icon
How it worksUse CasesPricingAbout usBlog
Book a demoDashboard
DashboardStart a free study
Burger Menu
Legal

Privacy Policy

Geschafft – deine Kontaktdaten sind bei uns eingegangen.
Oops! Something went wrong while submitting the form.

Privacy Policy

‍

1. Introduction

With the following information, we would like to give you, as a "data subject", an overview of how we process your personal data and of your rights under data protection law. In principle, our website can be used without entering any personal data. However, if you wish to use particular services offered by our company via our website, it may become necessary to process personal data. Where the processing of personal data is necessary and there is no legal basis for such processing, we will generally obtain your consent.

The processing of personal data, such as your name, address or e-mail address, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection provisions applicable to "IWD market research GmbH". By means of this privacy policy, we wish to inform you about the scope and purpose of the personal data we collect, use and process.

As the controller, we have implemented numerous technical and organisational measures to ensure the most complete protection possible of the personal data processed via this website. Nevertheless, internet-based data transmissions may in principle have security gaps, so that absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us by alternative means, for example by telephone or by post.

You, too, can take simple and easy-to-implement measures to protect yourself against unauthorised access to your data by third parties. We would therefore like to give you some advice here on handling your data securely:

  • Protect your account (login, user or customer account) and your IT system (computer, laptop, tablet or mobile device) with secure passwords.
  • Only you should have access to your passwords.
  • Make sure that you only ever use each password for one account (login, user or customer account).
  • Do not use the same password for different websites, applications or online services.
  • This applies in particular when using IT systems that are publicly accessible or shared with other people: you should always log out after each login to a website, application or online service.

Passwords should consist of at least 12 characters and be chosen so that they cannot easily be guessed. They should therefore not contain common everyday words, your own name or the names of relatives, but should instead contain upper- and lower-case letters, numbers and special characters.

‍

2. Controller

The controller within the meaning of the GDPR is:

IWD market research GmbH
Hasselbachplatz 3, 39104 Magdeburg, Germany

Telephone: 0391 7347 053
E-mail: info@iwd-marketresearch.de

Representative of the controller: Marcus Körner

‍

3. Data Protection Officer

You can contact our Data Protection Officer as follows:

Thomas Otten

Telephone: 05221/87292-08
Fax: 05221/87292-49
E-mail: datenschutz-iwd@audatis.de

You may contact our Data Protection Officer directly at any time with any questions or suggestions regarding data protection.

‍

4. Definitions

This privacy policy is based on the terminology used by the European legislator in adopting the General Data Protection Regulation (GDPR). Our privacy policy should be easy to read and understand for the general public as well as for our customers and business partners. To ensure this, we would first like to explain the terms used.

In this privacy policy, we use, among others, the following terms:

‍

1. Personal data

Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

‍

2. Data subject

A data subject is any identified or identifiable natural person whose personal data are processed by the controller (our company).

‍

3. Processing

Processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

‍

4. Restriction of processing

Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.

‍

5. Profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

‍

6. Pseudonymisation

Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

‍

7. Processor

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

‍

8. Recipient

Recipient means a natural or legal person, public authority, agency or other body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

‍

9. Third party

Third party means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

‍

10. Consent

Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

‍

5. Legal basis for processing

Art. 6(1)(a) GDPR (in conjunction with Section 25(1) TDDDG (formerly TTDSG)) serves as the legal basis for our company for processing operations for which we obtain consent for a specific processing purpose.

If the processing of personal data is necessary for the performance of a contract to which you are a party, as is the case, for example, with processing operations necessary for the supply of goods or the provision of any other service or consideration, the processing is based on Art. 6(1)(b) GDPR. The same applies to processing operations that are necessary to carry out pre-contractual measures, for example in the case of enquiries about our products or services.

If our company is subject to a legal obligation which requires the processing of personal data, for example to fulfil tax obligations, the processing is based on Art. 6(1)(c) GDPR.

In rare cases, the processing of personal data may become necessary to protect the vital interests of the data subject or of another natural person. This would be the case, for example, if a visitor were injured on our premises and their name, age, health insurance details or other vital information had to be passed on to a doctor, a hospital or other third parties. The processing would then be based on Art. 6(1)(d) GDPR.

