Hint: This document has been automatically translated from German. The original version in German is legally binding. You can find the version here.
Privacy Policy
Version 5.20.0 of August 26, 2026
I Name and address of the controller
The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is:
UniNow GmbH
DorotheenstraĂźe 10
39104 Magdeburg
Germany
Tel.: +49 391 5054670
Email: info@uninow.de
Website: www.uninow.de
Contact Data Protection
Email: datenschutz@uninow.de
II General information on data processing
1. Scope of processing of personal data
In principle, we only collect and use personal data of our users insofar as this is necessary to provide a functional mobile application as well as our content and services. The collection and use of personal data of our users takes place regularly only with the user’s consent. An exception applies in those cases where prior consent cannot be obtained for actual reasons and the processing of the data is permitted by legal regulations.
2. Legal basis for the processing of personal data
Insofar as we obtain the consent of the data subject for processing operations of personal data, Art. 6 Para. 1 lit. a EU General Data Protection Regulation (GDPR) serves as the legal basis. When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6 Para. 1 lit. b GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures. Insofar as processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Art. 6 Para. 1 lit. c GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 Para. 1 lit. d GDPR serves as the legal basis. If processing is necessary to safeguard a legitimate interest of our company or a third party and if the interests, fundamental rights and freedoms of the data subject do not outweigh the first-mentioned interest, Art. 6 Para. 1 lit. f GDPR serves as the legal basis for processing.
The controller is party to two contractual relationships: one with the respective university or student services organisation concerning the provision and operation of the app, and one with the user themselves concerning the use of the app. The usage agreement between the controller and the user is concluded pursuant to Sec. 1 of the Terms of Use upon commencement of use, at the latest upon registration. Where this privacy policy relies on contractual obligations of the controller, both contractual relationships are meant.
3. Recipients of the data and categories of recipients / disclosure to third parties
Within our company, we ensure that only those persons receive your data who need it to fulfill contractual and legal obligations. In this context, service providers support us in fulfilling these obligations in certain cases. The necessary data protection contracts have been concluded with all these service providers. These are IT service providers, including
- OVH SAS and Stack-IT GmbH (Hosting)
- Mailjet SAS (Mail dispatch)
- Google LLC / Firebase (Push notifications)
Furthermore, your data will only be passed on to third parties (in particular universities) within the framework of legal provisions (e.g. due to mandatory legal regulations to external bodies such as supervisory authorities or law enforcement agencies) or with appropriate consent.
4. Hosting
Servers and databases for the app are hosted in data centers in the EU.
5. Third country transfer / Intention to transfer to third countries
Data transfer to third countries (outside the European Union or the European Economic Area) only takes place if this is necessary for the performance of the contractual relationship, is required by law or you have given us your consent.
Note on Push Service (Firebase Cloud Messaging, Google LLC, USA):
Possible access from the USA is carried out exclusively within the framework of our push service. However, this is only done if you have given your consent. Details on recipients, protective guarantees and your rights can be found in Section VIII “Delivery of push notifications”.
Otherwise, we currently do not transfer your personal data to service providers outside the European Economic Area.
6. Data deletion and storage duration
The personal data of the data subject will be deleted or blocked as soon as the purpose of storage no longer applies. Storage may also take place if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfillment of a contract.
7. Local retrieval of university data
The app retrieves the user’s data from their university portal exclusively on the user’s device — for instance lectures and courses, examinations and grades, library and calendar data. For this purpose the user stores their credentials (username and password) for the university portal in the app. Login, retrieval of the pages and their evaluation all take place on the device; the connection is established directly between the device and the university.
The user’s credentials and the data retrieved in this way are at no time transmitted to the controller, processed on its servers or stored there. The controller has neither access to this data nor knowledge of its content. The only exception is where the user expressly transmits diagnostic data pursuant to Section VI.
The credentials are stored exclusively locally on the device — in the secure storage provided by the operating system (iOS Keychain or Android Keystore) — so that retrieval is possible without re-entering them. Storing the credentials and the retrieved data on the device is strictly necessary for the function of the app expressly requested by the user (Sec. 25 (2) no. 2 TDDDG). The user may end the retrieval at any time by clicking “Disconnect account” in the app’s settings; the locally stored credentials and university data are removed from the device as a result and when the app is deleted.
