Our Privacy Policy

Privacy Policy – taod.de

Privacy Policy

Thank you for your interest in our website www.taod.de. Protecting your personal data is important to us. Below we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), about which data we process, for what purposes and on what legal basis.

1. Controller

The controller within the meaning of the GDPR and other data protection provisions is:

taod Consulting GmbH
Oskar-Jäger-Str. 173, K4
50825 Cologne, Germany
Phone: +49 (0)221 – 975 849-70
E-mail: info@taod.de

Authorised managing directors: Simon Biela, Matthias Steinforth, Benedikt Stienen
Register court: Local Court of Cologne (Amtsgericht Köln), HRB 95089
VAT identification number: DE 300203432

2. Data Protection Officer

You can reach our external Data Protection Officer at:

Frank Gundlach
GCS – Geno Corporate Services GmbH
Türkenstraße 22–24
80333 Munich, Germany
Phone: +49 89 2868-5180
E-mail: info@taod.de

3. General Information on Data Processing

Personal data is any information relating to an identified or identifiable natural person. We generally process our users' personal data only to the extent necessary to provide a functional website as well as our content and services, or where you have given your consent.

Legal bases

  • Art. 6(1)(a) GDPR (consent) – for processing operations to which you have consented, in particular for non-essential cookies and tracking;
  • Art. 6(1)(b) GDPR – for the performance of a contract or pre-contractual measures (e.g. handling enquiries);
  • Art. 6(1)(c) GDPR – for compliance with legal obligations;
  • Art. 6(1)(f) GDPR – to safeguard our legitimate interests (e.g. secure and stable operation of the website).

Where consent is required for storing information on, or accessing information already stored in, your end device, Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) applies in addition.

4. Your Rights as a Data Subject

You have the following rights regarding the personal data concerning you:

  • Right of access (Art. 15 GDPR);
  • Right to rectification (Art. 16 GDPR);
  • Right to erasure (Art. 17 GDPR);
  • Right to restriction of processing (Art. 18 GDPR);
  • Right to data portability (Art. 20 GDPR);
  • Right to object to processing (Art. 21 GDPR);
  • Right to withdraw consent given at any time with effect for the future (Art. 7(3) GDPR).

To exercise your rights, an informal message to the contact details above is sufficient.

Right to object

Where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing; this also applies to profiling based on that provision. Where data is processed for the purpose of direct marketing, you may object to the processing at any time without giving reasons.

Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany

5. Hosting

The content of our website is delivered via Webflow's content delivery network; the provision of the domain and associated infrastructure is handled via Amazon Web Services (AWS). Personal data collected on this website is processed on these providers' servers. They are used for the secure, fast and reliable provision of our online offering on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Data processing agreements pursuant to Art. 28 GDPR are in place with each provider.

Webflow: The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. Privacy notice: https://webflow.com/legal/eu-privacy-policy

Amazon Web Services (AWS): The provider is Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg (parent company: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA). Privacy notice: https://aws.amazon.com/privacy/

Server log files

The provider automatically collects and stores information in so-called server log files, which your browser transmits automatically. These include in particular: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and IP address. This data is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR; we have a legitimate interest in the technically error-free presentation and security of our website.

6. Cookies and Consent Management

Our website uses cookies and comparable technologies (e.g. local storage). Cookies are small text files stored on your end device. Some cookies are technically necessary for the website to function; others serve statistical or marketing purposes and are only set with your consent.

Technically necessary cookies are processed on the basis of Art. 6(1)(f) GDPR and Section 25(2) TDDDG. All other cookies and services are used exclusively on the basis of your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you provide via our consent banner and may withdraw or adjust at any time with effect for the future.

consentmanager

To obtain and manage consent, we use the consent management platform consentmanager. The provider is consentmanager AB, Håltgelvägen 1b, 72348 Västerås, Sweden. consentmanager stores the settings you have made in order to take them into account on future visits. Processing is carried out to fulfil our legal obligation to document consent given (Art. 6(1)(c) GDPR) and on the basis of our legitimate interest in legally compliant consent management (Art. 6(1)(f) GDPR). Privacy notice: https://www.consentmanager.net/privacy/

7. SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the string "https://" in your browser's address bar.

8. Security and Bot Protection (Cloudflare)

We use services provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, to defend against attacks and to protect our forms. In particular, we use "Cloudflare Turnstile" to protect against automated input (cookie "cf.turnstile.u"). In addition, Cloudflare technologies are used by embedded third-party services (e.g. HubSpot), whereby technically necessary cookies (e.g. "__cf_bm", "_cfuvid") are set. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in security and availability). Privacy notice: https://www.cloudflare.com/privacypolicy/

9. Spam and Bot Protection (Google reCAPTCHA)

To protect our forms against misuse and spam, we use Google reCAPTCHA. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). reCAPTCHA analyses user behaviour based on various characteristics in order to distinguish humans from automated access; cookies or comparable technologies (e.g. "_GRECAPTCHA", "rc::a", "rc::f") may be set in this context. The legal basis is our legitimate interest in the security of our website (Art. 6(1)(f) GDPR). Privacy notice: https://business.safety.google/privacy/

10. Contact and Forms (HubSpot)

When you contact us via forms or e-mail, we process the data you provide (e.g. name, e-mail address, message) in order to handle your enquiry. For forms, CRM and parts of our website tracking we use HubSpot. The provider is HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland (parent company: HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA).

