Privacy Policy

1. Introduction

The protection of your personal data is a top priority. This privacy policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as "Data") in connection with our online offering. This includes the associated website, functions, and content, as well as external online presences, such as social media profiles (hereinafter collectively referred to as "Online Offering"). Your personal data will be treated confidentially and strictly in accordance with statutory data protection regulations and the provisions of this privacy policy.

General Information

This privacy policy provides you with a comprehensive overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to personally identify you. For detailed information on data protection, please refer to this complete privacy policy.

Responsible Party (Controller)

Data processing on this website is carried out by the website operator. The contact details of the controller can be found in the "Controller" section of this privacy policy.

Data Collection

Your personal data is collected when you actively provide it to us, e.g., by filling out a contact form. Other data is collected automatically or after your consent when you visit the website through our IT systems. This primarily involves technical data (e.g., internet browser, operating system, or time of the page request). This data collection occurs automatically as soon as you enter the website.

Use of Your Data

Part of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior in order to optimize our offering and adapt it to your needs.

Data Transfer to External Parties

As part of the controller's business activities, it may be necessary to transfer personal data to external parties. This transfer takes place exclusively under certain conditions: if the transfer is necessary for the performance of a contract, if there is a legal obligation, for example to tax authorities, if there is a legitimate interest according to Art. 6(1)(f) GDPR, or if another legal basis permits the data transfer. When using external service providers for data processing, the disclosure of personal data takes place exclusively on the basis of a valid data processing agreement in accordance with Art. 28 GDPR. If there is joint processing of data with other parties, a joint controllership agreement in accordance with Art. 26 GDPR will be concluded.

Revocation of Consent to Data Processing

Certain data processing operations can only take place with your explicit consent. You can revoke this consent at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Object to Specific Data Processing and Direct Marketing (Art. 21 GDPR)

If the processing of your personal data is based on Art. 6(1)(e) or (f) GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions. The specific legal basis for the data processing can be found in this privacy policy. If you object, the controller will no longer process your personal data unless compelling legitimate grounds for the processing can be demonstrated that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims (objection pursuant to Art. 21(1) GDPR). If your personal data is used for direct marketing purposes, you have the right to object to this processing at any time. This also applies to profiling insofar as it is connected with such direct marketing. Following your objection, the controller will no longer use your personal data for these marketing purposes (objection pursuant to Art. 21(2) GDPR).

Rights Under the General Data Protection Regulation (GDPR)

You have the right to lodge a complaint with a competent supervisory authority in the event of violations of the GDPR. This right can be exercised in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. Other administrative or judicial remedies remain unaffected. Personal data that is processed automatically on the basis of consent or for the performance of a contract can be requested in a structured, commonly used, and machine-readable format. Upon request, this data can also be transmitted directly to another controller, provided this is technically feasible. Every data subject has the right to receive free information about their stored personal data, its origin, recipients, and the purpose of the data processing. Furthermore, there is a right to rectification or deletion of this data, provided legal provisions permit this. For further questions or concerns regarding personal data, you can contact the controller at any time. You have the right to request the restriction of the processing of personal data if the accuracy of the data is contested and an investigation is pending. Even in the case of unlawful processing, you can request the restriction of data processing instead of deletion. Furthermore, restriction can be requested if the data is no longer needed but is required for the establishment, exercise, or defense of legal claims. In the event of an objection to processing pursuant to Art. 21(1) GDPR, until it is clarified whose interests prevail, there is also a right to restriction. If personal data is restricted in processing, it may, apart from storage, only be processed with the consent of the data subject or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the EU or a Member State.

2. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Marcus Vonthien
Address: Aldebaranstr. 3, 12529 Schönefeld
Website: webseum.co
E-mail: office@webseum.co

3. Processors

We collaborate with various processors who process data on our behalf. These service providers are contractually obligated to treat the data confidentially and to use it exclusively within the scope of the respective service. Additionally, there are cases where responsibility for data processing is shared jointly with other parties. In such cases, responsibilities are transparently regulated and documented to ensure compliance with data protection requirements.

4. Definitions

To ensure the transparency of this privacy policy and to make it understandable for everyone, we primarily use terms defined in the General Data Protection Regulation (GDPR). The full legal definitions can be found in Art. 4 GDPR. The most important terms in connection with this privacy policy are explained below: Personal Data: This includes any information relating to an identified or identifiable natural person (hereinafter "data subject"). A person is considered identifiable if they can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural, or social identity of that person. Processing: This term encompasses any operation or set of operations performed on personal data, whether or not by automated means. This includes collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction of data. Controller: This is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Processor: A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller. Consent: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them. Website: The website refers to the entire internet offering provided by the controller under a specific URL. This includes all content, information, functions, and services published by the controller that are made accessible to the user via this URL. The website serves as a digital platform for providing information, services, and for interaction between the controller and the users. End Device: An end device is an electronic device capable of accessing the internet and loading web pages. This includes computers, laptops, tablets, and smartphones, among others. These definitions help to better understand the privacy policy and to grasp the meaning of the terms used.

