Skip to content

Privacy policy

1. Data protection at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. For detailed information on data protection, please see the privacy policy set out below this text.

Data collection on this website

Who is responsible for collecting data on this website?

Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the section „Information on the controller“ in this privacy policy.

How do we collect your data?

Some of your data is collected because you provide it to us. This may, for example, be data you enter in a contact form.

Other data is collected automatically, or with your consent, by our IT systems when you visit the website. This is mainly technical data (for example your internet browser, operating system or the time of the page request). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour. Where contracts can be concluded or initiated through the website, the data transmitted is also processed for contractual offers, orders or other enquiries.

What rights do you have regarding your data?

You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw that consent at any time with effect for the future. You also have the right, in certain circumstances, to request the restriction of the processing of your personal data. You further have a right to lodge a complaint with the competent supervisory authority.

You can contact us at any time about this and about any further questions on data protection.

2. Hosting

We host the content of our website with the following providers:

Timme Hosting

The provider is Timme Hosting GmbH & Co. KG (hereinafter Timme Hosting). When you visit this website, Timme Hosting processes on our behalf the technically necessary data transmitted by your browser, in particular your IP address.

The server location is primarily Germany. In addition, further data centres within the European Union may be used. No personal data is transferred to a third country in this context.

Retention periods: Personal data is deleted or returned to us after the end of the contract. Specific retention periods for individual categories of data are not laid down in that contract.

Timme Hosting is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), in so far as the consent covers the storage of cookies or access to information on the user’s device (for example device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

Webflow

The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (hereinafter Webflow). When you visit our website, Webflow records various log files including your IP addresses.

Webflow is a tool for building and hosting websites. Webflow stores cookies or other recognition technologies that are necessary for displaying the page, for providing certain website functions and for ensuring security (necessary cookies). For details, please see the Webflow privacy policy: https://webflow.com/legal/eu-privacy-policy.

Webflow is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, in so far as the consent covers the storage of cookies or access to information on the user’s device (for example device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

The transfer of data to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://webflow.com/legal/eu-privacy-policy.

The company holds a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/6365.

Bunny.net (video delivery and content delivery network)

This website embeds videos via the Bunny Stream service and has content delivered via the Bunny.net content delivery network. The provider is BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia.

A content delivery network distributes content across several server locations so that it reaches you faster and more reliably. In doing so, your browser establishes a connection to the servers of Bunny.net. In the process, your IP address, the page requested, the referring page (referrer), the operating system used and your browser are processed.

The videos are loaded when the page is called up. The address called up in the process is vz-b51d5459-a36.b-cdn.net.

Bunny.net is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in the fast, reliable and secure delivery of our content. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, in so far as the consent covers the storage of cookies or access to information on the user’s device within the meaning of the TDDDG. Consent can be withdrawn at any time.

The provider is established within the European Economic Area. No personal data is transferred to a third country.

Processing on behalf of a controller

Data processing agreements (DPAs) are in place for the services named above. We conclude some of these directly with the provider. In other cases, one of our processors engages the provider as a sub-processor. These are contracts required by data protection law which ensure that the personal data of our website visitors is processed only in accordance with our instructions and in compliance with the GDPR.

3. General information and mandatory disclosures

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy.

When you use this website, various items of personal data are collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.

We point out that data transmission over the internet (for example when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.

Information on the controller

The controller for data processing on this website is:

GOT YOUR BACK GROUP GmbH
Phone: +49 89 9090 0620
Email: contact@gyb.group

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (for example names, email addresses or similar).

Retention period

Unless a more specific retention period is stated within this privacy policy, your personal data remains with us until the purpose of the data processing ceases to apply. If you make a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (for example retention periods under tax or commercial law). In the latter case, deletion takes place once those grounds cease to apply.

General information on the legal bases for data processing on this website

Where you have consented to the data processing, we process your personal data on the basis of Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, in so far as special categories of data within the meaning of Article 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, the processing is also based on Article 49(1)(a) GDPR. Where you have consented to the storage of cookies or to access to information on your device (for example via device fingerprinting), the data processing is additionally based on Section 25(1) TDDDG. Consent can be withdrawn at any time. Where your data is necessary for the performance of a contract or for pre-contractual measures, we process your data on the basis of Article 6(1)(b) GDPR. We also process your data where this is necessary for compliance with a legal obligation, on the basis of Article 6(1)(c) GDPR. Data processing may further be carried out on the basis of our legitimate interest under Article 6(1)(f) GDPR. The legal bases applicable in each individual case are set out in the following paragraphs of this privacy policy.

Recipients of personal data

In the course of our business activities we work with various external bodies. In some cases this also requires the transfer of personal data to those external bodies. We disclose personal data to external bodies only where this is necessary for the performance of a contract, where we are legally obliged to do so (for example disclosure of data to tax authorities), where we have a legitimate interest in the disclosure under Article 6(1)(f) GDPR, or where another legal basis permits the disclosure. Where we use processors, we disclose personal data of our customers only on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.

Withdrawal of your consent to data processing

Many data processing operations are possible only with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out up to the withdrawal remains unaffected by the withdrawal.

Right to object to the collection of data in particular cases and to direct marketing (Article 21 GDPR)

WHERE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ARTICLE 6(1)(e) OR (f) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA. THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ARTICLE 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSES OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING. THIS ALSO APPLIES TO PROFILING IN SO FAR AS IT IS CONNECTED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSES OF DIRECT MARKETING (OBJECTION UNDER ARTICLE 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. This right to lodge a complaint is without prejudice to any other administrative or judicial remedy.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place in so far as it is technically feasible.

