Last updated: 10 September 2026
1. Controller
Artemis Franchise GmbH
Andreas Pfeiffer (Managing Director)
Max-Planck-Str. 6-8, 50858 Köln, Germany
Email: info@artemis-franchise.com
Phone: 02234-2190063
Data protection officer: we are not legally required to appoint a data protection officer (§ 38 BDSG). Please direct all data protection matters – in particular the rights set out in section 15 – to info@artemis-franchise.com.
2. Principles
We process personal data exclusively on the basis of statutory provisions (GDPR, BDSG, TDDDG). Our website can generally be used without providing personal data. Most third-party content requiring consent is loaded exclusively after your explicit consent – including Google Tag Manager, through which our advertising and analytics tags run. No connection to Google is established before your decision (details in sections 4.3, 10 and 11.1).
Our website is served encrypted throughout (TLS/HTTPS), so the transmitted content cannot be read by others in transit.
The fonts used on this website are delivered from our own server. We use no Google Fonts and no other external font services – loading a page therefore does not create any connection to Google or another provider.
3. Consent management (CCM19)
To obtain, manage and document consent we use the consent management platform CCM19 provided by Papoo Software & Media GmbH, Auguststraße 4, 53229 Bonn, Germany. CCM19 is operated as a cloud service with servers located in Germany.
On your first visit, CCM19 displays a consent banner with the categories listed below. Most scripts requiring consent on our site are technically embedded so that CCM19 blocks them directly itself: the program code is present in the page source, but your browser does not execute it until CCM19 unlocks it after your consent (details per service in sections 4.3 and 12). To document your decision (obligation of proof under Art. 7 (1) GDPR), CCM19 stores a consent record containing a timestamp, the categories chosen, the consent ID and a truncated IP address. This information is stored in a strictly necessary cookie or in your browser's local storage.
The legal basis for using CCM19 itself is Art. 6 (1) (c) GDPR (compliance with the legal obligation to obtain and evidence consent) together with Art. 6 (1) (f) GDPR. Setting the consent cookie is permitted without consent under § 25 (2) no. 2 TDDDG because it is strictly necessary to provide this expressly requested service.
Withdrawal: You can change or fully withdraw your consent at any time via the "Privacy settings" link in the footer. Withdrawal takes effect for the future; processing that has already taken place remains unaffected.
4. Consent categories and assigned services
The categories offered in the banner map to the services in use as follows:
4.1 Used without consent
In the banner this category is called “Used without consent” and cannot be deselected there. It contains two kinds of items: services that are strictly necessary to run this website, and services that rely on a legitimate interest under Art. 6 (1) (f) GDPR. For the latter you have a right to object – where that applies, it is stated in the entry below.
- CCM19 – storage of your consent decision (see section 3).
- Spam protection for our forms – rate limiting and the honeypot run on our own server; in addition, Cloudflare Turnstile checks our forms for automated submissions. As a security measure it is strictly necessary for submitting the form and therefore does not require consent (see section 8).
- Plausible Analytics – cookieless audience measurement on our own server (see section 9). It is not strictly necessary; it relies on our legitimate interest under Art. 6 (1) (f) GDPR – which is why it sits in this category and not under “strictly necessary”. You may object at any time: object to traffic measurement.
- Your browser's local storage for ease of use – for example so that a notice you have dismissed does not reappear (see section 4.4).
4.2 Statistics (consent required)
- Google Analytics 4 – additional, NOT cookieless audience measurement run in parallel with Plausible for comparison purposes (see section 10). Runs technically via Google Tag Manager (see 4.3), which is itself only loaded after your consent – without it there is neither a connection to Google nor any measurement (details in section 10).
Our primary audience measurement remains deliberately cookieless via Plausible (section 9, no consent required).
4.3 Marketing (consent required)
All services in this category are held back using the same technical mechanism:
- Google Ads including Google Tag Manager (see section 11) – the Tag Manager that runs the Google Ads tag is only loaded after your consent. In addition, Google Consent Mode v2 governs what the individual tags inside the Tag Manager are allowed to do: before your decision, all consent signals are set to "denied", so personalised advertising and setting advertising cookies do not happen even once the Tag Manager has loaded (details in section 11.1).
- Meta pixel (see section 12b), YouTube videos, the ProvenExpert rating seal and the TrustIndex rating widget (see section 12) are likewise technically blocked by CCM19 itself: their program code is present on the page, but your browser only executes it once CCM19 unlocks it after your consent. Before that there is no connection to these providers and no transmission of your IP address.
