Privacy Policy
We hereby inform you, in accordance with applicable data protection laws—in particular the German Federal Data Protection Act, as amended (BDSG), and the European General Data Protection Regulation (GDPR)—about the nature, scope, and purposes of the processing of personal data by our company.
This Privacy Policy also applies to our websites and social media profiles. For definitions of terms such as “personal data” and “processing,” please refer to Article 4 GDPR.
Name and Contact Information of the Controller
The controller responsible for the processing of personal data, hereinafter referred to as the “Controller,” within the meaning of Article 4(7) GDPR is:
Two West GmbH
Krackser Straße 12
Gebäude (Building) G2
33659 Bielefeld
Germany
Managing Director: Christine Gaebel-Stodiek
Commercial Register No.: HRB 42027
Register Court: Bielefeld
Phone: +49 521 3292 0220
Fax: +49 521 3292 9891
Email: kontakt@twowest.de
Types of Data, Purposes of Processing, and Categories of Data Subjects
Below, we provide information about the nature, scope, and purposes of the collection, processing, and use of personal data.
1. Types of Data We Process
Contact information, such as phone numbers, email addresses, and fax numbers, as well as content data, such as text entries, videos, and photographs.
2. Purposes of Processing Pursuant to Article 13(1)(c) GDPR
The purposes of processing include:
- Technical and commercial optimization of the website;
- optimization and statistical analysis of our services;
- support of the commercial use of the website;
- user-friendly website design;
- cost-effective operation of advertising and the website;
- marketing, sales, and advertising;
- prevention of spam and misuse;
- handling of contact requests;
- provision of website functions and content; and
- implementation of security measures.
3. Categories of Data Subjects Pursuant to Article 13(1)(e) GDPR
Visitors to and users of the website.
The data subjects are collectively referred to below as “Users.”
Legal Bases for Processing Personal Data
We process personal data on the following legal bases:
- Where we have obtained your consent to process personal data, Article 6(1), first sentence, point (a) GDPR serves as the legal basis.
- Where processing is necessary to perform a contract or to take steps at your request before entering into a contract, Article 6(1), first sentence, point (b) GDPR serves as the legal basis.
- Where processing is necessary to comply with a legal obligation to which we are subject, such as statutory record-retention requirements, Article 6(1), first sentence, point (c) GDPR serves as the legal basis.
- Where processing is necessary to protect the vital interests of the data subject or another natural person, Article 6(1), first sentence, point (d) GDPR serves as the legal basis.
- Where processing is necessary for the purposes of our legitimate interests or those of a third party, and your interests or fundamental rights and freedoms do not override those interests, Article 6(1), first sentence, point (f) GDPR serves as the legal basis.
Disclosure of Personal Data to Third Parties and Processors
As a general rule, we do not disclose personal data to third parties without your consent.
Where such disclosure does occur, it is based on one of the legal bases described above. This may include, for example, transferring data to online payment providers for the performance of a contract, disclosing data pursuant to a court order, or complying with a legal obligation to provide data for purposes such as criminal prosecution, the prevention of threats or harm, or the enforcement of intellectual property rights.
We also use processors, meaning external service providers such as providers of website and database hosting services, to process your data.
Where data is disclosed to a processor under a data processing agreement, such disclosure is always carried out in accordance with Article 28 GDPR.
We carefully select our processors, review them regularly, and retain the right to issue instructions concerning the processing of personal data.
Processors must also implement appropriate technical and organizational measures and comply with the applicable provisions of the German Federal Data Protection Act, as amended, and the GDPR.
Transfers of Data to Third Countries
The adoption of the European General Data Protection Regulation established a uniform framework for data protection throughout Europe. Your data is therefore primarily processed by companies that are subject to the GDPR.
However, where processing is carried out by third-party service providers located outside the European Union or the European Economic Area, those providers must comply with the specific requirements of Articles 44 et seq. GDPR.
This means that processing must be based on appropriate safeguards. These may include an adequacy decision formally adopted by the European Commission confirming that the relevant country provides a level of data protection equivalent to that of the European Union, or compliance with formally recognized contractual obligations, known as Standard Contractual Clauses.
Where, due to the invalidation of the former Privacy Shield framework, we obtain your explicit consent pursuant to Article 49(1), first sentence, point (a) GDPR for a transfer of personal data to the United States, we inform you of the risk that U.S. authorities may access the data without your knowledge and use it for surveillance purposes, potentially without effective legal remedies being available to citizens of the European Union.
