoft Clarity
Our website uses Clarity for optimization, analysis, and marketing. The processing of this data is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR.
Your data may be transferred to Microsoft Ireland Operations Limited, Attn: Data Protection Officer, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Any potential transfer, storage, and processing in the USA is carried out on the basis of the EU Commission’s Standard Contractual Clauses and the EU-US Data Privacy Framework (DPF), for which Microsoft Corporation is certified.
The duration of data storage is determined by the general data deletion periods.
The data generally originates directly from the data subject. The categories of personal data include IP address, date and time of visit, unique user ID, session ID, user behavior, interaction data, mouse movements, clicks, and scrolling activity.
The provider’s data protection officer can be contacted at clarityms@microsoft.com. Further information on data processing by Microsoft can be found here: https://clarity.microsoft.com/privacy.