4.4 Local storage in your browser (no cookies)
Our website itself sets no cookies of its own. Instead we place up to four entries in your browser's local storage – three for ease of use, and one only if you object to traffic measurement:
- at-exit-intent-until-v2 – remembers that you have dismissed a notice so that it does not reappear immediately. Expires after 7 days.
- at-lead-submitted – remembers that you have already sent us an enquiry so that no further contact prompts are shown to you. Remains stored until you clear your browser's storage.
- at-convbar-dismissed – remembers within the current browser session that you have hidden the notice bar at the edge of the page. Discarded when the tab is closed.
- plausible_ignore – set only if you expressly object to traffic measurement (section 9); it then prevents any further counting. Without an objection the entry does not exist. It remains stored until you withdraw it on the objection page or clear your browser's storage.
These entries contain no identifier by which you could be recognised and no personal content – only a timestamp or a switch. They are not transmitted to us or to third parties and do not leave your browser. They are read within the browser only, and only to achieve the described effect – plausible_ignore, for instance, is checked by the measurement script before every count so that counting is omitted while your objection is set.
Storing all four is permitted without consent under § 25 (2) no. 2 TDDDG: for the first three because it serves solely to implement the behaviour you requested, and for plausible_ignore because it serves solely the exclusion you asked for yourself. You can delete the entries at any time via your browser settings.
5. Hosting and server logs
Our website runs on a virtual server managed by us at IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The server is located in Germany. We have concluded a data processing agreement with IONOS pursuant to Art. 28 GDPR. IONOS provides the infrastructure only and does not access website content.
Access logs: our web server keeps no persistent access log – page views are therefore not recorded together with IP address, timestamp and requested address. For technically unavoidable reasons the server processes your IP address for the duration of the connection in order to deliver the response at all; beyond that it is not stored.
Only malfunction and abuse events are logged: if our protective mechanisms are triggered (for example because an unusual number of form submissions arrives from one network), the application records that event with a timestamp and a truncated IP address (for IPv4 without the last number field), which does not allow any conclusion about an individual person. These operational logs are held exclusively on our server, are not passed on to third parties, are not evaluated by person and are deleted in the course of server maintenance once they are no longer needed for troubleshooting.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure, reliable operation and in protection against abusive use).
6. Contact and enquiry forms
If you contact us through a form on this website, we process the data you provide in order to answer your enquiry. That data comprises: first and last name, email address, telephone number, the sector segment you selected, your details on existing and planned locations, and your message. We additionally store, for technical reasons, which page and which form your enquiry came from and in which language you used our site. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR.
Mandatory information: only your email address and your consent to being contacted are required – without those two we cannot process your enquiry. All other fields are optional; you may leave them blank without any disadvantage to you. The more you tell us, the more precisely we can prepare the initial consultation.
In addition, where available, we store information about the origin of your visit (campaign parameters "UTM" and the Google click identifier "GCLID") in order to evaluate the effectiveness of our advertising (see section 11). The data is deleted as soon as it is no longer required for that purpose and no statutory retention obligations apply.
Transfer to our CRM system (Pipedrive): we transfer the details from your enquiry into our customer relationship management system in order to document the sales contact and to handle your enquiry in a traceable manner. For this we use Pipedrive (Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia). We have concluded a data processing agreement with Pipedrive pursuant to Art. 28 GDPR; Pipedrive processes the data exclusively on our behalf and not for its own purposes. Pipedrive operates the service in Amazon Web Services data centres and in doing so also involves its US company Pipedrive Inc. (530 Fifth Avenue, 8th floor, Suite 802, New York, NY 10036, USA). The EU standard contractual clauses (Implementing Decision 2021/914) apply to this transfer to the USA; Pipedrive Inc. is additionally registered under the EU-US Data Privacy Framework. Despite these safeguards it cannot be ruled out that US authorities access the data and that you have no legal remedies comparable to those in the EU. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in orderly sales documentation). Further information: Pipedrive privacy notice.
Automatic confirmation and notification email: after you submit your enquiry you automatically receive a confirmation email; at the same time our team receives an internal notification with your details. We send both of these emails through our own mailbox on Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) – not through the external marketing email provider Brevo (see section 7, which continues to cover only the newsletter). We have concluded a data processing agreement with Google as part of our Google Workspace use (Google Workspace Data Processing Amendment). The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR.