Deletion of Data and Retention Periods
Unless expressly stated otherwise in this Privacy Policy, your personal data will be deleted or restricted from further processing as soon as:
- you withdraw the consent previously granted for its processing;
- the purpose for which the data was stored no longer applies; or
- the data is no longer required for that purpose.
This does not apply where continued retention is required for evidentiary purposes or where statutory record-retention requirements prevent deletion.
Such requirements include, for example, the obligation under Section 257(1) of the German Commercial Code to retain business correspondence for six years, as well as the obligation under Section 147(1) of the German Fiscal Code to retain accounting records and supporting documentation for ten years.
Once the applicable retention period expires, your data will be restricted or deleted unless continued storage is still required to enter into or perform a contract.
Automated Decision-Making
We do not use automated decision-making or profiling.
Provision of Our Website and Creation of Log Files
Where you use our website solely for informational purposes, meaning that you do not register or otherwise submit information to us, we collect only the personal data transmitted by your browser to our server.
When you access our website, we collect the following information:
- IP address;
- the User’s internet service provider;
- date and time of access;
- browser type;
- language and browser version;
- content accessed;
- time zone;
- access status or HTTP status code;
- amount of data transferred;
- websites from which the request originated; and
- operating system.
This data is not combined or stored together with any other personal data relating to you.
The data is used to provide you with a user-friendly, functional, and secure website, including its features and content. It is also used to optimize the website and conduct statistical analyses.
The legal basis for this processing is our legitimate interest in processing the data for the purposes described above, pursuant to Article 6(1), first sentence, point (f) GDPR.
For security purposes, we store this data in server log files for a retention period of an unspecified number of days.
After this period expires, the data is automatically deleted unless continued retention is required as evidence in connection with attacks on the server infrastructure or other violations of law or rights.
Social Media Plug-ins
We use social media plug-ins from social networks on our website.
For this purpose, we use the Shariff “two-click solution” developed by c’t and heise.de:
https://www.heise.de/ct/artikel/Shariff-Social-Media-Buttons-mit-Datenschutz-2467514.html
Service provider:
Heise Medien GmbH & Co. KG
Karl-Wiechert-Allee 10
30625 Hanover
Germany
Privacy Policy:
https://www.heise.de/Datenschutzerklaerung-der-Heise-Medien-GmbH-Co-KG-4860.html
Categories of Data and Description of Processing
The categories of data processed include usage data, content data, and master data.
When our website is accessed, Shariff does not transmit personal data to third-party providers of social media plug-ins.
Next to the logo or trademark of the relevant social network, you will find a switch that allows you to activate the plug-in by clicking on it.
By activating the plug-in, you consent to the relevant social network provider receiving information that you have accessed our website. Your personal data may then be transmitted to and stored by the plug-in provider.
This may involve the use of third-party cookies.
According to certain providers, including Facebook and XING, your IP address is anonymized immediately after it is collected.
The plug-in provider may store the data collected about the User in the form of usage profiles.
You may withdraw your consent at any time by deactivating the switch.
Purposes of Processing
The purposes of processing include:
- improving and optimizing our website;
- increasing awareness of our company through social networks;
- enabling interaction between you and us;
- enabling interaction among Users through social networks;
- advertising;
- analysis; and
- designing the website according to Users’ needs.
Legal Bases
The legal basis for processing personal data is our legitimate interest in the purposes described above, pursuant to Article 6(1), first sentence, point (f) GDPR.
Where you have given us or the controller of the relevant social network your consent to process your personal data, the legal basis is Article 6(1), first sentence, point (a), in conjunction with Article 7 GDPR.
For pre-contractual requests or where personal data is used to perform a contract, Article 6(1), first sentence, point (b) GDPR serves as the legal basis.
Data Transfers and Categories of Recipients
The recipients of the data are the applicable social networks.
Social Networks Used and Right to Object
For information about the purpose and scope of data collection and processing, please refer to the privacy policies of the respective social networks.
Those privacy policies also provide information about your rights and the settings available to protect your personal data.
You have the right to object to the creation of User profiles. To exercise this right, you must contact the relevant plug-in provider directly.
We have integrated plug-ins from the Instagram social network into our website using the Shariff “two-click solution.”
The service provider is:
Facebook Ireland Ltd.
