Privacy Policy

Welcome to WERK. We are delighted that you are interested in our website (https://werk.store). Protecting your privacy is very important to us. To ensure you feel secure when visiting our websites, we strictly adhere to the legal provisions when processing your personal data and would like to provide you with detailed information here about how we handle your data.

Personal data is information relating to an identified or identifiable individual. This primarily includes details that allow conclusions to be drawn about your identity, such as your name, telephone number, postal address or email address. Statistical data that we collect, for example, when you visit our website and which cannot be linked to you personally, does not fall within the definition of personal data.

You can print or save this privacy policy by using the standard functions of your browser.

1. Data controller

The contact person and the so-called data controller responsible for processing your personal data when you visit our websites, within the meaning of the EU General Data Protection Regulation (GDPR), is:

AIO digital services GmbH
Schloßstr. 19
82031 Grünwald
Germany

Telephone: +49 89 215 422 925
Email: info@aiofficer.de

If you have any questions regarding data protection, you can contact our Data Protection Officer at any time. They can be reached at the postal address above and at the email address provided above (please mark your correspondence 'For the attention of the Data Protection Officer').

2. Data processing on our websites

2.1. Visiting our website / access data

Whenever you use our websites, we collect the access data that your browser automatically transmits to enable you to visit the website. The access data includes, in particular:

  • IP address of the requesting device
  • Date and time of the request
  • Address of the website accessed and the requesting website
  • Details of the browser and operating system used
  • Online identifiers (e.g. device identifiers, session IDs)

The processing of this access data is necessary to enable you to visit the website and to ensure the ongoing functionality and security of our systems. The access data is also temporarily stored in internal log files for the purposes described above, in order to compile statistical information on the use of our website, to further develop our website in line with our visitors' usage habits, and to carry out general administrative maintenance of our website. The legal basis is Article 6(1), first sentence, point (f) of the GDPR.

The information stored in the log files does not allow any direct identification of you – in particular, we store IP addresses only in a truncated, anonymised form. The log files are stored for 30 days and archived following anonymisation.

2.2. Contact

If you contact us by email, telephone or via the contact form on our websites, we will process the personal data you provide in order to deal with your enquiry. The data collected via the contact form is determined by the respective input fields.

The data you provide will be processed exclusively for the purpose of handling your enquiry, as well as for further communication and any follow-up questions.

The legal basis for processing in these cases is the performance of our services and the fulfilment of contractual obligations in accordance with Article 6(1), first sentence, point (b) of the GDPR, as well as processing to safeguard our legitimate interests in accordance with Article 6(1), first sentence, point (f) of the GDPR.

2.3. Registration and use of the learning platform

You have the option to register in the login area of our learning platform (werk.store) in order to use the functions and content offered there. We have highlighted the data you are required to provide by marking these as mandatory fields. Registration is not possible without this data. The legal basis for the processing is Article 6(1)(b) of the GDPR.

In addition, we set up a personal user account for participants who book a training course with us, insofar as this is necessary for the delivery of the booked training course and the use of the learning platform.

In connection with registration and use of the learning platform, we process in particular:

  • Personal details (e.g. name, email address, company, and, where applicable, company address and details)
  • Login details (username, encrypted password)
  • Information about booked training courses and learning progress
  • Provision and management of training content and learning materials
  • Participation information, as well as certificates and certificates of attendance

Processing is carried out for the purpose of providing and managing the user account, conducting booked training courses, providing learning content and communicating with participants. The legal basis for the processing is Article 6(1), first sentence, point (b) of the GDPR.

2.4. Pre-filling of company data (OffeneRegister.de)

To retrieve company data from the commercial register, we use the OffeneRegister.de service provided by Open Knowledge Foundation Deutschland e.V., Singerstr. 109, D-10179, Berlin, Germany.

When you enter your company name during registration, an API call is made to retrieve the company data from the commercial register so that the registration form can be pre-filled. The category of personal data that we process in this context is your company affiliation.