7. Newsletter (Brevo)
For sending our newsletter we use Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany; parent company Brevo SAS, France). Servers and data are located in the European Union. We have concluded a data processing agreement with Brevo pursuant to Art. 28 GDPR. The confirmation and notification emails for your contact enquiry do not run through Brevo but through our own mailbox (see section 6).
For the newsletter sign-up we process your email address and – if provided – your first name (for a personal salutation). We additionally store, for technical reasons, which page you signed up from and in which language. Sign-up uses the double opt-in procedure: after signing up you receive an email containing a confirmation link. Only after you click that link is your address added to our newsletter list at Brevo; until then it is stored solely with us in order to process the sign-up. We log the time of sign-up and of confirmation in order to be able to evidence your consent.
The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR. You can unsubscribe at any time via the link in every email or by writing to info@artemis-franchise.com; your address will then be removed from the distribution list. Brevo also processes delivery information on our behalf (e.g. whether an email could be delivered).
8. Form spam protection
Our forms are protected against automated submissions. Two of the three measures run entirely on our own server; for the third we use a service provider:
- Submission rate limiting: we accept only a limited number of submissions per minute from the same internet connection. To do so, the server compares the IP address of the current request with preceding ones. The address is held only transiently in memory (discarded after one minute at the latest) and is not stored in a database; it enters a log only in truncated form (see section 5).
- Invisible check field ("honeypot"): every form contains a field that is invisible to humans. If it is filled in, we discard the submission. No data beyond what was submitted is processed in the course of this.
- Cloudflare Turnstile (captcha): to detect automated submissions we embed the Turnstile service provided by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) in our forms. Your browser loads a script from challenges.cloudflare.com and transmits your IP address, information about your browser and operating system and interaction signals from your visit (such as mouse and keyboard behaviour) to Cloudflare. Cloudflare evaluates these signals and returns only the result "passed" or "not passed" to us – we do not receive the underlying raw data. According to Cloudflare, Turnstile operates without tracking cookies, without cross-device recognition and without using the data for advertising purposes.
The legal basis for all three measures is Art. 6 (1) (f) GDPR: we have a legitimate interest in protecting our forms against misuse. For rate limiting and the honeypot, no cookies are set and no information is read from your device. Turnstile is a security measure that is strictly necessary for the function you requested – submitting the form; insofar as it accesses information on your device at all, the exemption in § 25 (2) no. 2 TDDDG applies. Consent is therefore not required, and Turnstile is accordingly not controlled via our consent banner. The widget is loaded only within the forms, not on other pages.
Transfer to third countries: Cloudflare, Inc. is based in the USA; processing of your data there or in other third countries cannot be ruled out. The transfer is based on the European Commission's standard contractual clauses and on Cloudflare's certification under the EU-US Data Privacy Framework. [PRÜFEN] Confirm before publication: Cloudflare's current DPF certification status, conclusion of the data processing agreement (Cloudflare DPA) and which Cloudflare entity is named in the contract.
9. Audience measurement with Plausible Analytics
We use Plausible Analytics to analyse website usage. We host Plausible ourselves on a server in Germany; no data is passed on to third parties.
Plausible operates without cookies and without cross-device recognition: no cookies are set, no IP addresses are stored and no user profiles are created. Only aggregated information is collected, such as the page requested, referrer, device type, browser, operating system and country of origin (derived from the IP address, which is not stored in the process), as well as scroll depth and time spent on the respective page.
To tell returning visits from new ones, Plausible derives a daily rotating counting identifier from your IP address, your browser identification, our domain and a random value that is renewed and discarded every 24 hours. Neither the IP address nor the browser identification itself is stored; once the random value changes, the previous day can no longer be attributed.
In addition we measure five goal completions without any personal reference: submission of a contact form, submission of a newsletter sign-up, confirmation of a newsletter sign-up, clicks on calls to action and document downloads. In doing so we transmit no content you entered, such as your name, email address, telephone number or your message. Only classifying attributes about the event itself are sent along: which form or element triggered the action, in the case of an enquiry additionally the sector segment you selected (e.g. "hospitality"), in the case of a click the label and position of the element, and in the case of a download the file name.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in privacy-friendly statistics). For the measurement, the script reads your browser's viewport height and scroll position in order to determine scroll depth and time spent; no information is stored on your device in the process.
