{"id":13094,"date":"2026-07-02T14:12:45","date_gmt":"2026-07-02T12:12:45","guid":{"rendered":"https:\/\/compeso.com\/privacy-policy\/"},"modified":"2026-07-25T14:17:39","modified_gmt":"2026-07-25T12:17:39","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/compeso.com\/en\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"13094\" class=\"elementor elementor-13094 elementor-10677\" data-elementor-post-type=\"page\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2b77a954 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2b77a954\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-19aae3e\" data-id=\"19aae3e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1b2c86ce elementor-widget elementor-widget-text-editor\" data-id=\"1b2c86ce\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h1>Privacy Policy<\/h1>\n<p><strong>Last updated: 21 July 2026<\/strong><\/p>\n<p>This privacy policy provides information about the processing of personal data when using the compeso.com website, including the pages, language versions and protected areas available there.<\/p>\n<h1>1. Controller<\/h1>\n<p>The controller responsible for the processing of personal data on this website is:<\/p>\n<p><strong>COMPESO Computerperipherie und Software GmbH<\/strong><br>Carl-Zeiss-Ring 9<br>85737 Ismaning<br>Germany<\/p>\n<p>Phone: +49 89 969797-0<br>Email: info@compeso.com<\/p>\n<p>Further information about the company can be found in our legal notice.<\/p>\n<h1>2. Data protection contact<\/h1>\n<p>The following contact is available for data protection enquiries:<\/p>\n<p><strong>Maurice Hartmann<\/strong><\/p>\n<p>Data Privacy Consultant<\/p>\n<p>Phone: +49 611 94588190<\/p>\n<p>Mobile: +49 611 94588186<\/p>\n<p>Email \/ Teams: maurice.hartmann@sits.com<\/p>\n<p>Web: www.sits.com<\/p>\n<p>SITS Deutschland GmbH<\/p>\n<p>Krefelder Stra\u00dfe 121, 52070 Aachen<\/p>\n<h1>3. General information on data processing<\/h1>\n<p>We process personal data only insofar as this is necessary for the operation and security of our website, the handling of enquiries, the provision of a protected customer or member area, technical communication with you or to fulfil legal obligations, or where you have consented to processing.<\/p>\n<p>Depending on the processing, the following legal bases in particular may apply: Art. 6(1)(a) GDPR, where you have consented to processing; Art. 6(1)(b) GDPR, where the processing is necessary to carry out pre-contractual measures or to perform a contract; Art. 6(1)(c) GDPR, where we are subject to a legal obligation; and Art. 6(1)(f) GDPR, where the processing is necessary to safeguard our legitimate interests or those of third parties and your interests or fundamental rights do not override them.<\/p>\n<p>Our legitimate interests lie in particular in the secure, stable and user-friendly operation of the website, in the prevention of abuse, spam and attacks, in technical error analysis, in communication with prospects and customers, and in the optimisation of our online offering.<\/p>\n<h1>4. Accessing the website, hosting and server logs<\/h1>\n<p>The website is hosted by Hetzner. According to the current technical configuration, the website and server logs are processed in Germany.<\/p>\n<p>When our website is accessed, the web server automatically processes technical access data. This may include in particular: IP address, date and time of access, accessed URL, referrer URL, browser and user agent used, operating system, status code, amount of data transferred as well as error and security information.<\/p>\n<p>According to the current technical configuration, HTTP access logs in JSON format, PHP errors of the WordPress pool, database errors, banned IP addresses or blocking events as well as entries in a central logging system are processed in particular. The processing takes place for the technical provision of the website, for error analysis, to ensure stability and security, and to detect and defend against attacks.<\/p>\n<p>The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and trouble-free operation of our website.<\/p>\n<p>The visitor-related server logs are stored in the central logging system for up to 1 year.<\/p>\n<h2>4.1 Cloudflare (proxy, CDN, tunnel, security and web analytics)<\/h2>\n<p>To provide and secure our website we use services from Cloudflare. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, as well as the respective competent Cloudflare company. Traffic is routed through Cloudflare and transmitted to our web server via an encrypted Cloudflare Tunnel. Cloudflare serves in particular as a DNS and reverse proxy service, content delivery network (CDN), protection against DDoS attacks and automated access as well as for the detection of technical faults.<\/p>\n<p>In doing so, Cloudflare processes in particular the IP address, date and time of access, accessed URL, referrer, HTTP headers, browser and device information, amount of data transferred, location of the processing data centre, Cloudflare Ray ID as well as security and challenge results. Depending on the security check, Cloudflare may set technically necessary cookies, in particular <code>cf_clearance<\/code> as proof of a successfully passed security check and <code>__cf_bm<\/code> for bot detection. These cookies are not used for advertising or cross-site tracking.