Privacy Policy
Last updated: 9 July 2026
1. Preamble
This privacy policy informs you which types of personal data (“data”) we process, for which purposes, and to what extent. It applies to all processing of personal data carried out by us – in connection with our services as well as on our websites, in our web projects (SaaS offerings, WordPress plugins and tools/apps), on our blogs, and within our social media profiles (collectively, the “online offering”).
2. Controller
Andreas Winkler, Dipl.-Ing.
ADENION GmbH
Merkatorstraße 2
41515 Grevenbroich
Germany
3. Overview of Processing Activities
Categories of data subjects
Users of our websites, web projects, blogs and social media channels; customers and clients; prospective customers; business and cooperation partners; communication partners.
Purposes of processing
Provision of our online offering and its functions; performance of contractual services; communication and customer support; marketing and reach measurement; security of our IT infrastructure; affiliate tracking; review and feedback procedures; business, organizational and administrative processes.
Relevant legal bases (GDPR)
- Consent, Art. 6(1)(a) GDPR
- Performance of a contract / pre-contractual inquiries, Art. 6(1)(b) GDPR
- Legal obligation, Art. 6(1)(c) GDPR
- Legitimate interests, Art. 6(1)(f) GDPR
National data protection provisions also apply in addition, in particular the German Federal Data Protection Act (BDSG).
4. Disclosure of Data and International Transfers
We only disclose data where this is necessary for the performance of a contract, due to legal obligations, or on the basis of legitimate interests – for example, to service providers engaged for IT tasks or providers of embedded services. We enter into the necessary agreements with these parties to protect your data.
Where data is transferred to third countries (outside the EU/EEA), we ensure an adequate level of data protection – for US providers, generally via the Data Privacy Framework (DPF) as well as additionally via the European Commission's Standard Contractual Clauses. We provide separate information on the transfer basis for the respective services.
Further information: https://www.dataprivacyframework.gov/ and https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en
5. Storage and Deletion of Data
We delete personal data as soon as the underlying consent is withdrawn or there is no longer any legal basis for further processing – unless statutory retention obligations dictate otherwise. The following retention periods apply in particular to documents relevant under German commercial and tax law:
| Period | Documents | Legal basis |
|---|---|---|
| 10 years | Books, annual financial statements, inventories, management reports | § 147 AO, § 257 HGB |
| 8 years | Accounting vouchers, e.g. invoices | § 147 AO, § 257 HGB |
| 6 years | Other business correspondence, tax-relevant documents | § 147 AO, § 257 HGB |
| 3 years | Warranty and contractual claims | §§ 195, 199 BGB |
6. General Notices Regarding Our Websites, Web Projects, Blogs and Social Media Activities
This section applies to our websites, SaaS projects, WordPress plugins and tools/apps, blogs and our social media channels, unless otherwise specified in the relevant product section (Section 7).
6.1 Hosting, Server Log Files and SSL Encryption
To operate our online offering, we use storage space and computing capacity from the following hosting providers (legal basis in each case: legitimate interests, Art. 6(1)(f) GDPR):
- Host Europe GmbH, Hansestraße 111, 51149 Cologne, Germany – www.hosteurope.de
- Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp, Germany – www.mittwald.de
- 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany – www.ionos.de
Access to our online offering is logged in server log files (including IP address, page accessed, date/time, browser type, referrer URL) and serves the security and stability of our systems. Log files are deleted or anonymized after a maximum of 30 days, unless required for evidentiary purposes. We use SSL/TLS encryption (HTTPS) to secure data transmission.
6.2 Cookies and Consent Management
We use cookies in accordance with statutory requirements – technically necessary cookies on the basis of legitimate interests (Art. 6(1)(f) GDPR), all other cookies only with prior consent (Art. 6(1)(a) GDPR). Session cookies are deleted when the browser is closed; permanent cookies may be stored for up to two years.
We use a cookie consent solution to obtain, manage, and allow withdrawal of consent. This solution stores the consents given (time, scope, device and browser information, pseudonymous user identifier) for up to two years in order to be able to demonstrate proof of consent. Consent can be withdrawn at any time via the cookie settings.
6.3 Reach Measurement: Google Analytics and Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics is used for the pseudonymous analysis of the use of our online offering (including content accessed, time spent, technical device data, approximate geographic origin). IP addresses are truncated prior to any further processing (IP masking); individual IP addresses of EU users are not stored. Legal basis: consent (Art. 6(1)(a) GDPR). Privacy policy: business.safety.google/privacy · Opt-out: tools.google.com/dlpage/gaoptout
Google Tag Manager manages the integration of website tags and services; in doing so, the user's IP address is transmitted to Google for technical reasons. Legal basis: consent (Art. 6(1)(a) GDPR).
For both services: third-country transfer on the basis of the Data Privacy Framework (DPF) as well as additionally Standard Contractual Clauses.
6.4 Google Ads, Remarketing and Other Advertising Services
We use Google Conversion Tracking and Google Remarketing as well as comparable services (e.g. Meta/Facebook, Quora) for marketing purposes on the basis of your consent. You can object to or opt out of this via the respective provider's settings (e.g. myadcenter.google.com).
