Independent private service. Not a public authority and not affiliated with BaFin.
bafin-hilfe.comIndependent support
← Back to home

Legal

Terms — review draft

[[SERVICE_TERMS_MISSING]]

Review draft: the source labelled “AGB” largely contains privacy and vendor descriptions. The sections below reword that source; they do not confirm actual use and are not a complete service contract. Service scope, fees, contract formation, withdrawal and other applicable terms are missing.

Netlify

According to the supplied description, the website is hosted using Netlify Inc., 2325 3rd Street, Suite 215, San Francisco, California 94107, USA. That description states that a data processing agreement incorporating standard contractual clauses is in place to protect data to European standards.

Further information is available in Netlify’s privacy policy.

Matomo

The supplied description identifies Matomo as a self-hosted, open-source website analytics tool. Cookies collect usage information that is stored and analysed on the operator’s server. Processing is described as pseudonymous, with IP addresses shortened after collection. The source describes users as anonymous as a result and states that the usage information is not passed to third parties.

Further details are available in Matomo’s privacy information.

Google Ads Conversion

The source describes using Google Ads Conversion to advertise on external websites and assess campaign effectiveness. Its stated aims are to display relevant advertising and improve the website.

Google delivers the advertisements through ad servers. Ad-server cookies record information including impressions and clicks. A visit following a Google advertisement may result in a cookie being placed on the device; the source gives a typical lifetime of 30 days and says the cookie is not intended to identify a person directly. Stored values may include a unique cookie ID, impression frequency, the most recent interaction and opt-out information.

These cookies can allow Google to recognise a browser. When a visitor reaches a specified advertiser page while the cookie remains active, Google and the advertiser can identify an earlier ad click. The source says each advertiser receives its own cookie and that this prevents tracking across different advertisers’ websites.

According to the supplied text, the operator receives statistical reports only, with no additional information enabling individual users to be identified. The source states that the operator itself does not collect or process personal data in these advertising measures.

The integration may establish a direct connection between the browser and Google’s servers. The operator states that it cannot control the extent or further use of data collected there. Google may learn that a particular part of the website was visited or an advertisement clicked. A visit may be linked to a signed-in Google account, and an IP address may also be recorded without an account or sign-in.

Braze: push notifications and newsletters

The source describes Braze as providing browser or mobile-app push notifications with the user’s consent. It identifies regular market information as the intended content.

According to the supplied text, Braze processes email addresses, push tokens, interaction data and IP addresses to manage newsletters and notifications and assess responses. A data processing agreement with standard contractual clauses is described as maintaining European data protection standards. The source states that processing is performed on the operator’s instructions and that user data is not passed to third parties.

Further information: Braze privacy policy.

Statistical analysis of newsletters

The described newsletters contain a tracking pixel retrieved from a Braze server when the email is opened. The request may provide browser and system information, an IP address and the time of access. The source describes using this information for technical improvements and adapting content to audiences and reading habits, including inferred location and access time.

The source also describes measuring newsletter opens, opening times and clicked links. This information can technically be assigned to individual recipients. It states that individual monitoring is not intended; the aim is instead to adapt content and delivery to recipients’ interests.

Online newsletter viewing and data management

The source describes links to Braze pages for viewing a newsletter online, resolving display problems or changing an email address. Braze’s privacy policy is also hosted on the provider’s website.

According to the description, those pages may use cookies and process personal data through Braze, its partners or service providers such as Google Analytics. The operator states that it cannot control that collection. The source refers to advertising opt-out information at AboutAds and Your Online Choices.

Usercentrics

The source names Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany, as the consent management provider. Its stated role is to obtain and document consent to certain cookies.

The stated purposes are compliance with legal obligations and recording consent. The source identifies Article 6(1)(a) and (c) GDPR as the legal bases and excludes use for other purposes.

The listed data comprises browser and device information, opt-in and opt-out data, page path, visit date and time, geographic location and request URL. A cookie is described as linking subsequent consent or withdrawal to the user.

The source describes retaining this information until a deletion request, deletion of the Usercentrics cookie by the user or expiry of the purpose, subject to mandatory retention requirements. It also states that a data processing agreement is in place.

Further information: Usercentrics privacy policy.

FinanceAds

The supplied description states that the operator works with the FinanceAds affiliate network, operated by financeAds GmbH & Co. KG, Karlstraße 9, 90403 Nuremberg, Germany.

Advertising and personalisation are the stated purposes. A tracking ID described as anonymised is intended to identify the advertising partner through which a visitor reached the website.

The source says cookies may be prevented through browser settings, potentially affecting functionality. It also refers to an opt-out cookie. More information is available in the FinanceAds privacy policy.

Adjust

The source describes analytics technology supplied by adjust GmbH, Saarbrücker Str. 36, 10405 Berlin, Germany. Its stated role is to analyse user behaviour, particularly mobile-app installations, and improve the website, offering and advertising.

The listed data includes IP addresses, browser and device information, the registration email address in hashed form and temporary device identifiers where these have not been disabled in the device settings. A data processing agreement is described as requiring processing under the operator’s instructions and in accordance with the GDPR.

Further information: Adjust privacy policy.

YouTube

The source refers to embedded YouTube videos using the no-cookie variant. It identifies the provider as Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

According to the description, visiting a page containing such a video and starting playback establishes a connection to YouTube servers. The operator states that it cannot control this. Further information is available in Google’s privacy policy.

Solaris / SEON

The supplied text describes registration through the former bafin-hilfe.com website to use banking services provided by Solaris SE, Cuvrystraße 53, 10997 Berlin, Germany. It states that Solaris performs risk checks for fraud prevention and anti-money-laundering purposes at registration and throughout use of those services.

The source identifies SEON Technologies Kft., Rákóczi út 42, 7th floor, Budapest 1072, Hungary, as a processor acting under an Article 28 GDPR agreement with Solaris. The described cookie technology analyses browser, device, traffic and location information so that Solaris can assess fraud risks for existing and prospective customers.

The source characterises this as necessary for the secure provision of banking services and refers to the privacy notice for further details. The supplied files do not establish that this banking offering belongs to the redesigned website.