The legal basis for this processing is our legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to provide you with an optimal, user-friendly registration process. The data collected will be deleted once the purpose has been fulfilled. Further information on data processing at OffeneRegister.de can be found at: https://offeneregister.de/

3. Use of cookies

To make your visit to our websites more engaging and to enable the use of certain features, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e. once you close your browser (so-called session cookies). Other cookies remain on your device and enable us to recognise your browser the next time you visit (persistent cookies).

You can configure your browser so that you are notified when cookies are set and can decide on a case-by-case basis whether to accept them, or you can block the acceptance of cookies in specific cases or generally. If you do not accept cookies, the functionality of our website may be restricted. Our cookies do not store any sensitive data such as passwords, credit card details or similar information, and do not cause any damage to your device.

Cookies that are necessary for carrying out the electronic communication process or for providing specific functions you have requested (e.g. login function, language settings) are stored on the basis of Article 6(1)(f) of the GDPR.

3.1. Use of technically necessary cookies

We use technically necessary cookies in particular:

  • for login authentication;
  • for load balancing;
  • to save your language settings;
  • to record that a piece of information displayed on our website has been shown to you – so that it is not displayed again the next time you visit the website.

These services are based on our legitimate interests. The legal basis is Article 6(1), first sentence, point (f) of the GDPR.

4. Integrated third-party services

4.1. Cloudflare Turnstile

We use Cloudflare Turnstile on our websites, a service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA ("Cloudflare"). Cloudflare Turnstile is used to determine whether entries on our websites (e.g. via contact forms) are made by a natural person or by automated programmes (bots). This enables us to protect our websites from abusive enquiries, spam and automated attacks.

To this end, Cloudflare processes various technical details, in particular the user's IP address and other characteristics of their interaction with the website. The analysis takes place automatically when pages on which Turnstile is integrated are accessed. The information collected in this process is transmitted to Cloudflare and analysed there. The processing is carried out on the basis of Article 6(1)(f) of the GDPR.

Cloudflare processes the data on our behalf on the basis of a data processing agreement. Data is transferred to the USA in accordance with the EU-US Data Privacy Framework (DPF) and the European Commission's Standard Contractual Clauses. Further information on data protection at Cloudflare can be found at: www.cloudflare.com/privacypolicy/

4.2. Video and social media embeds

Where references are made to content on third-party platforms (e.g. LinkedIn, YouTube or other platforms), this is done exclusively via external links. Such links explicitly state that clicking on them will redirect you to the website of the respective third-party provider.

You will only leave our website once you have clicked on an external link. The processing of personal data on the linked pages is governed exclusively by the privacy and terms of use policies of the respective provider.

5. Disclosure of data

We will only disclose the data we have collected if:

  • you have given your explicit consent in accordance with Article 6(1), first sentence, point (a) of the GDPR,
  • the disclosure is necessary, in accordance with Article 6(1), first sentence, point (f) of the GDPR, for the establishment, exercise or defence of legal claims, and there is no reason to believe that you have an overriding legitimate interest in preventing the disclosure of your data,
  • we are legally obliged to disclose the data under Article 6(1), first sentence, point (c) of the GDPR, or
  • this is permitted by law and necessary under Article 6(1), first sentence, point (b) of the GDPR for the performance of contractual relationships or for the implementation of pre-contractual measures with you.

Some of the data processing may be carried out by our service providers. In addition to the service providers mentioned in this privacy policy, these may include, in particular, data centres that host our website and databases, IT service providers that maintain our systems, and consultancy firms. Where we disclose data to our service providers, they may use the data solely for the purpose of fulfilling their tasks. We have carefully selected and commissioned these service providers. They are contractually bound by our instructions, have appropriate technical and organisational measures in place to protect the rights of data subjects, and are regularly monitored by us.

Furthermore, data may be disclosed in connection with requests from public authorities, court orders and legal proceedings where this is necessary for the pursuit or enforcement of legal claims.

5.1. Hosting and email dispatch

The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services and technical maintenance services, which we utilise for the purpose of operating this online service. In this context, we, or our hosting provider, process personal data, contact details, content data, contractual data, usage data, metadata and communication data relating to customers, prospective customers and visitors to this online service on the basis of our legitimate interests in the efficient and secure provision of this online service in accordance with Article 6(1)(f) of the GDPR in conjunction with Article 28 of the GDPR (conclusion of a data processing agreement).