Finally, processing operations may be based on Art. 6(1)(f) GDPR. Processing operations not covered by any of the aforementioned legal bases are based on this legal basis if the processing is necessary to safeguard a legitimate interest of our company or of a third party, provided that the interests, fundamental rights and freedoms of the data subject do not override them. We are permitted to carry out such processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, the legislator took the view that a legitimate interest could be assumed if you are a customer of our company (Recital 47, sentence 2 GDPR).

Our services are generally aimed at adults. Persons under the age of 16 may not transmit any personal data to us without the consent of their parents or legal guardians. We do not request personal data from children and adolescents, do not collect such data and do not pass it on to third parties.

‍

6. Transfer of data to third parties

Your personal data will not be transferred to third parties for purposes other than those listed below.

We only pass on your personal data to third parties if:

  1. you have given us your express consent to do so in accordance with Art. 6(1)(a) GDPR,
  2. the disclosure is permissible under Art. 6(1)(f) GDPR to safeguard our legitimate interests and there is no reason to assume that you have an overriding interest worthy of protection in your data not being disclosed,
  3. there is a legal obligation for the disclosure under Art. 6(1)(c) GDPR, and
  4. this is legally permissible and necessary under Art. 6(1)(b) GDPR for the performance of contractual relationships with you.

In the course of the processing operations described in this privacy policy, personal data may be transferred to the USA. Companies in the USA only offer an adequate level of data protection if they are certified under the EU-US Data Privacy Framework, so that the adequacy decision of the European Commission pursuant to Art. 45 GDPR applies. We have explicitly stated this for the service providers concerned in this privacy policy. To protect your data in all other cases, we have concluded data processing agreements based on the Standard Contractual Clauses of the European Commission. Where the Standard Contractual Clauses are not sufficient to establish an adequate level of security, your consent pursuant to Art. 49(1)(a) GDPR may serve as the legal basis for the transfer to third countries. This may not apply to data transfers to third countries for which the European Commission has issued an adequacy decision pursuant to Art. 45 GDPR.

‍

7. Technology

‍

7.1 SSL/TLS encryption

To ensure the security of data processing and to protect the transmission of confidential content, such as orders, login details or contact requests that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser shows "https://" instead of "http://" and by the padlock symbol in your browser bar.

We use this technology to protect the data you transmit.

‍

7.2 Data collection when visiting the website

If you use our website for information purposes only, i.e. if you do not register or otherwise provide us with information or do not give consent to processing that requires consent, we only collect the data that is strictly technically necessary to provide the service. This is usually data that your browser transmits to our server ("so-called server log files"). Each time you or an automated system calls up a page, our website collects a range of general data and information. This general data and information is stored in the server log files. The following may be recorded:

  1. the browser types and versions used,
  2. the operating system used by the accessing system,
  3. the website from which an accessing system reaches our website (so-called referrer),
  4. the sub-pages accessed via an accessing system on our website,
  5. the date and time of access to the website,
  6. an Internet Protocol address (IP address), and
  7. the internet service provider of the accessing system.

When using this general data and information, we do not draw any conclusions about you personally. Rather, this information is needed in order to

  1. deliver the content of our website correctly,
  2. optimise the content of our website and the advertising for it,
  3. ensure the long-term operability of our IT systems and the technology of our website, and
  4. provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack.

We therefore evaluate this collected data and information on the one hand statistically and on the other hand with the aim of increasing data protection and data security within our company, ultimately to ensure an optimum level of protection for the personal data we process. The data in the server log files are stored separately from all personal data provided by a data subject.

The legal basis for the data processing is Art. 6(1)(f) GDPR. Our legitimate interest follows from the purposes of data collection listed above.

‍

7.3 Amazon CloudFront (Content Delivery Network)

We use Amazon CloudFront, a web service provided by Amazon Web Services Inc., 410 Terry Avenue North, 98109, Seattle, Washington, USA.