<\/p>\n<p>In addition, Cloudflare Real User Monitoring (RUM) \/ Web Analytics is integrated. For this, the browser loads a script from <code>static.cloudflareinsights.com<\/code> and transmits performance data to the endpoint <code>\/cdn-cgi\/rum<\/code>. This may include in particular page and referrer URL, load and rendering times, navigation and resource timings as well as a random page-view ID. According to Cloudflare, the RUM script does not access cookies, local storage or session storage; the IP address that technically arises during transmission is discarded at the nearest Cloudflare data centre and not stored in the central RUM databases or logs.<\/p>\n<p>The processing takes place for the secure, fast and stable provision of the website as well as to measure and improve its technical performance. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in protection against attacks, in fail-safe delivery and in the technical optimisation of our online offering. Insofar as Cloudflare stores or reads technically necessary cookies, this takes place on the basis of \u00a7 25(2) no. 2 TDDDG.<\/p>\n<p>Cloudflare may also process data outside the EU or the EEA, in particular in the USA. Where necessary, transfers are based on the certification under the EU-US Data Privacy Framework and, additionally, on the EU standard contractual clauses. Further information: https:\/\/www.cloudflare.com\/policies\/privacy\/ and https:\/\/developers.cloudflare.com\/fundamentals\/reference\/policies-compliances\/cloudflare-cookies\/.<\/p>\n<h1>5. Cookies, local storage, session storage and consent management<\/h1>\n<p>Our website uses cookies as well as comparable technologies such as local storage and session storage. These technologies may be necessary to technically provide the website, implement security functions, store the selected language and consent decision, or enable reach measurement and analytics after consent.<\/p>\n<p>We use strictly technically necessary cookies and storage technologies on the basis of \u00a7 25(2) no. 2 TDDDG. The subsequent processing of personal data takes place, depending on the purpose, on the basis of Art. 6(1)(c) or (f) GDPR. We use technologies that are not technically necessary only after prior consent pursuant to \u00a7 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent given can be withdrawn or changed at any time with effect for the future via the cookie settings.<\/p>\n<h2>5.1 Consent management with CookieYes<\/h2>\n<p>To obtain, manage and document consents we use CookieYes. The provider is CookieYes Limited, 3 Warren Yard Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom. CookieYes is loaded on the first page view so that the consent banner can be displayed and the choice can be technically implemented.<\/p>\n<p>In the process, configuration, translation and banner files are retrieved from CookieYes. In addition, a technical event for loading the banner is transmitted to CookieYes. In particular, a pseudonymous consent ID, consent status and categories, timestamp, website identifier, accessed page or referrer, IP address as well as browser and device information may be processed. The necessary cookie <code>cookieyes-consent<\/code> stores the consent ID and the choice made. According to the current configuration, CookieYes stores the choice for up to one year.<\/p>\n<p>The processing serves to fulfil our data protection documentation and organisational obligations as well as the reliable operation of the consent management. The legal bases are Art. 6(1)(c) and (f) GDPR; the storage of the consent decision takes place pursuant to \u00a7 25(2) no. 2 TDDDG. Our legitimate interest lies in a verifiable, user-friendly and technically uniform management of consents. A data processing agreement is in place with CookieYes. For the United Kingdom there is an adequacy decision of the European Commission.<\/p>\n<h2>5.2 Currently identified and situational cookies and browser storage<\/h2>\n<div style=\"max-width:100%; overflow-x:auto; -webkit-overflow-scrolling:touch;\">\n<table style=\"min-width:900px;\">\n<thead><tr><th>Name<\/th><th>Provider\/domain<\/th><th>Purpose<\/th><th>Storage period<\/th><th>Classification<\/th><\/tr><\/thead>\n<tbody>\n<tr><td><code>cookieyes-consent<\/code><\/td><td>CookieYes \/ compeso.com<\/td><td>Stores the consent ID, choice and consent categories.<\/td><td>Up to 1 year<\/td><td>Technically necessary<\/td><\/tr>\n<tr><td><code>wp-wpml_current_language<\/code><\/td><td>WPML \/ compeso.com<\/td><td>Stores the current language for language switching and language-dependent AJAX requests.<\/td><td>Browser session<\/td><td>Technically necessary<\/td><\/tr>\n<tr><td><code>_cfuvid<\/code><\/td><td>Cloudflare for Brevo \/ .sibforms.com<\/td><td>Distinguishes visitors behind the same IP address for security and rate-limiting functions of the newsletter form.<\/td><td>Browser session<\/td><td>Security function of the embedded Brevo form<\/td><\/tr>\n<tr><td><code>cf_clearance<\/code><\/td><td>Cloudflare \/ .compeso.com<\/td><td>Stores proof of a passed security check and supports JavaScript-based detections to protect the website.