Where the university instead provides the data via its own interface, login takes place via the university’s own sign-in procedure (single sign-on). The app never receives the user’s password in this case, but only a time-limited access token issued by the university. We then process the university data on behalf of the university (Art. 28 GDPR); the university is the controller and its privacy notice applies. The same applies to further functions we operate on behalf of the university or the student services organisation (e.g. digital student ID, course bookings or payment functions): in that respect, too, the respective institution is the controller and its privacy notice applies.
8. Local email mailbox
The app can integrate the user’s email mailbox at their university as an email client. Emails are retrieved and sent exclusively directly between the user’s device and the university’s mail server or the email provider commissioned by the university (such as Microsoft 365 or Google Workspace). Messages are stored locally on the device for offline use; the credentials for the mailbox are stored exclusively locally in the secure storage provided by the operating system (iOS Keychain or Android Keystore).
Neither the credentials nor the contents of the mailbox are transmitted to the controller or processed or stored on its servers. Storing this data on the device is strictly necessary for the function expressly requested by the user (Sec. 25 (2) no. 2 TDDDG). The user can sign out of the mailbox in the app at any time; the locally stored credentials and messages are then removed from the device, as they are when the app is deleted.
9. Storage and encryption of personal data on the user’s device
The app stores the personal data requested by the user locally on the user’s device in order to enable the user to use the app even without an internet connection. All data is encrypted on the user’s device if their device has been provided with a device code. If this is not the case, secure encryption of the data cannot be guaranteed by the controller. The controller therefore recommends that the user use a device code to ensure the security and encryption of the data.
10. Secure transmission of your data
In order to protect the data stored by us as best as possible against accidental or intentional manipulation, loss, destruction or access by unauthorized persons, we use appropriate technical and organizational security measures. The security levels are continuously checked in cooperation with security experts and adapted to new security standards.
Data exchange from and to our application takes place in encrypted form. We offer TLS as the encryption protocol for secure data transmission. In addition, there is the possibility of using alternative communication channels (e.g. by post).
11. Access rights
For the app to work on your device, it is necessary to grant the app various permissions to access certain functions of the device. For all devices, regardless of the operating system they have, it is necessary to grant the app certain permissions, which we call “basic permissions”. Depending on the operating system of the device you use, it may have additional functions for which it is necessary to grant further permissions for the app to work. We list these following the “basic permissions” sorted by operating system (Android or iOS).
The basic permissions (Android and iOS) are:
➢ Receive push notifications: Is required if the push notifications functionality is used.
➢ Retrieve Wi-Fi connections: Is required so that content can be retrieved in the app.
➢ Retrieve network connections: Is required so that content can be retrieved in the app.
➢ Retrieve location: Is required if a functionality with GPS navigation is used.
➢ Take pictures and videos: Is required if a functionality with camera (e.g. scanning QR code) is used.
If you use the app via a device running the Android operating system, the following permissions are also required due to the operating system:
➢ Read USB storage contents: The permission is required so that documents stored on the USB storage of the device can be read.
➢ Change or delete USB storage contents: The permission is required so that documents stored on the USB storage of the device can be changed or deleted or stored for the first time.
If, however, you use the app via a device running the iOS (Apple) operating system, the following permissions are additionally required due to the operating system, in addition to the basic permissions:
➢ Mobile data/access to mobile data: If the user wishes to download documents exclusively via Wi-Fi, they can make a corresponding setting in the app menu and deactivate the use of mobile data. Access to mobile data is necessary in this respect so that the functionality of switching off document downloads via mobile data can be ensured.
➢ Receive critical push notifications: Is required to receive critical push notifications.
12. Automated individual decision-making
We do not use purely automated processing processes to bring about a decision.
III Creation of a UniNow account
1. Description and scope of data processing
As part of the registration, the user can create a UniNow account and is asked to provide some personal information. The controller stores the following user data entered during the registration process:
- Email address
- Password
- First name and last name (optional)
- Profile picture (optional)
2. Legal basis for data processing
The legal basis for the processing of personal data is Art. 6 Para. 1 lit. b GDPR.