5. Hosting

This website is hosted on the servers of an external service provider to guarantee a reliable and secure use of this online offering. Data processing by the hosting provider takes place pursuant to Art. 6(1)(f) GDPR, as the controller has a legitimate interest in providing a stable and secure website. Should it be necessary to obtain the user's consent (for example, for the use of certain cookies or tracking technologies), the data processing is based on the user's consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TTDSG. You can revoke your consent at any time with effect for the future. The hosting provider is:

dataforest GmbH
Taunusstraße 52
65830 Kriftel
Germany

Details on data processing and data protection can be found in the privacy policy of the hosting provider. You can find it here: https://www.dataforest.net/datenschutz

6. Legal Basis for Data Processing

The processing of your personal data takes place on the basis of the General Data Protection Regulation (GDPR) as well as other relevant legal provisions. Depending on the purpose of the data processing, different legal bases apply. If you have consented to the processing of your personal data, this is done on the basis of your consent pursuant to Art. 6(1)(a) GDPR. This applies in particular to the processing of special categories of personal data pursuant to Art. 9(2)(a) GDPR and to the transfer of personal data to third countries pursuant to Art. 49(1)(a) GDPR. Your consent can be revoked at any time. The processing of your data may be necessary for the performance of a contract or for the implementation of pre-contractual measures and in this case takes place on the basis of Art. 6(1)(b) GDPR. Furthermore, processing may be necessary to comply with legal obligations, which then occurs pursuant to Art. 6(1)(c) GDPR. In certain cases, processing takes place to safeguard the legitimate interests of the controller or a third party, provided your interests or fundamental rights and freedoms do not override them. This processing is based on Art. 6(1)(f) GDPR. For certain processing operations, national regulations, such as § 25 TTDSG regarding the storage of cookies or accessing information on your end device, may also apply. The applicable legal bases are explained in detail in the specific sections of this privacy policy. If your data is required for the fulfillment of a contract or the implementation of pre-contractual measures, the processing of your data is based on Art. 6(1)(b) GDPR. For compliance with a legal obligation, data processing is based on Art. 6(1)(c) GDPR. Furthermore, data processing may occur on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR. The specific legal bases in individual cases are explained in the following sections of this privacy policy.

7. Data Transfer to Unsafe Third Countries and Non-DPF Certified US Companies

If tools from companies located in privacy-insecure third countries are used on this website, or if US tools are used whose providers are not certified under the EU-US Data Privacy Framework (DPF), your personal data may be transferred to and processed in these countries. Please note that no level of data protection comparable to that of the EU can be guaranteed in privacy-insecure third countries. For the USA as an insecure third country, a level of data protection comparable to the EU is generally not guaranteed. A data transfer to the USA is therefore only permissible if the recipient either holds a certification under the "EU-US Data Privacy Framework" (DPF) or has suitable additional safeguards. Detailed information on possible transfers to third countries, including data recipients, can be found in this privacy policy.

8. Storage Duration

Unless a more specific storage duration has been specified within this privacy policy, personal data will remain with the controller until the purpose for the data processing no longer applies. If a legitimate request for deletion is asserted or consent to data processing is revoked, the relevant data will be deleted unless there are other legally permissible reasons for storing the personal data (e.g., tax or commercial law retention periods). In these cases, deletion will occur after these reasons no longer apply. The controller stores personal data only as long as is necessary to fulfill the respective purposes for which the data was collected. This includes in particular the fulfillment of contractual obligations, compliance with statutory retention periods, and the safeguarding of the controller's legitimate interests, such as IT security and protection against misuse. If the processing of personal data is based on consent, storage continues until this consent is revoked by the data subject. Such revocation is possible at any time with effect for the future. Thereafter, the data will be deleted immediately, unless there are statutory retention obligations or other overriding legal reasons requiring continued storage. In summary, personal data will be deleted after the purpose has been fulfilled or the legal basis for storage has ceased to exist, unless there are ongoing legal obligations or legitimate interests that justify continued storage.

9. Security Measures and Data Minimization

Comprehensive technical and organizational measures are taken to effectively protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. Care is taken to ensure that only the data absolutely necessary for the respective purpose is collected and processed. This data minimization strategy helps to significantly reduce the risk of misuse and unauthorized access. Security measures are continuously adapted to the state of the art to ensure a permanent, high level of protection for your data.

10. SSL/TLS Encryption

To protect the security of your data during transmission, state-of-the-art encryption methods (e.g., SSL or TLS) are used over HTTPS. SSL (Secure Socket Layer) and TLS (Transport Layer Security) are protocols for encrypting data transmissions on the internet. This ensures that the data exchanged between your browser and the server is protected against unauthorized access. You can recognize an encrypted connection by the browser's address bar changing from "http://" to "https://" and by the lock symbol in your browser bar.