6.5 Registration and User Account
Users may create a user account to use personalized services (login data: username, password, email address; where applicable, name, address, phone number). We also store the IP address and time of registration to protect against misuse. Registered users may view, change or delete their data at any time. Upon termination of the user account, we delete the data unless statutory retention obligations apply. Legal bases: performance of a contract (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
6.6 Contact
When you contact us (contact form, email, telephone, mail, social media), we process the information provided (including name, contact details, content of the inquiry) in order to handle your request. Legal bases: performance of a contract or pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
6.7 Newsletter and Other Electronic Notifications
We send newsletters only with the recipient's consent (Art. 6(1)(a) GDPR) or on another legal basis. As a rule, only your email address is required; additional information (e.g. name) is used for personal address. We may retain unsubscribed email addresses for up to three years on the basis of legitimate interests in order to demonstrate proof of previously given consent, or on a suppression list to permanently honor objections.
You can unsubscribe from the newsletter at any time via the unsubscribe link at the bottom of each email or using the contact details given in Section 8.
6.8 Payment Processing
For payment transactions, we use the following payment service providers, which process account, banking and transaction data solely for the purpose of payment processing (legal basis: performance of a contract, Art. 6(1)(b) GDPR):
- Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA – stripe.com/privacy (third-country transfer: DPF)
- PayPro Global Inc., Toronto, Canada (for Blog2Social and Assistini subscriptions)
- Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Republic of Ireland – apple.com/legal/privacy (for in-app purchases and subscriptions in our iOS apps; third-country transfer: Standard Contractual Clauses)
- Google Commerce Limited, Gordon House, Barrow Street, Dublin 4, Ireland – policies.google.com/privacy (for in-app purchases and subscriptions in our Android apps; third-country transfer: DPF, Standard Contractual Clauses)
We do not receive any payment or card data of users from Apple or Google, only a confirmation of successful completion of the transaction.
6.9 Blogs and Publication Media
We operate blogs to inform you about our services. We process readers' data only to the extent necessary for the presentation of the blog, for communication between authors and readers, or for security reasons. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
6.10 Social Media: Our Own Profiles and Embedded Social Plugins
We maintain profiles on social networks and embed social media buttons (“social plugins”) in our online offering. When a user visits a page containing a plugin, the browser connects directly to the server of the respective network; if the user is logged in there, the visit may be attributed to their account. For our own profiles (“fan pages”), we may be jointly responsible with the respective provider for the collection of visitor statistics (“insights”); further processing is the sole responsibility of the provider. You may assert data subject rights either with us or directly with the respective provider. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
| Network | Provider | Privacy policy |
|---|---|---|
| Facebook / Instagram / Threads / WhatsApp | Meta Platforms Ireland Ltd. (profiles) or Meta Platforms, Inc. (plugins) | facebook.com/privacy/policy · privacycenter.instagram.com/policy |
| X (Twitter) | X Internet Unlimited Company, Dublin | x.com/privacy |
| LinkedIn Ireland Unlimited Company, Dublin | linkedin.com/legal/privacy-policy | |
| Pinterest Europe Limited, Dublin | policy.pinterest.com/privacy-policy | |
| YouTube / Google Business | Google Ireland Limited, Dublin | business.safety.google/privacy |
| New Work SE, Hamburg | privacy.xing.com/datenschutzerklaerung | |
| Bluesky | Bluesky PBLLC, USA | bsky.social/about/support/privacy-policy |
| TikTok | TikTok Technology Ltd., Dublin | tiktok.com/legal/privacy-policy |
| Reddit Inc., USA | redditinc.com/policies/privacy-policy | |
| Discord | Discord Inc., USA | discord.com/privacy |
| Telegram | Telegram FZ-LLC, Dubai | telegram.org/privacy |
| Tumblr | Automattic Inc., USA | tumblr.com/privacy |
| Vimeo | Vimeo Inc., USA | vimeo.com/privacy |
| Mastodon | depends on instance (e.g. Mastodon gGmbH, Berlin) | mastodon.social/privacy-policy |
| Diigo / Instapaper | Diigo Inc. / Instant Paper Inc., USA | diigo.com/terms · instapaper.com/privacy |
Anyone who does not want a network to collect data about them via our website should not be logged into the respective network before visiting the website.
6.11 Affiliate Program
We offer an affiliate program: users (“affiliates”) who refer visitors to our services by means of an individual affiliate link or discount code receive a commission for doing so. To track whether use of our services is based on such a referral, we process the usage and contract data necessary for this purpose. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
6.12 Customer Reviews and Rating Procedures
We participate in rating procedures to evaluate and promote our services. To verify that reviewers have actually used our services, we transmit, with the customer's consent, the data required for this purpose (e.g. name, email address, order number) to the respective review platform; the platform's own terms of use and privacy notices also apply. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
6.13 Embedded Third-Party Content and Functions
We embed third-party content (e.g. graphics, videos, maps). To do so, the respective provider necessarily processes users' IP addresses; in some cases, pixel tags or cookies are additionally used for statistical or marketing purposes. Legal basis: consent (Art. 6(1)(a) GDPR) where required, otherwise legitimate interests (Art. 6(1)(f) GDPR).