3. Purpose of data processing
The processing of the data on the servers of the controller is necessary to create an account.
4. Duration of storage
The data will be deleted as soon as they are no longer required to achieve the purpose of their processing or until revocation by the data subject.
5. Possibility of objection and elimination
The user has the option to delete their account and the associated personal data at any time. The revocation or deletion request takes place via the website accounts.uninow.com.
IV Provision of the app and creation of log files
1. Description and scope of data processing
Each time our app is accessed, our system automatically collects data and information from the system of the accessing device. Processing this data serves to ensure system security, the stability of technical operations, error analysis, and the defense against and tracking of security incidents.
The following data is collected:
- Date and time of access
- Information about the app version used
- Operating system and operating system version of the user
- Accessed system route or function within the app
- IP address of the user
The data is stored in server log files. System security also covers the app’s error and crash reports (Sentry) and diagnostic logs limited to technical information, which are transmitted regardless of the “Share usage data” setting (Section VII Item 5). They carry an identifier for correlating related reports; when the setting is off, this is only a separate logging identifier that can be attributed solely in the context of a support request by the user. The server log files are not combined with other personal data of the user. There is no transfer of the data processed in this context to recipients in third countries within the meaning of Art. 44 et seq. GDPR.
2. Legal basis for data processing
The legal basis for the temporary storage of data and log files is Art. 6 Para. 1 lit. b GDPR.
UniNow is obliged, both under the usage agreement with the user and by contractual obligations towards the respective university, to ensure the security, integrity, stability and traceability of the technical operation of the app.
The processing of log data is necessary to fulfill these contractual obligations, in particular to detect, analyze and document security incidents, to defend against attacks and to ensure proper operation.
3. Purpose of data processing
The temporary storage of the IP address is necessary to enable delivery of the content to the device.
Storage in log files also takes place for: Ensuring IT security, maintaining system stability, error diagnosis and technical optimization, detection and defense against unauthorized access, verifiability in the event of security or abuse incidents.
4. Duration of storage
The data will be deleted as soon as they are no longer required to achieve the purpose of their processing.
In the case of collection for the provision of content, this is the case when the respective session has ended.
In the case of storage in log files, deletion takes place after 30 days at the latest, unless security-relevant events require longer storage in individual cases.
5. Possibility of objection and elimination
The collection of data for the provision of the app and storage in log files is strictly necessary to fulfill contractual obligations towards the user and the respective university and to ensure IT security. Consequently, there is no possibility for the user to object.
V Use of the support chat
1. Description and scope of data processing
In the app, there is the possibility to contact the controller via an integrated chat function.
The use of the support chat serves to process technical or content-related inquiries in connection with the use of the app. The content entered by the user and technical metadata (e.g. time of the request, user ID and technical identifiers of the app for correlating error reports) are processed.
The chat history is used exclusively for processing the respective service request and ensuring proper contract fulfillment. The controller has no influence on which personal data the user communicates in the context of chat communication.
To handle support cases we operate a self-operated support ticket system based on Chatwoot in a data centre within the European Union.
At the request of the controller, the user may additionally transmit diagnostic data in the support chat. This processing takes place exclusively on the basis of a separate consent; for details please see Section VI.
2. Legal basis for data processing
The legal basis for the processing of personal data transmitted in the support chat is Art. 6 Para. 1 lit. b GDPR.
UniNow is obliged, both under the usage agreement with the user and by contractual obligations towards the respective university, to provide technical support. The processing of data transmitted within the scope of the support chat is necessary to fulfill these contractual obligations.
3. Purpose of data processing
The data is processed for the purpose of processing support requests, technical troubleshooting, user support and ensuring the contractually owed services to the user and the respective university.
4. Duration of storage
The data processed in the context of the support chat will be deleted as soon as they are no longer required to achieve the purpose of their processing.
Deletion takes place at the latest after one year of inactivity, unless there are statutory retention obligations or legitimate interests in longer storage.
5. Possibility of objection and elimination
The processing of personal data transmitted in the support chat is necessary to fulfill contractual obligations towards the user and the respective university.
Consequently, there is no possibility for the user to object.
This does not apply to the transmission of diagnostic data pursuant to Section VI: this takes place voluntarily on the basis of a consent which the user may withdraw at any time.