4 Grand Canal Square
Grand Canal Harbour
Dublin 2
Ireland
The plug-ins can be identified by the Instagram logo, which is displayed in the shape of a square camera.
When you deliberately activate the plug-in, a connection is established between your browser and Instagram’s servers.
Instagram then receives information, including your IP address, indicating that you have visited our website. This information is transferred to Instagram servers in the United States, where it is stored.
Where you are logged into your Instagram account, Instagram may associate this information with your account.
You may also click the Instagram button to share and save content from our website through your Instagram account and, where applicable, display it to your friends or followers on Instagram.
We have no knowledge of the exact content of the data transmitted, how Instagram uses the data, or how long Instagram stores the data.
Where you log out of Instagram before visiting our website and delete your cookies, activating the plug-in will not result in information about your visit to our website being associated with your Instagram profile.
Additional information is available in Instagram’s Privacy Policy and opt-out information:
Opt-out:
https://help.instagram.com/519522125107875
Objection:
https://help.instagram.com/contact/186020218683230
Rights of the Data Subject
Right to Object to Processing or Withdraw Consent
Where processing is based on your consent pursuant to Article 6(1), first sentence, point (a) and Article 7 GDPR, you have the right to withdraw your consent at any time.
The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Where we base the processing of your personal data on a balancing of interests pursuant to Article 6(1), first sentence, point (f) GDPR, you may object to the processing.
This applies in particular where processing is not necessary to perform a contract with you, as explained in the descriptions of the respective features and functions.
When exercising your right to object, we ask that you explain why your personal data should no longer be processed in the manner described.
In the event of a justified objection, we will review the circumstances and will either discontinue or modify the processing or explain the compelling legitimate grounds on which we will continue the processing.
You may object to the processing of your personal data for advertising and data analysis purposes at any time.
You may exercise your right to object free of charge.
You may notify us of your objection to advertising using the following contact information:
Two West GmbH
Krackser Straße 12
Gebäude (Building) G2
33659 Bielefeld
Germany
Managing Director: Christine Gaebel-Stodiek
Commercial Register No.: HRB 42027
Register Court: Bielefeld
Phone: +49 521 3292 0220
Fax: +49 521 3292 9891
Email: kontakt@twowest.de
Right of Access
You have the right to request confirmation from us as to whether personal data concerning you is being processed.
Where such processing takes place, you have the right to obtain access to the personal data stored by us concerning you, pursuant to Article 15 GDPR.
This includes, in particular, information about:
- the purposes of processing;
- the categories of personal data concerned;
- the categories of recipients to whom your data has been or will be disclosed;
- the planned retention period; and
- the source of the data, where it was not collected directly from you.
Right to Rectification
Pursuant to Article 16 GDPR, you have the right to have inaccurate personal data corrected and incomplete personal data completed.
Right to Erasure
Pursuant to Article 17 GDPR, you have the right to request the deletion of personal data stored by us concerning you, unless statutory or contractual retention periods or other legal obligations or rights requiring continued storage prevent its deletion.
Right to Restriction of Processing
You have the right to request that the processing of your personal data be restricted where one of the conditions set out in Article 18(1), points (a) through (d) GDPR applies:
- You contest the accuracy of personal data concerning you, for a period that allows the Controller to verify the accuracy of the personal data;
- the processing is unlawful, and you oppose the deletion of the personal data and request that its use be restricted instead;
- the Controller no longer requires the personal data for the purposes of processing, but you require the data for the establishment, exercise, or defense of legal claims; or
- you have objected to processing pursuant to Article 21(1) GDPR, and it has not yet been determined whether the legitimate grounds of the Controller override your grounds.
Right to Data Portability
Pursuant to Article 20 GDPR, you have the right to data portability.
This means that you may receive the personal data concerning you that is stored by us in a structured, commonly used, and machine-readable format.
You may also request that the data be transmitted to another controller.
Right to File a Complaint
You have the right to file a complaint with a supervisory authority.
As a general rule, you may contact the supervisory authority located in the EU Member State of your habitual residence, your place of employment, or the location of the alleged violation.
Data Security
To protect all personal data transmitted to us and to ensure that both we and our external service providers comply with applicable data protection laws, we have implemented appropriate technical and organizational security measures.
Among other measures, data transmitted between your browser and our server is encrypted using a secure SSL connection.
Last updated: July 22, 2026