Amazon CloudFront is a content delivery network (CDN). It routes the transfer of information between your browser and our website via the CloudFront network. This reduces the latency with which we can deliver static and dynamic web content. It also improves the security of our website through traffic encryption and access controls.

In addition, CloudFront stores cookies on your computer to optimise the service. You can delete cookies in your browser, allow cookies only in individual cases and activate the automatic deletion of cookies when closing the browser.

Amazon Web Services receives and processes personal data as our processor under the EU Standard Contractual Clauses. CloudFront is used to collect statistical data about visits to our website. This includes, among other things:

  • IP address
  • Website accessed
  • Referrer URL
  • Browser type
  • Operating system
  • Device type

If you have consented to the use of CloudFront, the legal basis for the processing of personal data is Art. 6(1)(a) GDPR. In addition, it is in our legitimate interest within the meaning of Art. 6(1)(f) GDPR to use CloudFront in order to optimise our website, make it more secure and avoid having to operate a content delivery network ourselves. The personal data are retained by Amazon Web Services for as long as is necessary to achieve the purposes described.

Amazon Web Services Inc. is certified under the EU-US Data Privacy Framework. There is therefore an adequacy decision pursuant to Art. 45 GDPR, so that personal data may be transferred without further guarantees or additional measures.

More detailed information on CloudFront can be found at: https://aws.amazon.com/de/cloudfront/.

‍

7.4 Cloudflare (Content Delivery Network)

Our website uses functions of CloudFlare. The provider is CloudFlare, Inc., 665 3rd St. #200, San Francisco, CA 94107, USA.

CloudFlare offers a globally distributed content delivery network with DNS. Technically, the transfer of information between your browser and our website is routed via the CloudFlare network. This enables CloudFlare to analyse the data traffic between users and our websites, for example in order to detect and defend against attacks on our services. In addition, CloudFlare may store cookies on your computer for optimisation and analysis purposes.

You can configure your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.

We have concluded a corresponding data processing agreement with Cloudflare on the basis of the GDPR or under the EU Standard Contractual Clauses. Cloudflare collects statistical data about visits to this website. The access data include: name of the web page accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider. Cloudflare uses the log data for statistical analyses for the purpose of operating, securing and optimising the service.

If you have consented to the use of Cloudflare, the legal basis for the processing of personal data is Art. 6(1)(a) GDPR. In addition, we have a legitimate interest in using Cloudflare in order to optimise our online offering and make it more secure. The corresponding legal basis for this is Art. 6(1)(f) GDPR. The personal data are retained for as long as they are necessary to fulfil the purpose of processing. The data are deleted as soon as they are no longer required to achieve the purpose.

This US company is certified under the EU-US Data Privacy Framework. There is therefore an adequacy decision pursuant to Art. 45 GDPR, so that personal data may be transferred without further guarantees or additional measures.

Further information on CloudFlare can be found at: https://www.cloudflare.com/privacypolicy/.

‍

7.5 Hosting by Webflow

Our website is hosted by Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA (hereinafter referred to as Webflow).

When you visit our website, your personal data (e.g. IP addresses in log files) are processed on Webflow's servers.

Webflow is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting, providing and securing our website as reliably as possible.

We have concluded a data processing agreement (DPA) with Webflow pursuant to Art. 28 GDPR. This is a contract required under data protection law which ensures that Webflow processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Further information on Webflow's data protection provisions can be found at: https://webflow.com/legal/privacy.

‍

8. Cookies

‍

8.1 General information on cookies

Cookies are small files that your browser creates automatically and that are stored on your IT system (laptop, tablet, smartphone or similar) when you visit our website.

The cookie stores information that arises in each case in connection with the specific device used. However, this does not mean that we thereby gain direct knowledge of your identity.

The use of cookies serves to make the use of our services more convenient for you. For example, we use so-called session cookies to recognise that you have already visited individual pages of our website. These are automatically deleted after you leave our website.

In addition, to optimise user-friendliness, we also use temporary cookies that are stored on your device for a specified period of time. If you visit our website again to use our services, it is automatically recognised that you have already visited us and which entries and settings you have made, so that you do not have to enter them again.