Information, correction and deletion

Within the framework of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients and the purpose of the data processing, and where applicable a right to have this data corrected or deleted. You can contact us at any time about this and about any further questions on personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us about this at any time. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was or is unlawful, you can request the restriction of the data processing instead of deletion.
  • If we no longer need your personal data but you require it for the exercise, defence or establishment of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
  • If you have lodged an objection under Article 21(1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data may – apart from being stored – only be processed with your consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of an important public interest of the European Union or of a Member State.

4. Plugins and tools

Vimeo

This website uses plugins of the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

The Vimeo player is loaded on this website only after you have expressly started it by clicking the button in the preview area. Before that click, no connection is established to Vimeo or to Cloudflare, the service provider used by Vimeo, and no data is transmitted to these providers. The click is your consent within the meaning of Article 6(1)(a) GDPR and Section 25(1) TDDDG. Without your click, the video is not loaded.

Once you have started the player, a connection to Vimeo’s servers is established. The Vimeo server is thereby informed which of our pages you have visited. Vimeo also obtains your IP address. This also applies if you are not logged in to Vimeo or do not have a Vimeo account. The information recorded by Vimeo is transmitted to the Vimeo server in the USA.

If you are logged in to your Vimeo account, you enable Vimeo to assign your browsing behaviour directly to your personal profile. You can prevent this by logging out of your Vimeo account.

To recognise website visitors, Vimeo uses cookies or comparable recognition technologies (for example device fingerprinting). We call up the player with the „Do Not Track“ setting. Vimeo then sets no cookies for statistical or recognition purposes. Only those cookies are set which Vimeo and Cloudflare regard as necessary for the secure operation of the player (player_clearance, cf_clearance, _cf_bm, _cfuvid).

Vimeo is used in the interest of an appealing presentation of our online offering. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, in so far as the consent covers the storage of cookies or access to information on the user’s device (for example device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time. To withdraw consent you have given, reload the page. The player is then blocked again.

The transfer of data to the USA is based on the standard contractual clauses of the EU Commission and, according to Vimeo, on „legitimate business interests“. You can find details here: https://vimeo.com/privacy.

For further information on the handling of user data, please see the Vimeo privacy policy at: https://vimeo.com/privacy.

The company holds a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5711.

Wordly

This website embeds the subtitling and translation service Wordly. The provider is Wordly, Inc., 175 S. San Antonio Road, Suite 102, Los Altos, CA 94022, USA.

The service is loaded only after you have expressly started it by clicking the button in the preview area. Before that click, no connection is established to Wordly and no data is transmitted to Wordly. The click is your consent within the meaning of Article 6(1)(a) GDPR and Section 25(1) TDDDG. Without your click, no subtitles are loaded.

You take part in the translation in a reading capacity only. What is translated is solely the audio of the event, that is to say the contributions of the speakers. Your voice, your name and any spoken contributions of your own are not transmitted to Wordly. The embedded frame is granted no permission for your microphone and none for your camera. No access to them takes place.

After the start, your browser establishes connections to the following hosts: attend.wordly.ai delivers the user interface, assets.wordly.ai the files used within it, and the translated text reaches you over a persistent connection to endpoint.wordly.ai. In addition, fonts are loaded from fonts.gstatic.com, a service of Google LLC. The service itself is likewise operated in Google’s cloud infrastructure.

The following is transmitted from you in the process: your IP address, your browser identification, and the time and duration of the connection. If you select a target language or switch on the speech output, that selection is transmitted as well. No further details about your person are collected.

According to our measurement of 22 September 2026, Wordly sets no cookies. The service does, however, store information in the local storage of your browser, namely the language last selected and a session key for the current connection. This storage is likewise based on your consent under Section 25(1) TDDDG.

Wordly, Inc. is listed in the register of the EU-US Data Privacy Framework as an active participant (record 9374, certified since 28 October 2025). According to the official record, the certification covers exclusively human resources data (HR data). Data of website visitors and event participants is not covered by it. You can find the record at the following link: https://www.dataprivacyframework.gov/participant/9374.

The transfer of your IP address and of the other connection data named above to the USA is therefore not based on the adequacy decision on the Data Privacy Framework, but on your explicit consent under Article 49(1)(a) GDPR. You give this consent by clicking the button. We point out that the USA does not offer a level of data protection equivalent to European law, and that you may have no effective legal remedies against US authorities. Consent can be withdrawn at any time. To withdraw it, reload the page. The service is then blocked again.

For further information on the handling of user data, please see the Wordly privacy policy at: https://www.wordly.ai/privacy-policy.

5. Web analytics

Web analytics with Umami

We use the analytics software Umami, which we operate on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (processing on our behalf), in order to evaluate the use of our website statistically. The pages requested, the times, the referring pages and details of browser, operating system, device type and approximate geographical origin are recorded. Umami sets no cookies. Screen resolution and browser language are not read out. Your IP address is processed for approximate location assignment and for a technical identifier that changes daily, but it is not stored in the analytics database. This data is not merged with other data sources, and no profiles of individual persons are created. The legal basis is our legitimate interest in measuring reach and improving our offering (Article 6(1)(f) GDPR). You can object to this processing at any time (Article 21 GDPR), for example by message to the contact address named in this policy.

Die GOT YOUR BACK GROUP verbindet die unternehmerische Verantwortung, spezialisierte Expertise und Verbindlichkeit eigenständiger Agenturen mit der Ressourcenstärke, Schlagkraft und Skalierbarkeit einer Gruppe.

The GOT YOUR BACK GROUP combines the entrepreneurial accountability, specialized expertise, and commitment of independent agencies with the resource strength, muscle, and scalability of a major group.