11. Storage of User Information in Log Files

With every access to the website, information of a general nature is automatically collected, which your browser transmits to the server. This information is stored in so-called log files and generally includes: a) IP address of the requesting computer
b) Date and time of access
c) Name and URL of the retrieved file
d) Website from which access is made (Referrer URL)
e) Browser used and User Agent string
f) Operating system
g) Name of your access provider
h) HTTP status code

The storage of this data takes place for security reasons, to ensure a smooth connection setup of the website, to evaluate system security and stability, to defend against attacks (e.g., DDoS attacks), and for other administrative purposes. The legal basis for data processing is Art. 6(1)(f) GDPR. The legitimate interest arises from the stated purposes for data collection. Under no circumstances will the collected data be used for the purpose of drawing conclusions about your person. To ensure data minimization, full IP addresses in the server log files are automatically deleted after a maximum of 7 days or anonymized in such a way that assignment to the calling client is no longer possible.

12. Technically Necessary Cookies

This website uses so-called cookies. These are small text files automatically created by your browser and stored on your end device (laptop, tablet, smartphone, etc.) when you visit the site. Cookies do not harm your end device and contain no viruses or other malicious software. We completely refrain from using tracking, analysis, or advertising cookies on this website. Only strictly technically necessary cookies (e.g., session cookies) are used. These are necessary to provide basic functions of the website, such as maintaining your login status when you log into your user account. These session cookies are generally automatically deleted after you close the browser. The storage of these technically necessary cookies takes place on the basis of § 25(2) TTDSG. The subsequent processing of the data contained in the cookies takes place to safeguard our legitimate interests in the error-free and secure provision of our online offering pursuant to Art. 6(1)(f) GDPR. You can configure your browser so that no cookies are stored on your computer or a warning always appears before a new cookie is created. However, completely disabling cookies will result in you being unable to use core functions of the website (such as the login area).

13. Use of the Contact Form

For questions of any kind, you can contact the controller via a form provided on this website. To know who the request is from and to be able to answer it, the following data must be provided: Name, E-mail address, Description Data processing for the purpose of contacting the controller is carried out pursuant to Art. 6(1)(a) GDPR based on your voluntarily granted consent. The personal data collected for the use of the contact form will be routinely deleted after your request has been resolved.

14. Inquiries by E-Mail or Telephone

It is possible to send inquiries to the controller by e-mail or telephone. The personal data transmitted in this context (e.g., name, e-mail address, phone number, and the request itself) will be processed and stored by the controller exclusively for the purpose of processing the inquiry and any follow-up questions. The legal basis for this data processing is Art. 6(1)(b) GDPR, as the processing is necessary for the performance of a contract or the implementation of pre-contractual measures. If the processing does not relate to a contract, it takes place on the basis of Art. 6(1)(f) GDPR, as the controller has a legitimate interest in processing and answering inquiries.

15. Registration on the Website

It is possible to register on the website. The data entered for this purpose will be used by the controller solely for the purpose of utilizing the respective offering or service for which the registration took place. The mandatory information requested during registration must be provided in full. Otherwise, the registration will be rejected. For important changes, for example in the scope of the offering or technically necessary changes, the controller will use the e-mail address provided during registration to inform you in this manner. The processing of the data entered during registration is carried out for the purpose of establishing and fulfilling a user contract pursuant to Art. 6(1)(b) GDPR. Registration is strictly required to use the core functions of the platform (such as submitting and managing exhibits). The data collected during registration will be stored for as long as you are registered on the website. If you delete your account, this data will be deleted immediately, provided no statutory retention periods stand in the way.

16. Submission and Publication of Content (Exhibits)

As part of using our platform, registered users have the opportunity to submit their own digital projects ("Exhibits") in order to place them in the digital grid (Canvas) of the website. During submission, data such as the name/title of the project, the URL of the website or product, and optionally uploaded images are processed. This data is collected for the purpose of reviewing, assigning, and subsequently publishing the submitted Exhibit on the platform. Please note that the information explicitly provided by you for the Exhibit (title, URL, image material) will be publicly visible worldwide to all visitors on the platform. The legal basis for the processing and publication of this data is the performance of a contract or the implementation of pre-contractual measures pursuant to Art. 6(1)(b) GDPR, as the public presentation of the Exhibits constitutes the main purpose of the user service we provide. The data published within the scope of the Exhibits will remain stored and publicly accessible as long as the Exhibit is listed on the platform or until you, as a user, request the deletion of your account or the specific Exhibit. Statutory retention obligations remain unaffected by this.

17. Links to Other Websites

Due to its nature, this website contains an enormous number of links to other websites. When you click on a third-party link, you will be redirected to that site. Please note that these external sites are not operated or controlled by us in any way. Therefore, we strongly advise you to review the privacy policies of those websites. We have no control over the content, privacy policies, or practices of any linked third-party sites or services and assume no responsibility for them.

Last update: Mai 27, 2026