VI Transmission of diagnostic data in support cases
1. Description and scope of data processing
If a malfunction occurs while using the app, the controller may ask the user in the support chat to transmit diagnostic data. For this purpose, the app compiles a diagnostic package on the user’s device, which the user transmits as an attachment to a message in the support chat by clicking the “Send diagnostic data” button. Without this express action by the user, no diagnostic data is transmitted.
The following data may be affected:
- Log data of the app (log entries at the levels Debug, Info, Warning and Error)
- Information about the device and the app (e.g. device type, operating system and operating system version, app version as well as installation and user identifier)
- Snapshots of those pages the app has loaded from the user’s university portal
The snapshots pursuant to item 3 may contain personal data from the user’s university portal, in particular the name of the university, surname and first name, matriculation number, subjects of study, lectures and courses, examinations and grades as well as library, calendar and appointment data. The controller has no influence over which data the university displays on the retrieved pages; further personal data may therefore be contained. For the same reason, the diagnostic data may in individual cases contain special categories of personal data within the meaning of Art. 9 Para. 1 GDPR, such as information relating to health.
The diagnostic package is asymmetrically encrypted on the user’s device (OpenPGP) and transmitted exclusively via a TLS-encrypted connection. It is stored as a message attachment in our self-operated support ticket system based on Chatwoot and in the associated object storage; both are operated in data centres within the European Union. The data remains encrypted there throughout. Decryption does not take place automatically, but only by employees of the controller and only insofar as it is necessary for diagnosing the reported malfunction; the private key required for this is kept separately from the data. There is no transfer of the data processed in this context to recipients in third countries within the meaning of Art. 44 et seq. GDPR.
2. Legal basis for data processing
The legal basis for the processing of the diagnostic data is Art. 6 Para. 1 lit. a GDPR. Insofar as the diagnostic data contains special categories of personal data, Art. 9 Para. 2 lit. a GDPR serves as an additional legal basis.
You can find the underlying declaration of consent here.
3. Purpose of data processing
The processing of the diagnostic data serves exclusively to diagnose and remedy the malfunction reported by the user, in particular errors in the retrieval of data from the university network. The data is not used for any other purpose, in particular not for advertising purposes, profiling or product and usage analysis.
4. Duration of storage
The diagnostic data is deleted as soon as the support case has been concluded, at the latest 90 days after transmission. Copies downloaded and decrypted for diagnosis are deleted immediately after the diagnosis has been completed. In addition, the data is deleted as soon as the user requests this.
5. Possibility of objection and elimination
The transmission of diagnostic data is voluntary. Unlike the remaining support communication pursuant to Section V, the user has a right of withdrawal at any time here.
The user may withdraw their consent in whole or in part at any time with effect for the future without incurring any disadvantages. Withdrawal is carried out by a message in the app’s support chat — for instance by asking for the message containing the diagnostic data to be deleted — or by email to datenschutz@uninow.de. We will then delete the message including the attachment as well as any copies already downloaded. The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.
VII Optimization of the app
1. Description and scope of data processing
In order to continuously improve the app technically, fix errors and ensure stability and performance, we carry out performance monitoring as well as product and usage analyses. For this purpose, we process technical usage and event data (e.g. accessed functions, app version, device type, operating system version, timestamp and shortened or anonymized IP address). To evaluate this log and event data, we use the solution RudderStack (product and usage analysis), which is operated exclusively on servers in the European Economic Area (see Section II Item 4 „Hosting“), as well as our own systems operated there, to which the app transmits technical log data and runtime measurements (logging and performance tracing). Usage analysis is carried out under a randomly generated analytics identifier that is not linked to the user account. Log and runtime data, by contrast, contain an installation identifier and a user identifier so that errors can be attributed to a support case. There is no transfer of the data processed in this context to recipients in third countries within the meaning of Art. 44 et seq. GDPR. Error and crash reports (Sentry) are described in Section IV.
These automatically collected usage and error analysis data are to be distinguished from the diagnostic data pursuant to Section VI, which is transmitted only in individual cases and exclusively upon the express consent of the user.
2. Legal basis for data processing
The legal basis for the processing of this usage and error analysis data is Art. 6 Para. 1 lit. f GDPR.
