privacy policy

preamble
with the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") we process, for what purposes, and to what extent. this privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offer").

the terms used are not gender-specific.

 

status: july 19, 2026

 

table of contents
•    preamble
•    controller
•    overview of processing operations
•    relevant legal bases
•    security measures
•    transmission of personal data
•    international data transfers
•    general information on data storage and erasure
•    rights of the data subjects
•    business services
•    use of cookies
•    changes and updates
•    definitions of terms

 

controller
menze-media
michael menze
tucholskystr. 11
63303 dreieich
germany

 

persons authorized to represent: michael menze
email address: info@menze-media.de
imprint: www.menze-media.de

 

overview of processing operations
the following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

 

types of data processed
•    master data.
•    payment data.
•    contact data.
•    contract data.
•    meta, communication, and process data.

 

categories of data subjects
•    service recipients and clients.
•    interested parties.
•    users.
•    business and contractual partners.

 

purposes of processing
•    provision of contractual services and fulfillment of contractual obligations.
•    communication.
•    office and organizational procedures.
•    organizational and administrative procedures.
•    business processes and operational procedures.

 

relevant legal bases
relevant legal bases under the gdpr: below you will find an overview of the legal bases of the gdpr on which we process personal data. please note that in addition to the regulations of the gdpr, national data protection regulations may apply in your or our country of residence or domicile. if more specific legal bases are relevant in individual cases, we will inform you of them in this privacy policy.
•    consent (art. 6 (1) (a) gdpr) - the data subject has given consent to the processing of his or her personal data for one or more

specific purposes.
•    performance of a contract and prior inquiries (art. 6 (1) (b) gdpr) - processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
•    legal obligation (art. 6 (1) (c) gdpr) - processing is necessary for compliance with a legal obligation to which the controller is subject.
•    legitimate interests (art. 6 (1) (f) gdpr) - processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject

 

which require protection of personal data.

national data protection regulations in germany: in addition to the data protection regulations of the gdpr, national regulations on data protection apply in germany. this includes, in particular, the federal data protection act (bundesdatenschutzgesetz – bdsg). the bdsg contains special regulations on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission as well as automated individual decision-making including profiling. furthermore, state data protection laws of the individual federal states may apply.

 

security measures
we take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

the measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access, input, transmission, securing availability, and separation of data. furthermore, we have established procedures to ensure the exercise of data subject rights, the erasure of data, and rapid responses to data threats. furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures in accordance with the principle of data protection by design and by default.

securing online connections through tls/ssl encryption technology (https): in order to protect user data transmitted via our online services from unauthorized access, we use tls/ssl encryption technology. secure sockets layer (ssl) and transport layer security (tls) are the cornerstones of secure data transmission on the internet. these technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. tls, as the further developed and more secure version of ssl, ensures that all data transmissions meet the highest security standards. when a website is secured by an ssl/tls certificate, this is indicated by the display of https in the url. this serves as an indicator to users that their data is transmitted securely and encrypted.

 

transmission of personal data
in the context of our processing of personal data, it may happen that the data is transferred to other offices, companies, legally independent organizational units, or persons, or disclosed to them. recipients of this data may include, for example, it service providers commissioned with it tasks or providers of services and content integrated into a website. in such cases, we comply with legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.

 

international data transfers
data processing in third countries: if we transfer data to a third country (i.e., outside the european union (eu) or the european economic area (eea)) or if this occurs in the context of using third-party services or disclosing or transferring data to other persons, offices, or companies (which becomes recognizable by the postal address of the respective provider or if explicitly mentioned in this privacy policy), this is always done in accordance with legal requirements.

for data transfers to the usa, we primarily rely on the data privacy framework (dpf), which was recognized as a secure legal framework by an adequacy decision of the eu commission dated july 10, 2023. in addition, we have concluded standard contractual clauses (scc) with the respective providers, which comply with the requirements of the eu commission and establish contractual obligations to protect your data.

this double safeguarding ensures comprehensive protection of your data even when processed abroad.

general information on data storage and erasure
we erase personal data that we process in accordance with legal requirements as soon as the consent granted for processing is revoked or other permissions cease to apply (e.g., if the purpose of processing this data no longer applies or it is not required for the purpose). if the data is not erased because it is required for other and legally permissible purposes, its processing is restricted to these purposes. this means that the data is blocked and not processed for other purposes. this applies, for example, to data that must be retained for commercial or tax reasons or whose storage is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person.

our privacy notices may also contain further information on the retention and erasure of data, which take precedence for the respective processing operations.

 

rights of the data subjects
as a data subject under the gdpr, you have various rights, which arise in particular from articles 15 to 21 of the gdpr:
•    right to object: you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (e) or (f) of article 6(1) gdpr, including profiling based on those provisions. if your personal data is processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
•    right of withdrawal for consents: you have the right to withdraw any consent given at any time.
•    right of access: you have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and to receive access to this data and further information in accordance with legal requirements.
•    right to rectification: you have the right to demand the completion or rectification of inaccurate personal data concerning you.
•    right to erasure and restriction of processing: you have the right to demand that personal data concerning you be erased immediately, or alternatively, to demand a restriction of processing in accordance with legal requirements.
•    right to data portability: you have the right to receive personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format or to demand its transmission to another controller.
•    complaint to a supervisory authority: in accordance with legal requirements, you also have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the gdpr.

 

business services
we process data of our contractual and business partners, e.g., clients and interested parties (collectively referred to as "contractual partners"), within the scope of contractual and comparable legal relationships as well as associated measures and communication.

we process this data to fulfill our contractual obligations. this includes, in particular, the obligation to provide the agreed services, any update obligations, and remedies in the event of warranty and other service disruptions. in addition, we process the data to safeguard our rights and for the purpose of administrative tasks associated with these obligations and business organization. furthermore, we process the data on the basis of our legitimate interests in proper and business-like management as well as security measures to protect our contractual partners and our business operations from misuse.

•    processed data types: master data; payment data; contact data; contract data.
•    data subjects: service recipients, clients, interested parties, business partners.
•    purposes of processing: contractual services, communication, administrative and organizational procedures.
•    legal bases: performance of a contract and prior inquiries (art. 6 (1) (b) gdpr); legal obligation (art. 6 (1) (c) gdpr); legitimate interests (art. 6 (1) (f) gdpr).

 

use of cookies
cookies are small text files, or other storage tags, that store information on end devices and read information from the end devices. for example, to store the login status in a user account, the shopping cart contents in an e-shop, the accessed contents or used functions of an online offer. cookies can also be used for various purposes, e.g., for purposes of functionality, security and comfort of online offers as well as the creation of analyses of visitor flows.

notes on consent: we only use cookies in accordance with legal regulations. therefore, we obtain prior consent from users, except when consent is not required by law. in particular, consent is not required if the storage and reading of information, including cookies, are absolutely necessary to provide the users with a telemedia service (i.e., our online offer) explicitly requested by them.

•    legal bases: legitimate interests (art. 6 (1) (f) gdpr).

 

changes and updates
we ask you to inform yourself regularly about the content of our privacy policy. we will adapt the privacy policy as soon as changes in the data processing carried out by us make this necessary. we will inform you as soon as the changes require an act of cooperation on your part (e.g., consent) or other individual notification.

if we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and we ask you to check the information before contacting them.

 

definitions of terms
this section provides an overview of the terms used in this privacy policy to help you understand them better.
•    personal data: "personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
•    controller: the "controller" is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
•    processing: "processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
 

created with free privacy-generator.de by dr. thomas schwenke