<\/td><td>Depending on the security configuration; up to 1 year in the current technical test<\/td><td>Technically necessary security cookie<\/td><\/tr>\n<tr><td><code>__cf_bm<\/code><\/td><td>Cloudflare \/ .compeso.com<\/td><td>May store an encrypted bot score and a session identifier during a bot check.<\/td><td>30 minutes after the last activity<\/td><td>Situational, technically necessary security cookie<\/td><\/tr>\n<tr><td><code>_ga<\/code><\/td><td>Google Analytics \/ .compeso.com<\/td><td>Distinguishes visitors for reach measurement.<\/td><td>Up to 400 days<\/td><td>Only after consent to analytics<\/td><\/tr>\n<tr><td><code>_ga_TZDGE2Y5T6<\/code><\/td><td>Google Analytics \/ .compeso.com<\/td><td>Stores the session status of the GA4 measurement ID used.<\/td><td>Up to 400 days<\/td><td>Only after consent to analytics<\/td><\/tr>\n<tr><td><code>elementor<\/code> in local storage<\/td><td>Elementor \/ compeso.com<\/td><td>Stores local front-end states, in particular <code>pageViews<\/code> and <code>sessions<\/code>, to control page elements and popup conditions.<\/td><td>Until the browser storage is cleared<\/td><td>Functional browser storage<\/td><\/tr>\n<tr><td><code>elementor<\/code> in session storage<\/td><td>Elementor \/ compeso.com<\/td><td>Stores the status of the active front-end session.<\/td><td>Browser session<\/td><td>Functional browser storage<\/td><\/tr>\n<tr><td><code>wpEmojiSettingsSupports<\/code> in session storage<\/td><td>WordPress \/ compeso.com<\/td><td>Stores the result of a local browser compatibility test for emojis.<\/td><td>Browser session<\/td><td>Technically necessary<\/td><\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>The Elementor and WordPress storage entries are used locally in the browser. According to the current technical review, no direct transmission of these storage contents to Elementor or WordPress could be identified. Insofar as browser storage is required solely for the display and session control of the website you have expressly accessed, it is used on the basis of \u00a7 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. Any further use for analytics or advertising purposes takes place only with consent.<\/p>\n<p>The list displayed in the CookieYes banner supplements this information and may change if services or their technical configuration are adjusted.<\/p>\n<h1>6. Contact form<\/h1>\n<p>On our website we provide a contact form, in particular on the contact page.<\/p>\n<p>The following mandatory information is collected in the contact form: first name, last name, email address, message and confirmation that you have taken note of the data protection information.<\/p>\n<p>The following information can optionally be provided: cinema and the selection of how we can help, e.g. demo, quote or other.<\/p>\n<p>We need the mandatory information in order to assign and answer your enquiry. The confirmation of the data protection information serves as proof that you have been informed about the processing of your data. It does not constitute consent to advertising or newsletter communication.<\/p>\n<p>The contact form is technically processed via Elementor Forms in WordPress. The form data is stored in WordPress. In addition, a notification email is sent to the stored email mailbox. The technical email dispatch takes place via AWS SES.<\/p>\n<p>The processing takes place in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry is aimed at concluding or performing a contract. In all other cases, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper handling of incoming enquiries.<\/p>\n<p>We store the data submitted in the contact form for as long as this is necessary to handle your enquiry. Insofar as statutory retention periods exist or further storage is necessary for the assertion, exercise or defence of legal claims, the data is stored for the duration of these periods.<\/p>\n<h1>7. Email dispatch via AWS SES<\/h1>\n<p>For sending website emails, in particular notifications from contact forms as well as system, registration and login emails, we use Amazon Simple Email Service (AWS SES) via SMTP. The region used is Frankfurt, Germany.<\/p>\n<p>During dispatch, the email address, name, message contents, technical dispatch data as well as delivery, error and log data may be processed in particular. The processing takes place in order to technically send the respective email and to ensure delivery, troubleshooting and system security.<\/p>\n<p>Depending on the content of the communication, the legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR. Our legitimate interest lies in the reliable and secure dispatch of website and system emails.<\/p>\n<p>Dispatch, delivery and error logs relating to AWS SES are stored for up to 1 year.<\/p>\n<p>Insofar as processing outside the EU or the EEA cannot be ruled out within the scope of AWS, it takes place on the basis of appropriate safeguards, in particular adequacy decisions, certifications under the EU-US Data Privacy Framework or EU standard contractual clauses.<\/p>\n<h1>8. Newsletter and Brevo<\/h1>\n<p>For the registration and dispatch of our newsletter we use Brevo. The provider is Brevo GmbH, K\u00f6penicker Stra\u00dfe 126, 10179 Berlin, Germany, or the contractual partner identified in our Brevo account. Brevo processes newsletter data on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place for this purpose.