Information
Privacy
Cookies and settings on your device
Updated: 22 September 2026 · Consent version v1.
We do not use advertising or visitor tracking. You can use our website and portals without consenting to optional storage of display preferences. On the public website, the language follows the German or English page address; we do not store a language cookie for this.
Necessary cookies
We use technically necessary cookies for the sign-in and secure functions you request, under section 25(2)(2) TDDDG. These include alrc.portal for sign-in, .AspNetCore.Antiforgery.* for form security and, where applicable, orch_notify for short-lived feedback after a CMS action. They are not part of optional consent. Sign-in cookies are normally session cookies; selecting “Remember me” retains sign-in beyond the browser session. Authentication tickets are valid for 14 days by default and can be renewed during active use. Antiforgery cookies are session cookies; CMS messages are deleted after display.
When an administrator explicitly starts connecting Google Drive for backups, alrc-drive-authorization secures the authorization exchange. It lasts no more than ten minutes and is deleted on return.
Optional display preferences
Only after “Yes” do we store and read table widths and column order (alrc-columns-v1:*), the last admin portal area (alrc-admin-area) and CMS display preferences such as sidebar layout, colour scheme and media views (*-adminPreferences, *-theme, *-mediaApplicationPrefs, *-mediaFieldPrefs, *-mediaFieldGallery_*, and where applicable *-admintheme and admin_culture_*). These use Local Storage and, in the CMS, some cookies. Preferences are not synchronized across devices or used for advertising or visitor profiles. Storage and access rely on your consent under section 25(1) TDDDG and, where personal data are involved, Article 6(1)(a) GDPR.
Permission lasts up to 180 days from your selection. Afterwards, stored preferences are no longer used; Local Storage values are deleted on the next visit or next check in an open page. Choosing “No” leaves the portals usable. You can adjust views on the currently open page, but they are not remembered permanently. We do not send these preferences to external analytics or advertising services.
Changing your decision and withdrawing consent
You can choose “No” under “Device settings” at the bottom of the page, or at the bottom of the CMS navigation, at any time to withdraw consent for the future, as easily as you gave it. Existing optional values are removed. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal. Optional storage is disabled before a decision and after it expires.
The necessary alrc-preferences cookie records acceptance or rejection, the text version and expiry time for 180 days. It contains no individual tracking ID. It is used only to respect your decision (section 25(2)(2) TDDDG) and applies to the website and portals at the same web address in this browser profile. Clearing browser data removes the decision. We document the consent wording and technical procedures.
Usage data and billing
Usage and business statistics are derived from service usage, credit and billing records, not from tracking your browsing. These records support service delivery, billing and traceable transactions. Your display-preference choice does not affect this processing. Where personal data are involved, the legal basis depends on the purpose: Article 6(1)(b) GDPR (contract), (c) (legal obligations), or (f) (legitimate interests in traceable operational reporting). The contractual basis does not automatically extend to the personal data of a business customer's employees.
Usage records are currently not automatically anonymized after the billing month. Retention depends on purpose, necessary evidence and legal obligations. A specific period for anonymizing detailed usage records still needs to be defined and implemented; billing documents and records subject to legal retention must be treated separately.
Business registration verification
We use the company name, registered address, business email domain, company website and VAT identification number to verify eligibility for this business-only service and to prevent unauthorized registrations.
For companies in another EU country, we transmit the VAT number, company name, street, postal code and city to the European Commission's VIES service for VAT validity and company-data checks. The response, submitted company details and time of the check are stored with the registration for review and documentation. An administrator reviews registrations outside the EU and registrations that cannot be fully verified automatically.
Information about VIES is available from the European Commission.
The complete operator-specific privacy notice, including controller contact details, legal bases and retention periods, must be finalized before public launch.
Subscription checkout
For subscription payments, company billing name, address, billing email, the selected offer, tax settings and internal company/subscription references are transmitted to Stripe to create and administer a subscription. Payment details are entered on Stripe Checkout; this portal does not receive full card numbers or security codes.
We store the agreed offer and billing snapshot, Stripe checkout/subscription/invoice identifiers, paid amounts, billing periods and resulting credit entries for reconciliation. See Stripe’s privacy policy.