You may object to this measurement at any time – the objection takes effect immediately and applies to the browser in which you set it: object to traffic measurement. Independently of this, you have the right to object under Art. 21 GDPR.
10. Google Analytics 4
In addition to our primary, cookieless audience measurement with Plausible (section 9), we use Google Analytics 4 (GA4; Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), usually as a tag inside Google Tag Manager (see section 11.1). The purpose is to directly compare both measurement tools using the same metrics and goal events. Unlike Plausible, GA4 is NOT cookieless.
The Google Tag Manager that runs GA4 for us is only loaded after your consent (see section 11.1 for the reasoning). Without it there is no connection to Google and no measurement. Google Consent Mode v2 applies in addition: as long as the consent signals (including analytics_storage) are set to "denied", Google states that GA4 does not set cookies and does not recognise your browser. Only after you consent to the "Statistics" or "Marketing" category are the signals updated to "granted".
After consent, GA4 sets its own cookies (including _ga, _ga_<property ID>) to recognise your browser across multiple visits. Data processed includes pages visited, referrer, device/browser data, approximate location (derived from the IP address, which Google truncates before processing) and the goal events listed below. Data may be transferred to third countries, in particular the USA; Google is certified under the EU-US Data Privacy Framework, and EU standard contractual clauses apply in addition. The event data retention period in the GA4 property is set to Google's default value of 2 months.
To keep both tools directly comparable, we measure the same five goal events in GA4 as in Plausible (section 9) – with the same range of classifying attributes and likewise without any content you entered, such as your name, email address, telephone number or message.
The legal basis for loading Google Tag Manager, for setting cookies and for recognising your browser is uniformly your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. None of these operations takes place without it. You may also object to the processing under Art. 21 GDPR and withdraw your consent at any time via the "Privacy settings" link in the footer. Google also provides a browser add-on to disable Google Analytics: Google Analytics opt-out browser add-on. Further information: Google privacy policy.
11. Google Ads and conversion measurement
We advertise our services via Google Ads (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). To measure the effectiveness of our ads we process conversion data in two ways:
11.1 Google Ads tag in the browser (via Google Tag Manager)
We load Google Tag Manager (GTM), which also runs the Google Ads tag, only after your consent – just like the Meta pixel (section 12b) and the other services requiring consent. Its program code is present on the page, but your browser only executes it once our consent management provider CCM19 unlocks it. Before your decision there is therefore no connection to Google, and your IP address is not transmitted to Google. This is the operating mode Google calls basic consent mode: Google tags do not load until you have made a choice in the banner.
As a second safeguard, Google Consent Mode v2 applies inside the Tag Manager: before your decision, all consent signals (including ad_storage, ad_user_data, ad_personalization, analytics_storage) are set to "denied". In this state, Google states that it does not set advertising cookies, does not personalise ads, and uses at most modelled estimates that cannot be attributed to you personally instead of real user data for measurement. Only after you consent to the "Marketing" category are the signals updated to "granted"; only then does Google set advertising cookies, personalise ads, and can it link your visit to previous visits or your Google account. Data may be transferred to third countries, in particular the USA. Google is certified under the EU-US Data Privacy Framework; EU standard contractual clauses apply in addition.
The legal basis for loading the Tag Manager and for all further processing (advertising cookies, personalisation, recognition) is uniformly your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. None of these operations takes place without your consent.
11.2 Server-side conversion import (without cookies)
Independently of this, we report contract enquiries back to Google Ads by transmitting the click identifier appended by Google itself to the ad's destination URL (GCLID) together with the time of the enquiry via the Google Ads interface ("offline conversion import"). Only this click identifier and the timestamp are transmitted – no email addresses, names, telephone numbers or other content of your enquiry. No cookies are set and no information is read from your device for this purpose.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in measuring the success of our advertising). Further information: Google privacy policy.
12. Embedded third-party content (technically blocked by CCM19)
On individual pages we embed third-party content. This concerns three services: videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), the rating seal of ProvenExpert (Expert Systems AG, Quedlinburger Straße 1, 10589 Berlin, Germany), and the rating widget of TrustIndex (Trustindex Ltd. / Trustindex Kft., Nyári Pál utca 15, 2724 Újlengyel, Hungary).
YouTube videos: this includes our curated video showcase featuring selected videos from Christian Becker's YouTube channel (@chrisbecker.franchise), which may appear on several pages (including the homepage, "About us" and press). Embedded YouTube videos use the privacy-enhanced mode (youtube-nocookie.com): YouTube does not set personalised advertising cookies before playback, but data is still transmitted to Google (including your IP address) once the video is loaded.