<\/p>\n<h2>8.1 Technical integration of the registration form<\/h2>\n<p>The newsletter form is integrated as a Brevo form into a globally available website popup. According to the current technical configuration, the form is already loaded as external content from the domains <code>b0abc4db.sibforms.com<\/code> and <code>sibforms.com<\/code> when the website is accessed, even if the newsletter popup has not yet been opened and no consent decision has yet been made in the cookie banner.<\/p>\n<p>When loading, a connection to Brevo and the technical service providers used by Brevo is established. In particular, the IP address, referrer URL, time of access, browser and device information as well as the requested form address are transmitted. For the secure provision and rate limiting of the form, the Cloudflare infrastructure used by Brevo sets the cookie <code>_cfuvid<\/code> on the domain <code>.sibforms.com<\/code>. The cookie is used to distinguish individual visitors who use the same public IP address. It is not used by us for advertising or reach-measurement purposes and, according to the current configuration, is stored for up to seven days.<\/p>\n<p>The processing of the technical connection data takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and abuse-protected provision of the newsletter registration form. Insofar as <code>_cfuvid<\/code> is used exclusively for the security and rate-limiting function of the accessed form, we base the storage on \u00a7 25(2) no. 2 TDDDG. The technical integration and the necessity of loading before the form is actively opened are reviewed by us regularly.<\/p>\n<h2>8.2 Newsletter registration and dispatch<\/h2>\n<p>When you register for our newsletter, we use the data provided in the registration form to regularly send you information about our services, products, events, news and offers by email. We collect the email address, first name, last name, company and, optionally, the position. This information is used for dispatch, personal address and assignment in a business context.<\/p>\n<p>The processing takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR. Insofar as the newsletter contains promotional content, it is sent only with prior consent within the meaning of \u00a7 7 UWG.<\/p>\n<p>We use the double opt-in procedure for registration. After registration, a confirmation email is sent. Only after confirmation are you added to the distribution list. To prove consent, we store the time of registration and confirmation as well as the IP address used, insofar as this is technically provided.<\/p>\n<p>The newsletter data is used exclusively for the dispatch and administration of the newsletter and is not passed on to third parties for their own advertising purposes. Consent can be withdrawn at any time with effect for the future via the unsubscribe link in every newsletter or by a message to info@compeso.com. After unsubscribing, we delete the data from the active newsletter distribution list, provided that no statutory retention obligations or legitimate proof obligations conflict with this.<\/p>\n<p>Insofar as we evaluate opens or link clicks, this newsletter performance measurement takes place only on the basis of consent pursuant to Art. 6(1)(a) GDPR.<\/p>\n<p>Brevo and sub-processors used by Brevo may process data outside the EU or the EEA. The safeguards described in section 17 apply to such transfers.<\/p>\n<h1>9. User accounts, login and protected customer area<\/h1>\n<p>Our website has a protected login or customer and member area. This is located within the compeso.com domain and is not operated via a separate subdomain.<\/p>\n<p>The WordPress plugin Ultimate Member is used to manage the login and member area. In connection with registration, login and account management, the username, email address, encrypted password and the profile data required for the user account may be processed in particular.<\/p>\n<p>In addition, technically necessary data may be processed, such as IP address, registration time, login times, activation data, security events and technical log data, insofar as this is required by WordPress, Ultimate Member or security functions.<\/p>\n<p>Profiles and user data are not publicly visible and cannot be viewed by other users. Uploads by users are not provided for.<\/p>\n<p>The processing takes place to provide and manage the protected area. The legal basis is Art. 6(1)(b) GDPR insofar as the user account is necessary for the performance of a contractual or pre-contractual relationship. For technical security and log data, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure operation of the protected area and in preventing unauthorised access.<\/p>\n<p>User accounts are managed manually. There is no automatic deactivation or deletion due to inactivity. Users can delete their account themselves. Otherwise, we delete user accounts when they are no longer required for the purposes for which they were set up and no statutory retention periods or legitimate interests conflict with further storage.<\/p>\n<h1>10. Security services, Wordfence, WPS Hide Login and spam protection<\/h1>\n<p>To protect our website we use security and spam protection functions. These include in particular Wordfence Security, WPS Hide Login, Google reCAPTCHA and a honeypot spam protection.