6.14 Management and Organizational Tools
To organize, manage and provide our services, we use software and platforms from third-party providers, whose servers may process personal data (including master and contact data, transaction data). Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
7. Product-Specific Privacy Notices
The following product-specific notices apply in addition to Section 6 for the respective products.
7.1 PR-Gateway
As part of our PR services (PR-Gateway and connected online press portals), users provide personal data intended for press work or for publication within press releases (in particular contact details). This data is passed on to third-party portals for the purpose of publication; where selected by the user, this may also include portals outside the European Union. Legal basis: performance of a contract (Art. 6(1)(b) GDPR); where a third-country transfer is involved, additionally consent (Art. 6(1)(a) GDPR).
7.2 Blog2Social (SaaS, WordPress Plugin and Web App)
Blog2Social is a social media management tool for publishing content on social networks.
Connecting to social networks: When a user connects their account to a social network in the admin area, the following data is collected, depending on the network: network account ID, access and refresh tokens, page/group ID and name, network account name and, where applicable, password. By connecting, the user acknowledges the terms of use and privacy notices of the respective network (including YouTube/Google, Facebook, Instagram, Threads, LinkedIn, XING, X, Bluesky, Medium, Tumblr, Vimeo, TikTok, Google Business, Pinterest, VKontakte, HumHub, Bloglovin, Torial, Flickr, Reddit, Telegram, Ravelry, Instapaper, Diigo, Blogger, Discord). We provide the current links to the terms of use and privacy policies of the supported networks separately. Network connections can be deleted at any time in the plugin or web app and can additionally be revoked in the security settings of the respective network (e.g. security.google.com/settings/security/permissions).
Blog2Social plugin and apps: Within the Blog2Social apps, the following personal data of the user is collected where paid services are used: email address, user ID and URL; a unique user ID is generated from this data for technical purposes.
Registration for paid services (premium versions):When registering for premium services in the admin area, we collect email address, name, address and, where applicable, payment/account data. Payment service provider: see Payment Processing.
7.3 AI Tools (Assistini, AI Knowledge Base and Other Tools/Apps)
Some of our AI tools and apps – including the Assistini WordPress plugin and the AI knowledge base – offer AI-powered functions based on different language model providers. Depending on the tool, users can choose between several providers, including:
- OpenAI: OpenAI, Inc., 3180 18th St, San Francisco, CA 94110, USA – openai.com/privacy
- Google Gemini: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland – policies.google.com/privacy
- Anthropic Claude: Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA – privacy.claude.com
- Replit, Inc., 1001 E Hillsdale Blvd, Foster City, CA 94404, USA – replit.com/site/privacy; data processing agreement: replit.com/dpa
The technical processing differs depending on the tool: in some cases, input is forwarded to the respective provider via our interface, without us permanently storing the content; in other cases, the user submits their input directly to the provider of their choice, in some cases using their own access credentials provided by the user. Where processing takes place directly between the user and the provider, we have no influence over, and no knowledge of, the content transmitted; in this case, sole responsibility for this processing lies with the respective provider. Our legal basis is consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time by deactivating the respective function.
8. Your Rights to Access, Rectification, Restriction, Erasure and Objection
As a data subject, you have the following rights under Articles 15 to 21 GDPR:
- Right to obtain access to the personal data we hold about you (Art. 15 GDPR)
- Right to request rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR)
- Right to request erasure of your data (Art. 17 GDPR)
- Right to request restriction of processing (Art. 18 GDPR)
- Right to receive your data in a structured, commonly used, machine-readable format (Art. 20 GDPR)
- Right to object, on grounds relating to your particular situation, to processing (Art. 21 GDPR)
- Right to lodge a complaint with a supervisory authority: without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
In order for a restriction on data to be observed at any time, such data must be retained in a restricted file for control purposes. You may also request erasure of the data, provided there is no statutory obligation to archive it, the data was not provided for the purpose of widespread distribution on the internet, the media privilege applies, or ADENION has no direct influence over the data (e.g. deletion from third-party internet portals). Where an obligation exists, we will restrict your data upon request.
You may make changes to, or withdraw, a consent at any time by notifying us, with effect for the future.
Right of Withdrawal for Newsletter and Email Communication
If you wish to withdraw this consent, you will find a link at the bottom of every email allowing you to unsubscribe. Alternatively, you may send us an email specifying the email address to which you no longer wish to receive product updates, etc.

Alternatively, you may send us a letter at:
ADENION GmbH
Merkatorstraße 2
41515 Grevenbroich
Germany
Please always state the email address you registered with, as well as the service you wish to cancel or for which you wish to withdraw consent.
9. Changes and Updates to This Privacy Policy
We will adapt this privacy policy whenever changes to our data processing make this necessary, and we will inform you if this requires you to take any action on your part (e.g. renewed consent). Please check the content of this policy regularly.