5.2. Transfers to third countries

Should we use services from providers whose registered offices are partly located in so-called third countries – that is, countries whose level of data protection does not correspond to that of the European Union – the following applies: Where this is the case and the European Commission has not adopted an adequacy decision (Article 45 of the GDPR) for these countries, we have taken appropriate measures to ensure an adequate level of data protection for any data transfers. These include, amongst other things, the European Union's standard contractual clauses or binding internal data protection regulations. Where this is not possible, we base the data transfer on the exceptions set out in Article 49 of the GDPR, in particular your explicit consent or the necessity of the transfer for the performance of a contract. Where a transfer to a third country is envisaged and no adequacy decision or suitable safeguards are in place, it is possible that authorities in the relevant third country (e.g. intelligence services) may gain access to the transferred data and that the enforceability of your rights as a data subject cannot be guaranteed. You will also be informed of this when your consent is sought.

6. Retention period

As a general rule, we only store personal data for as long as is necessary to fulfil the contractual or legal obligations for which we collected the data. Thereafter, we delete the data without delay, unless we still require the data until the expiry of the statutory limitation period for the purposes of providing evidence in civil law claims or due to statutory retention obligations.

For evidential purposes, we must retain contractual data for a further three years from the end of the year in which our business relationship with you ends. Any claims become time-barred at the earliest at this point, in accordance with the standard statutory limitation period.

Even after that, we may still need to retain some of your data for accounting purposes. We are obliged to do so due to statutory documentation requirements, which may arise from the German Commercial Code, the German Fiscal Code, the German Banking Act, the Money Laundering Act and the German Securities Trading Act. The retention periods for documents specified in these laws range from two to ten years.

7. Your rights

You have the right at any time to request information about our processing of your personal data. When providing this information, we will explain the data processing to you and provide an overview of the data stored about you.

If any data stored by us is incorrect or out of date, you have the right to have this data rectified.

You may also request the erasure of your data. Should erasure be exceptionally impossible due to other legal provisions, the data will be blocked so that it is only available for that specific legal purpose.

You may also have the processing of your data restricted, for example if you believe that the data we hold is incorrect. You also have the right to data portability, meaning that, upon request, we will provide you with a digital copy of the personal data you have supplied.

To exercise the rights described here, you may contact us at any time using the contact details provided above. This also applies if you wish to receive copies of guarantees demonstrating an adequate level of data protection.

Furthermore, you have the right to object to data processing based on Article 6(1)(e) or (f) of the GDPR. Finally, you have the right to lodge a complaint with the data protection supervisory authority responsible for us. You may exercise this right with a supervisory authority in the Member State of your residence, your place of work or the place where the alleged infringement occurred. Supervisory authority responsible for Grünwald: Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach

8. Right to withdraw consent and right to object

In accordance with Article 7(2) of the GDPR, you have the right to withdraw your consent at any time. As a result, we will no longer continue the data processing that was based on this consent in future. Withdrawing your consent does not affect the lawfulness of the processing carried out on the basis of your consent up until the time of withdrawal.

Where we process your data on the basis of legitimate interests pursuant to Article 6(1), first sentence, point (f) of the GDPR, you have the right, under Article 21 of the GDPR, to object to the processing of your data, provided there are grounds arising from your particular situation or the objection relates to direct marketing. In the latter case, you have a general right to object, which we will honour even without you giving reasons.

If you wish to exercise your right to withdraw consent or to object, an informal notification sent to the contact details given above will suffice.

9. Data security

We maintain up-to-date technical measures to ensure data security, in particular to protect your personal data from risks during data transmission and from access by third parties. These measures are regularly updated in line with the current state of the art. To secure the personal data you provide on our website, we use Transport Layer Security (TLS), which encrypts the information you enter.

10. Changes to the Privacy Policy

We occasionally update this privacy policy, for example when we make changes to our websites or when legal or regulatory requirements change. The latest version is available on our websites.

Version: 2.0 / Date: June 2026