<\/p>\n<h2>10.1 Wordfence Security<\/h2>\n<p>We use Wordfence Security for firewall and login protection functions. Wordfence may process security-relevant data, in particular IP address, user agent, login attempts, blocking events, security-relevant accesses and technical log data. The service may also use cookies or comparable storage technologies.<\/p>\n<p>The processing takes place to detect and defend against attacks, brute-force attempts, abusive accesses and other security risks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, our systems and the data processed via the website.<\/p>\n<p>Insofar as Wordfence uses technically necessary cookies or comparable technologies, this takes place on the basis of \u00a7 25(2) no. 2 TDDDG. In all other cases, information is stored or accessed on your device only on the basis of your consent.<\/p>\n<p>The storage period of the security data depends on the Wordfence settings.<\/p>\n<h2>10.2 WPS Hide Login<\/h2>\n<p>We use WPS Hide Login to better protect the login area of the website technically against automated attacks. Technical access data may be processed in the process, insofar as this is necessary to provide and secure the login area.<\/p>\n<p>The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in securing the website and reducing abusive login attempts.<\/p>\n<h2>10.3 Honeypot spam protection<\/h2>\n<p>In addition, we use a honeypot spam protection on forms. This detects automated bot entries without users having to actively solve a captcha. The processing takes place to prevent spam and abuse.<\/p>\n<p>The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our forms from spam, automated use and abusive requests.<\/p>\n<h1>11. Google reCAPTCHA<\/h1>\n<p>On pages with forms we use Google reCAPTCHA. reCAPTCHA is used to check whether entries in forms are made by humans or automated programs. This protects our website from spam, abuse and automated attacks.<\/p>\n<p>Google reCAPTCHA is loaded when form pages are accessed. When using reCAPTCHA, the IP address, browser and device information, accessed URL, referrer, time of access, mouse movements, keyboard entries, interaction data as well as cookies or comparable technologies may be processed in particular.<\/p>\n<p>The legal basis for the processing of personal data is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our forms and systems from spam, abuse and automated access.<\/p>\n<p>Insofar as reCAPTCHA stores or reads information on your device and this is technically necessary to secure the form function, this takes place on the basis of \u00a7 25(2) no. 2 TDDDG. In all other cases, information is stored or accessed on your device only on the basis of your consent pursuant to \u00a7 25(1) TDDDG and Art. 6(1)(a) GDPR.<\/p>\n<p>Processing by Google may also take place outside the EU or the EEA. Where necessary, the transfer takes place on the basis of appropriate safeguards, in particular adequacy decisions, a certification under the EU-US Data Privacy Framework or EU standard contractual clauses.<\/p>\n<h1>12. Google Analytics 4 and Google Consent Mode<\/h1>\n<p>We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics 4 is integrated directly via the Google tag <code>gtag.js<\/code> with its own measurement ID; a Google Tag Manager container is not used for this.<\/p>\n<h2>12.1 Behaviour before a consent decision<\/h2>\n<p>Our website uses the advanced Google Consent Mode. CookieYes initially sets the consent states for analytics, advertising, personalisation and functional storage to <code>denied<\/code>. Nevertheless, on the first page view the Google tag is already loaded from <code>www.googletagmanager.com<\/code>. This creates a connection to Google before a choice is made in the cookie banner. In particular, the IP address, referrer, accessed URL, time, browser and device information as well as the set consent status may be processed.<\/p>\n<p>As long as <code>analytics_storage<\/code> and <code>ad_storage<\/code> are set to <code>denied<\/code>, no Google Analytics or advertising cookies may be read or written. However, Google points out that in advanced Consent Mode, cookieless signals and measurement events may be transmitted for aggregated statistical and modelling purposes. These signals may contain the consent status and technical information about the page view.<\/p>\n<p>The processing of the technical connection and consent data before analytics consent is granted takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the technical control of the consent states and in a data-minimising, consent-controlled reach measurement. In doing so, we take into account that no analytics cookies are used before consent and that the consent states are denied by default.<\/p>\n<h2>12.2 Analytics after consent<\/h2>\n<p>Only after consent to the &#8220;Analytics&#8221; category are the corresponding consent signals set to <code>granted<\/code>. Google Analytics 4 can then process in particular page views, interactions, events, session data, usage duration, referrer, approximate location, browser and device information as well as cookie and device identifiers. The evaluation serves reach measurement and the improvement of our online offering.