Our legitimate interest lies in ensuring the technical functionality, stability, security and continuous improvement of the app as well as error analysis and performance optimization.
3. Purpose of data processing
The processing of data serves exclusively for technical optimization, further development and ensuring stable operation of the app.
4. Duration of storage
The data is deleted or anonymized as soon as it is no longer required to achieve the purpose of its processing.
Insofar as further storage for statistical purposes takes place, the data is anonymized beforehand so that a personal reference can no longer be established.
5. Possibility of objection and elimination
According to Art. 21 GDPR, you have the right to object at any time to the processing of your personal data based on Art. 6 Para. 1 lit. f GDPR for reasons arising from your particular situation.
In the event of an objection, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
The easiest way to object is directly in the app: under Settings → Data Usage you can deactivate the “Share usage data” toggle at any time; the transmission of usage analytics data, performance measurements and log data for analysis purposes then stops immediately. Not covered by this toggle are error and crash reports as well as diagnostic logs limited to technical information; these serve system security and are described in Section IV. The analytics identifier is deleted upon objection; the remaining reports then no longer contain an installation or user identifier. Otherwise, the objection can be declared by a message in the app’s support chat or by email to support@uninow.de
VIII Delivery of push notifications
1. Description and scope of data processing
We use the Firebase Cloud Messaging service from Google LLC (hereinafter “Google”) to deliver push notifications. For this purpose, a notification token is generated by the operating system (iOS or Android) and stored in the service. Further information can be found at: Firebase Cloud Messaging.
2. Legal basis for data processing
The legal basis for the use of the Firebase Cloud Messaging service is Art. 6 Para. 1 lit. a GDPR and §25 Para. 1 TDDDG.
3. Purpose of data processing
On behalf of the app operator, Google will use this information to deliver push notifications to the device.
4. Duration of storage
The data will be deleted as soon as they are no longer required to achieve the purpose of their processing.
5. Possibility of objection and elimination
You can stop receiving push notifications at any time. This option is usually found in the settings of the device.
6. Third country transfer
When using the push service, access to your data by Google LLC, USA may occur. For the United States, there has been an adequacy decision by the EU Commission („EU-US Data Privacy Framework“) in accordance with Art. 45 GDPR since July 10, 2023; Google LLC is certified under this framework. In addition, we have concluded the EU Standard Contractual Clauses (SCC) with Google. This ensures an appropriate level of data protection.
IX Content and organisation features (feed, to-dos)
1. Description and scope of data processing
In the app, the user can use the feed — read posts, follow authors or channels, like posts, take part in polls within posts and save posts as bookmarks — and create their own content in organisation features, in particular to-dos and lists. In doing so, we process the content and interactions created by the user (followed authors, likes, votes, bookmarks, to-do entries) and their assignment to the UniNow account. The data is stored on the controller’s servers.
2. Legal basis for data processing
The legal basis for the processing is Art. 6 Para. 1 lit. b GDPR (provision of the features requested by the user).
3. Purpose of data processing
The processing serves to provide the respective feature, in particular to display the user’s own content and interactions and to synchronise them across the user’s devices.
4. Duration of storage
The user can remove their content and interactions in the app at any time. At the latest, the data is deleted when the UniNow account is deleted.
5. Possibility of objection and elimination
Use of the features is voluntary. The user can remove their content and interactions in the app at any time.
X Applicant profile and search criteria (career feature)
1. Description and scope of data processing
In the career area of the app, the user can create an applicant profile. They can provide the following data there:
- Salutation, title, first and last name
- Email address and telephone number
- Postal address
- Profile photo
- Work experience
- Education and internships
- Languages and skills
At the user’s request, the controller creates a CV from this information as a PDF file, which is also stored in the applicant profile.
In addition, the user can specify search criteria for the job search, in particular their professional situation, desired contract and working arrangements, their availability, preferred locations including a radius, as well as saved companies and jobs. If the user specifies a preferred location via the location function of their device, the location is queried once for this purpose; no continuous location tracking takes place.
All information is voluntary. The data is stored on the controller’s servers.
2. Legal basis for data processing
The legal basis for the processing is Art. 6 Para. 1 lit. b GDPR (provision of the career feature requested by the user).