We also use cookies to record the use of our website statistically and to evaluate our services for you for the purpose of optimisation. These cookies enable us to automatically recognise that you have already visited our website when you visit it again. The cookies set in this way are automatically deleted after a defined period. The respective storage period of the cookies can be found in the settings of the consent tool used.

‍

9. Content of our website

‍

9.1 Contacting us / contact form

Personal data are collected when you contact us (e.g. via the contact form or by e-mail). The data collected when a contact form is used can be seen from the respective contact form. These data are stored and used exclusively for the purpose of responding to your enquiry or for establishing contact and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your enquiry pursuant to Art. 6(1)(f) GDPR. If your contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6(1)(b) GDPR. Your data will be deleted once your enquiry has been fully processed; this is the case when it can be inferred from the circumstances that the matter in question has been conclusively resolved and there are no statutory retention obligations preventing deletion.

‍

10. Web analytics

‍

10.1 Google Analytics 4 (GA4)

On our websites, we use Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

In this context, pseudonymised usage profiles are created and cookies (see the section "Cookies") are used. The information generated by the cookie about your use of this website may include, among other things:

  • brief recording of the IP address without permanent storage
  • Location data
  • Browser type/version
  • Operating system used
  • Referrer URL (previously visited page)
  • Time of the server request

The pseudonymised data may be transferred by Google to a server in the USA and stored there.

The information is used to evaluate the use of the website, to compile reports on website activity and to provide further services related to website and internet usage for the purposes of market research and the needs-based design of these websites. This information may also be transferred to third parties where required by law or where third parties process this data on our behalf.

These processing operations take place exclusively if express consent has been given in accordance with Art. 6(1)(a) GDPR.

The data retention period preset by Google is 14 months. Otherwise, the personal data are retained for as long as they are necessary to fulfil the purpose of processing. The data are deleted as soon as they are no longer required to achieve the purpose.

The parent company Google LLC, as a US company, is certified under the EU-US Data Privacy Framework. There is therefore an adequacy decision pursuant to Art. 45 GDPR, so that personal data may be transferred without further guarantees or additional measures.

Further information on data protection when using GA4 can be found at: https://support.google.com/analytics/answer/12017362?hl=de.

‍

11. Plugins and other services

‍

11.1 Google Tag Manager

On this website, we use the Google Tag Manager service. The operating company of Google Tag Manager is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies headquartered at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

This tool allows "website tags" (i.e. keywords embedded in HTML elements) to be implemented and managed via an interface. By using Google Tag Manager, we can automatically track which button, link or personalised image you have actively clicked on and can then record which content on our website is of particular interest to you.

The tool also triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If you have carried out a deactivation at domain or cookie level, it remains in place for all tracking tags implemented with Google Tag Manager.

These processing operations take place exclusively if express consent has been given in accordance with Art. 6(1)(a) GDPR.

The parent company Google LLC, as a US company, is certified under the EU-US Data Privacy Framework. There is therefore an adequacy decision pursuant to Art. 45 GDPR, so that personal data may be transferred without further guarantees or additional measures.

Further information on Google Tag Manager and Google's privacy policy can be found at: https://www.google.com/intl/de/policies/privacy/.

‍

11.2 Google WebFonts

Our website uses so-called web fonts to ensure the uniform display of fonts. Google WebFonts are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google group of companies headquartered at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

These processing operations take place exclusively if express consent has been given in accordance with Art. 6(1)(a) GDPR.

The parent company Google LLC, as a US company, is certified under the EU-US Data Privacy Framework. There is therefore an adequacy decision pursuant to Art. 45 GDPR, so that personal data may be transferred without further guarantees or additional measures.

Further information on Google WebFonts and Google's privacy policy can be found at: https://developers.google.com/fonts/faq ; https://www.google.com/policies/privacy/.

‍

11.3 Google Hosted Libraries

On our website, we use Google Hosted Libraries, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Hosted Libraries provides frequently used open-source program libraries, in particular JavaScript libraries, via a content delivery network. For this purpose, files are embedded on our website via the domain ajax.googleapis.com.