<\/p>\n<p>The legal basis for the analytics and for the storage or reading of non-essential cookies and identifiers is consent pursuant to Art. 6(1)(a) GDPR and \u00a7 25(1) TDDDG. Consent can be withdrawn at any time with effect for the future via the cookie settings.<\/p>\n<p>Data retention in Google Analytics 4 is 14 months according to the current configuration. Google Signals, Advertising Features, User ID, Google Ads, remarketing and conversion tracking are not used according to the current configuration.<\/p>\n<p>Google may also process data outside the EU or the EEA, in particular in the USA. Insofar as data is transferred to Google LLC in the USA, this takes place \u2013 provided the respective requirements are met \u2013 on the basis of the certification under the EU-US Data Privacy Framework and, additionally, on the basis of the EU standard contractual clauses of 2021.<\/p>\n<h1>13. External content, fonts, libraries and embedded services<\/h1>\n<p>The fonts used on our website are loaded locally from our own server. No fonts are loaded subsequently from Google Fonts or other external font providers.<\/p>\n<h2>13.1 Other external services<\/h2>\n<p>The external services used are in particular Cloudflare, CookieYes, Brevo, Google Analytics 4 and Google reCAPTCHA. CookieYes and the Google tag for the advanced Consent Mode are loaded on all pages. According to the current technical configuration, the Brevo newsletter form is also already loaded on the initial page view. Google reCAPTCHA is used on pages with correspondingly protected forms.<\/p>\n<p>Depending on the service, the IP address, browser and device information, accessed URL, referrer, timestamp as well as technically necessary cookie, consent and session data may be processed in particular. Details can be found in the respective sections of this privacy policy.<\/p>\n<p>As things currently stand, no externally embedded videos, maps, social media feeds, chats, appointment booking systems or review widgets are integrated.<\/p>\n<h1>14. SEO tools and Google Search Console<\/h1>\n<p>We use Yoast SEO and Google Search Console exclusively for administrative purposes in the backend. In the frontend, these tools do not load any scripts, pixels, cookies or other technologies for visitors and do not transmit any visitor data to third parties via the frontend.<\/p>\n<p>Google Analytics 4 is treated separately from this. Within the scope of the advanced Consent Mode described in section 12, the Google tag is loaded on the first page view with initially denied consent states. Cookie-based analytics only takes place after consent to the &#8220;Analytics&#8221; category.<\/p>\n<h1>15. Social media and LinkedIn share buttons<\/h1>\n<p>Our website contains ordinary links to social media profiles as well as LinkedIn share buttons on news and event pages. According to the current technical configuration, no LinkedIn Insight Tag, no social media feed and no other social media tracking script is used.<\/p>\n<p>Insofar as social media links or share buttons are implemented as pure links, no personal data is transmitted to the respective social networks when our website is merely accessed. Only when you click on such a link or share button do you leave our website or is a connection to the respective provider established. The respective provider is responsible for the subsequent processing.<\/p>\n<p>The legal basis for providing the links and share functions is Art. 6(1)(f) GDPR. Our legitimate interest lies in the visibility of our content and the user-friendly ability to share content.<\/p>\n<h1>16. Recipients of personal data<\/h1>\n<p>Depending on how the website is used, personal data may be transmitted to the following categories of recipients: hosting and IT service providers, security and CDN service providers, consent management service providers, email and newsletter service providers, providers of analytics and spam protection services, internal responsible bodies as well as external advisors or authorities, insofar as this is legally required.<\/p>\n<p>Specifically, according to the current technical configuration, the following recipients or services in particular are relevant: Hetzner, Cloudflare, CookieYes Limited, AWS SES, Brevo, Google Ireland Limited or Google LLC, Wordfence as well as the systems and plugins used within the WordPress website: Elementor Forms, WPML, Ultimate Member, Wordfence Security and WPS Hide Login.<\/p>\n<p>Insofar as service providers process personal data on our behalf, we conclude the necessary data processing agreements and review the sub-processors used as well as the requirements for possible third-country transfers.<\/p>\n<h1>17. Third-country transfers<\/h1>\n<p>Some of the service providers used or their sub-processors may process personal data outside the European Union or the European Economic Area, in particular in the United Kingdom or the USA.<\/p>\n<p>For the United Kingdom there is an adequacy decision pursuant to Art. 45 GDPR, renewed by the European Commission in December 2025. Data transfers to providers in the United Kingdom can therefore be based on this adequacy decision.<\/p>\n<p>For transfers to the USA we rely, insofar as the specific recipient is effectively certified, on the EU-US Data Privacy Framework. Insofar as no applicable adequacy decision or sufficient certification exists, we use appropriate safeguards, in particular the EU standard contractual clauses adopted by the European Commission in 2021 pursuant to Art. 46(2)(c) GDPR. Where necessary, we review supplementary technical and organisational measures.