3. Purpose of data processing
The processing serves to provide the applicant profile, to create the CV and to display suitable job and company offers.
4. Duration of storage
The data is stored for as long as the user uses the career feature. The user can edit and delete their information in the app at any time. At the latest, the data is deleted when the UniNow account is deleted.
5. Possibility of objection and elimination
Use of the career feature and provision of the data are voluntary. The user can edit or delete their information in the app at any time.
XI Job recommendations and advertisements
1. Description and scope of data processing
In the career area of the app, the user is shown job recommendations in the form of job and company offers and advertising. These displays are based on the following data:
- University for which the app is provided
- Study data provided by the user (course of study and field, start of studies)
- Search criteria pursuant to Section X, including preferred locations
- Saved companies and jobs
2. Legal basis for data processing
The legal basis for the display of job recommendations and advertising is the usage agreement concluded between the provider and the user pursuant to Art. 6 Para. 1 lit. b GDPR and Sec. 25 (2) TDDDG, under which, in return for the free use of the app, the display of job recommendations and advertising — and thus the use of the data for this purpose — is agreed.
3. Purpose of data processing
The data is used to display suitable job recommendations and advertising to the user.
4. Duration of storage
The data is deleted as soon as it is no longer required to achieve the purpose of its processing.
5. Possibility of objection and elimination
The user can end or limit the personalisation at any time by adjusting or deleting the underlying information in the app (search criteria via “Adjust search profile” in the career area, study data in the settings). In addition, the user can object to the use of their data for personalised job recommendations and advertising at any time via the app’s support chat. Use of the app remains possible nonetheless.
XII Contact by companies and applications
1. Description and scope of data processing
In the career area of the app, the user can consent via a toggle that their applicant profile can be viewed by companies in anonymised form and that companies may send them contact requests. The toggle is deactivated by default. The user’s identity — in particular name, contact details and profile photo — is only disclosed to a company once the user expressly accepts the respective contact request.
If the user applies for a job offer via the app or confirms a contact request, the controller transmits the user’s applicant profile (see Section X) including the created CV to the respective company. The transmission only takes place after express confirmation by the user; before sending, the user is shown which data will be transmitted.
2. Legal basis for data processing
The legal basis for the visibility of the applicant profile and the transmission to companies is Art. 6 Para. 1 lit. a GDPR. You can find the underlying declaration of consent here.
3. Purpose of data processing
The processing serves to establish contact between the user and companies and to carry out the application requested by the user.
4. Duration of storage
Upon transmission, the respective company becomes an independent controller under data protection law for the transmitted data; the company’s privacy notice applies to its further processing. At the controller, the data processed in connection with the transmission is deleted as soon as it is no longer required to achieve the purpose of its processing.
5. Possibility of objection and elimination
The user can deactivate the visibility of their applicant profile at any time via the toggle in the career area; their profile is then no longer viewable by companies. Otherwise, the user can withdraw their consent at any time with effect for the future via the app’s support chat or by email to datenschutz@uninow.de. For data already transmitted to a company, the user can assert their data subject rights against the respective company.
XIII Rights of the data subject
If personal data is processed by you, you are a data subject within the meaning of the GDPR and you have the following rights towards the controller:
- The right to information (Art. 15 GDPR),
- The right to deletion (Art. 17 GDPR),
- The right to rectification (Art. 16 GDPR),
- The right to data portability (Art. 20 GDPR),
- The right to restriction of data processing (Art. 18 GDPR),
- The right to object to data processing (Art. 21 GDPR),
- The right to revoke the data protection declaration of consent (Art. 7 Para. 3 GDPR).
To exercise these rights, please contact: datenschutz@uninow.de. The same applies if you have questions about data processing in our company or would like to revoke consent given. You also have the right to lodge a complaint with a data protection supervisory authority.
Right of objection
You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you, which is carried out on the basis of Art. 6 Para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. The controller no longer processes the personal data concerning you, unless they can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. If the personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling insofar as it is associated with such direct advertising. If you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes. You have the possibility, in connection with the use of information society services — notwithstanding Directive 2002/58/EC — to exercise your right of objection by means of automated procedures using technical specifications.