HubSpot sets cookies (e.g. "__hstc", "hubspotutk", "__hssc", "__hssrc") to analyse the use of our website and to attribute enquiries. The legal basis for handling enquiries is Art. 6(1)(b) or (f) GDPR; for tracking and non-essential cookies it is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Privacy notice: https://legal.hubspot.com/privacy-policy

11. Tag Management (Google Tag Manager)

We use Google Tag Manager provided by Google Ireland Limited (address as above). The Tag Manager is a tool that lets us manage and deploy tags (snippets of code). The Tag Manager itself does not create user profiles, but it can control the triggering of further tags that in turn collect data. Consent-requiring services controlled via the Tag Manager are only processed after your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); otherwise Art. 6(1)(f) GDPR applies. Privacy notice: https://business.safety.google/privacy/

12. Web Analytics and Reach Measurement

Google Analytics

With your consent, we use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Analytics uses cookies (e.g. "_ga", "_ga_*", "_gcl_au") that enable an analysis of website use. The information generated about your use is generally transmitted to and stored by Google. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://business.safety.google/privacy/

Microsoft Clarity

With your consent, we use Microsoft Clarity to analyse usage behaviour (e.g. session recordings, heatmaps). The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA). Clarity sets cookies (e.g. "_clck", "_clsk"). The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://privacy.microsoft.com/en-us/privacystatement

Hotjar

With your consent, we use Hotjar to analyse usage behaviour (e.g. clicks, mouse movements, scroll depth). The provider is Hotjar Ltd, Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville, St Julian's STJ 3141, Malta. Hotjar uses cookies and local storage (e.g. "_hjSessionUser_*", "_hjSession_*"). The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://www.hotjar.com/legal/policies/privacy/

13. Marketing and Conversion Tracking

Google Ads and Conversion Tracking

With your consent, we use Google Ads including conversion tracking and remarketing (provider: Google Ireland Limited, address as above). Cookies (e.g. "GCL_AW_P", "_gcl_aw") are set to measure the effectiveness of advertisements and to display interest-based advertising to you. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://business.safety.google/privacy/

Microsoft Advertising (Bing Ads)

With your consent, we use Microsoft Advertising (formerly Bing Ads) for conversion measurement and remarketing via Universal Event Tracking (UET). The provider is Microsoft Ireland Operations Limited (address as above). Cookies (e.g. "MUID", "_uetsid", "_uetvid") are set in this context. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://privacy.microsoft.com/en-us/privacystatement

Meta Pixel (Facebook/Instagram)

With your consent, we use the Meta Pixel for reach measurement and the delivery of advertising on Meta's platforms. The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (parent company: Meta Platforms, Inc., USA). Cookies (e.g. "_fbp") are set in this context. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://www.facebook.com/privacy/policy

Reddit Pixel

With your consent, we use the Reddit Pixel for conversion measurement and ad delivery. The provider is Reddit, Inc., 1455 Market Street, Suite 1600, San Francisco, CA 94103, USA. A cookie (e.g. "_rdt_uuid") is set in this context. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://www.reddit.com/policies/privacy-policy

LinkedIn Insight Tag and LinkedIn Ads

With your consent, we use services provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (parent company: LinkedIn Corporation / Microsoft, USA), in particular the LinkedIn Insight Tag, for conversion measurement, retargeting and reach analysis. Cookies (e.g. "bcookie", "li_gc", "lidc", "li_fat_id") are set in this context. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://www.linkedin.com/legal/privacy-policy

14. Embedding of YouTube Videos

With your consent, we embed videos from the YouTube platform (in extended privacy mode via youtube-nocookie.com). The provider is Google Ireland Limited (address as above). When playback starts, cookies (e.g. "VISITOR_INFO1_LIVE", "YSC") may be set and data may be transmitted to Google. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Privacy notice: https://business.safety.google/privacy/

15. Data Transfer to Third Countries

Some of the providers we use are based in the USA or process data there (in particular Google, Microsoft, Meta, Reddit, HubSpot, Cloudflare and LinkedIn/Microsoft). The USA does not offer a level of data protection equivalent to European law. Where providers are certified under the EU-US Data Privacy Framework (DPF), transfers are made on this basis. Otherwise, we base transfers to third countries on the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or on your explicit consent (Art. 49(1)(a) GDPR). Despite these measures, access by US authorities in particular cannot be entirely ruled out.

16. Storage Period

We process and store personal data only for as long as is necessary to achieve the respective purpose or as required by statutory retention periods. The storage period of individual cookies may vary (from the respective session up to several months). Cookie-related processing ends at the latest upon withdrawal of your consent.

17. Currency and Amendment of this Privacy Policy

This privacy policy is currently valid and dated June 2026. As our website develops or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy.

taod Consulting GmbH logo
Stay up to date with our monthly newsletter. All new white papers, blog articles and information included.
Subscribe to newsletter
Get exclusive knowledge for your data projects. In our print magazine data! Experienced data experts report directly from the world of data.
Data! subscribe
Headquarter Cologne

taod Consulting GmbH
Oskar-Jaeger-Strasse 173, K4
50825 Cologne‍
Hamburg location

taod Consulting GmbH
Alter Wall 32
20457 Hamburg‍
Stuttgart location

taod Consulting GmbH
Schelmenwasenstrasse 32
70567 Stuttgart
© 2026 all rights reserved