<\/p>\n<p>A third-country transfer only takes place insofar as the requirements of Art. 44 et seq. GDPR are met. The safeguards used in each case depend on the specific service, contractual partner and processing route.<\/p>\n<h1>18. Storage period<\/h1>\n<p>We store personal data only for as long as this is necessary for the respective purposes. After that, the data is deleted, provided that no statutory retention obligations exist or we have a legitimate interest in further storage, for example for the assertion, exercise or defence of legal claims.<\/p>\n<p>For individual areas, the following periods or criteria in particular apply according to the current technical configuration:<\/p>\n<ul>\n<li>Server and security logs are stored in the central logging system for up to 1 year.<\/li>\n<li>Dispatch, delivery and error logs relating to AWS SES are stored for up to 1 year.<\/li>\n<li>Contact form data is stored for the handling of the enquiry and subsequently in accordance with statutory retention periods or legitimate proof interests.<\/li>\n<li>User accounts exist until they are deleted or are no longer required for the respective purpose.<\/li>\n<li>The cookie <code>cookieyes-consent<\/code> and the associated consent decision are stored for up to 1 year according to the current CookieYes configuration.<\/li>\n<li>The WPML language cookie <code>wp-wpml_current_language<\/code> is stored for the browser session.<\/li>\n<li>The cookie set by the Brevo\/Cloudflare infrastructure <code>_cfuvid<\/code> is stored for the browser session.<\/li>\n<li>Cloudflare security cookies are stored depending on the situation: <code>cf_clearance<\/code> up to 1 year according to the current technical review, <code>__cf_bm<\/code> up to 30 minutes after the last activity.<\/li>\n<li>The Google Analytics cookies <code>_ga<\/code> and <code>_ga_TZDGE2Y5T6<\/code> are stored for up to 400 days after analytics consent.<\/li>\n<li>Elementor data in local storage remains until the browser storage is cleared; entries in session storage are deleted at the end of the browser session.<\/li>\n<li>Security data in Wordfence is stored in accordance with the Wordfence settings.<\/li>\n<li>Analytics data in Google Analytics 4 is stored for 14 months according to the current configuration.<\/li>\n<li>Newsletter data is stored until consent is withdrawn or the purpose no longer applies; necessary proof of consent may be retained longer within the framework of statutory limitation and proof obligations.<\/li>\n<\/ul>\n<h1>19. Obligation to provide personal data<\/h1>\n<p>The provision of personal data is in principle neither legally nor contractually required. For certain functions, however, provision is necessary.<\/p>\n<p>If you would like to use our contact form, we need the information marked as mandatory fields in order to process your enquiry. Without this information, we cannot answer your enquiry or can only answer it to a limited extent.<\/p>\n<p>If you would like to use a protected customer or member area, we need the data required for the user account. Without this information, a user account cannot be provided or managed.<\/p>\n<p>Technically necessary data is processed in order to provide the website securely and functionally.<\/p>\n<h1>20. No automated decision-making<\/h1>\n<p>Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.<\/p>\n<h1>21. Your rights<\/h1>\n<p>Within the framework of the statutory requirements you have the following rights: You can request information about the data stored about you. You can request the rectification of incorrect data. You can request the erasure of your data, provided that no statutory retention obligations or overriding legitimate grounds conflict with this. You can request the restriction of processing. You can receive data that you have provided to us in a structured, commonly used and machine-readable format, provided that the requirements for data portability are met.<\/p>\n<p>Insofar as processing is based on your consent, you can withdraw this consent at any time with effect for the future. The lawfulness of the processing up to the withdrawal remains unaffected.<\/p>\n<p>Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR, you can object to the processing on grounds relating to your particular situation.<\/p>\n<p>You also have the right to lodge a complaint with a data protection supervisory authority. In particular, you can contact the supervisory authority of your habitual residence, your place of work or the place of the alleged data protection violation.<\/p>\n<h1>22. Changes to this privacy policy<\/h1>\n<p>We reserve the right to adapt this privacy policy if the website, the services used, technical processes or legal requirements change. The current version published on this website applies in each case.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Privacy Policy Last updated: 21 July 2026 This privacy policy provides information about the processing of personal data when using the compeso.com website, including the pages, language versions and protected areas available there. 