When you call up a page in which such a program library is embedded, your browser establishes a connection to Google's servers in order to retrieve the respective file. In particular, your IP address as well as technical connection and device information may be transmitted to Google and processed by Google.

Google Hosted Libraries are embedded exclusively if you have given your express consent in accordance with Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future.

Insofar as personal data are transferred to the parent company Google LLC in the USA, Google LLC is certified under the EU-US Data Privacy Framework. The adequacy decision of the European Commission pursuant to Art. 45 GDPR can therefore be relied upon for such data transfers.

Further information on Google Hosted Libraries and on data protection at Google can be found at: https://developers.google.com/speed/libraries and https://policies.google.com/privacy.

‍

12. Your rights as a data subject

‍

12.1 Right to confirmation

You have the right to request confirmation from us as to whether personal data concerning you are being processed.

‍

12.2 Right of access, Art. 15 GDPR

You have the right to obtain from us, at any time and free of charge, information about the personal data stored about you as well as a copy of these data in accordance with the statutory provisions.

‍

12.3 Right to rectification, Art. 16 GDPR

You have the right to request the rectification of inaccurate personal data concerning you. Furthermore, taking into account the purposes of the processing, you have the right to request the completion of incomplete personal data.

‍

12.4 Erasure, Art. 17 GDPR

You have the right to request that we erase the personal data concerning you without undue delay, provided that one of the statutory grounds applies and insofar as the processing or storage is not necessary.

‍

12.5 Restriction of processing, Art. 18 GDPR

You have the right to request that we restrict processing if one of the statutory conditions is met.

‍

12.6 Data portability, Art. 20 GDPR

You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format. You also have the right to transmit these data to another controller without hindrance from us, to whom the personal data have been provided, where the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and the processing is carried out by automated means, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.

Furthermore, in exercising your right to data portability pursuant to Art. 20(1) GDPR, you have the right to have the personal data transmitted directly from one controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.

‍

12.7 Objection, Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) GDPR (data processing in the public interest) or Art. 6(1)(f) GDPR (data processing based on a balancing of interests).

This also applies to profiling based on these provisions within the meaning of Art. 4(4) GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

In individual cases, we process personal data for the purpose of direct marketing. You may object at any time to the processing of personal data for the purpose of such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, we will no longer process the personal data for these purposes.

In addition, you have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you which is carried out by us for scientific or historical research purposes or for statistical purposes pursuant to Art. 89(1) GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.

In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you are free to exercise your right to object by automated means using technical specifications.

‍

12.8 Withdrawal of consent under data protection law

You have the right to withdraw consent to the processing of personal data at any time with effect for the future.

‍

12.9 Complaint to a supervisory authority

You have the right to lodge a complaint about our processing of personal data with a supervisory authority responsible for data protection.

‍

13. Routine storage, erasure and blocking of personal data

We process and store your personal data only for the period necessary to achieve the purpose of storage or insofar as this is provided for by the legal provisions to which our company is subject.

If the purpose of storage no longer applies or if a prescribed storage period expires, the personal data will be routinely blocked or erased in accordance with the statutory provisions.

‍

14. Duration of storage of personal data

The criterion for the duration of storage of personal data is the respective statutory retention period. After this period has expired, the corresponding data are routinely erased, provided they are no longer required for the performance or initiation of a contract.

‍

15. Validity and amendments to this privacy policy

‍

This privacy policy is currently valid and was last updated in August 2026.

As a result of the further development of our websites and services, or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version of the privacy policy can be accessed and printed by you at any time on the website at "https://ava-twins.com/datenschutz".

This privacy policy was created with the support of the data protection software audatis MANAGER.

Sign up so you never miss any news:

Deine Anmeldung konnte nicht gespeichert werden. Bitte versuche es erneut.
Deine Einreichung war erfolgreich.

How it worksUse CasesPricingBook a demo
About usBlogContact
Privacy policyLegal noticeTerms & conditions

A brand of:

Developed with:

© 2026 IWD market research GmbH
ava-twins.com