1. Controller The controller responsible for the processing of personal data on this website is: COMPESO Computerperipherie und Software GmbHCarl-Zeiss-Ring 985737 IsmaningGermany [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-13094","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Privacy Policy - Compeso<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/compeso.com\/en\/privacy-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy Policy - Compeso\" \/>\n<meta property=\"og:description\" content=\"Privacy Policy Last updated: 21 July 2026 This privacy policy provides information about the processing of personal data when using the compeso.com website, including the pages, language versions and protected areas available there. 1. Controller The controller responsible for the processing of personal data on this website is: COMPESO Computerperipherie und Software GmbHCarl-Zeiss-Ring 985737 IsmaningGermany [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/compeso.com\/en\/privacy-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"Compeso\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-25T12:17:39+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"25 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/privacy-policy\\\/\",\"url\":\"https:\\\/\\\/compeso.com\\\/en\\\/privacy-policy\\\/\",\"name\":\"Privacy Policy - Compeso\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/#website\"},\"datePublished\":\"2026-07-02T12:12:45+00:00\",\"dateModified\":\"2026-07-25T12:17:39+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/privacy-policy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/compeso.com\\\/en\\\/privacy-policy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/privacy-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Compeso\",\"item\":\"https:\\\/\\\/compeso.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Privacy Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/compeso.com\\\/en\\\/\",\"name\":\"Compeso\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/compeso.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/#organization\",\"name\":\"Compeso\",\"url\":\"https:\\\/\\\/compeso.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/compeso.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Compeso-Logo-Paket-RGB-01-1.svg\",\"contentUrl\":\"https:\\\/\\\/compeso.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Compeso-Logo-Paket-RGB-01-1.svg\",\"width\":1,\"height\":1,\"caption\":\"Compeso\"},\"image\":{\"@id\":\"https:\\\/\\\/compeso.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Privacy Policy - Compeso","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/compeso.com\/en\/privacy-policy\/","og_locale":"en_US","og_type":"article","og_title":"Privacy Policy - Compeso","og_description":"Privacy Policy Last updated: 21 July 2026 This privacy policy provides information about the processing of personal data when using the compeso.com website, including the pages, language versions and protected areas available there. 1. Controller The controller responsible for the processing of personal data on this website is: COMPESO Computerperipherie und Software GmbHCarl-Zeiss-Ring 985737 IsmaningGermany [&hellip;]","og_url":"https:\/\/compeso.com\/en\/privacy-policy\/","og_site_name":"Compeso","article_modified_time":"2026-07-25T12:17:39+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"25 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/compeso.com\/en\/privacy-policy\/","url":"https:\/\/compeso.com\/en\/privacy-policy\/","name":"Privacy Policy - Compeso","isPartOf":{"@id":"https:\/\/compeso.com\/en\/#website"},"datePublished":"2026-07-02T12:12:45+00:00","dateModified":"2026-07-25T12:17:39+00:00","breadcrumb":{"@id":"https:\/\/compeso.com\/en\/privacy-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/compeso.com\/en\/privacy-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/compeso.com\/en\/privacy-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Compeso","item":"https:\/\/compeso.com\/en\/"},{"@type":"ListItem","position":2,"name":"Privacy Policy"}]},{"@type":"WebSite","@id":"https:\/\/compeso.com\/en\/#website","url":"https:\/\/compeso.com\/en\/","name":"Compeso","description":"","publisher":{"@id":"https:\/\/compeso.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/compeso.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/compeso.com\/en\/#organization","name":"Compeso","url":"https:\/\/compeso.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/compeso.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/compeso.com\/wp-content\/uploads\/2026\/02\/Compeso-Logo-Paket-RGB-01-1.svg","contentUrl":"https:\/\/compeso.com\/wp-content\/uploads\/2026\/02\/Compeso-Logo-Paket-RGB-01-1.svg","width":1,"height":1,"caption":"Compeso"},"image":{"@id":"https:\/\/compeso.com\/en\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/pages\/13094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/comments?post=13094"}],"version-history":[{"count":1,"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/pages\/13094\/revisions"}],"predecessor-version":[{"id":13095,"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/pages\/13094\/revisions\/13095"}],"wp:attachment":[{"href":"https:\/\/compeso.com\/en\/wp-json\/wp\/v2\/media?parent=13094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}