ProvenExpert rating seal: on the homepage we display the official rating seal of our ProvenExpert profile. When it is loaded, your browser retrieves program code from s.provenexpert.net and the current rating data from d.provenexpert.net; in doing so ProvenExpert receives your IP address as well as technical details about browser and device. The display of the plain rating metrics described in section 12a is independent of this and works without that connection.
TrustIndex rating widget: in the trust bar near the top of the page we display a rating widget provided by TrustIndex. When it is loaded, your browser retrieves program code and rating data from cdn.trustindex.io as well as a European data endpoint (de-proxy.trustindex.io); in doing so TrustIndex receives your IP address as well as technical details about browser and device.
All three are technically embedded so that our consent management provider CCM19 directly blocks their program code itself until you have consented to the "Marketing" category (see sections 3/4.3): the code is present on the page, but your browser does not execute it as long as no consent has been given – no connection to the respective provider exists at that point. Once unlocked, the provider receives your IP address and can set cookies and – if you are logged in there – associate the request with your account. Data may be transferred to third countries, in particular the USA. The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TDDDG.
Plain links to our profiles with providers and social networks (e.g. in the footer, in the social media bar or the channel link next to the video showcase) are not embeds: data is only transmitted once you actively click the link. We do not embed posts from social networks (see section 13).
12a. Display of external rating metrics
Our website displays aggregated rating metrics (average score and number of reviews) from various rating portals, including Stilpunkte, Google and ProvenExpert. We maintain these metrics editorially in our own content management system – when you visit our website, your browser does not connect to these portals for this purpose; no personal data of yours is transmitted to these providers. Only when you actively click a corresponding link do you leave our website, at which point the respective provider's privacy policy applies.
This is to be distinguished from the ProvenExpert rating seal, which is actually loaded from the provider and therefore requires consent – see section 12.
12b. Meta pixel (Facebook and Instagram)
We also advertise our services on Facebook and Instagram. In order to measure the success of those ads and to reach people again who have shown an interest in our offering, we use the Meta pixel – a measurement tool provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland ("Meta").
What the pixel does: once CCM19 unlocks the Meta script after your consent, it reports your visit to Meta. The data transmitted comprises your IP address, the address of the page visited, technical details about browser and device, and the same five goal events as in section 9 – submitting a contact form, submitting and confirming a newsletter sign-up, clicks on calls to action, and document downloads, each with the classifying attributes named there (including the sector segment you selected). No content entered by you, such as your name, email address, telephone number or your message, is transmitted to Meta; in particular we do not upload customer lists and do not transmit hashed contact data.
Cookies: the pixel sets its own cookies, in particular _fbp (lifetime up to 90 days), in order to recognise your browser across several visits. If you are logged in to Facebook or Instagram, Meta can additionally attribute the visit to your account there and add you to advertising audiences.
Nothing happens without consent: the Meta script is technically embedded on our site so that CCM19 only executes it at all after you consent to the "Marketing" category – the program code is present on the page but is not merely muted by the browser, it simply is not executed. Before that there is no connection to Meta, no IP address is transmitted and no cookie is set.
Transfer to the USA: Meta also processes data in the United States. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework; EU standard contractual clauses apply in addition. Despite these safeguards it cannot be ruled out that US authorities access the data and that you have no legal remedies comparable to those in the EU. By giving your consent you also consent to this transfer (Art. 49 (1) (a) GDPR).
Joint controllership: we and Meta are joint controllers for the collection and transmission of the data to Meta (Art. 26 GDPR); Meta is the sole controller for the subsequent further processing within its own systems. The allocation follows from the addendum Meta provides for this purpose.
Legal basis and withdrawal: the legal basis is your consent pursuant to Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. You can withdraw it at any time via the "Privacy settings" link in the footer; the pixel then stops processing and the associated cookies are deleted. You can additionally object to the use of your activity for advertising in your Facebook/Instagram settings. Further information: Meta privacy policy.
13. Services not used
For the avoidance of doubt: this website uses no Google AdSense and no visitor identification services (e.g. Leadfeeder/Dealfront). Of the social networks' marketing pixels we use only the Meta pixel (Facebook/Instagram) – see section 12b; pixels from LinkedIn and TikTok are not used.
Likewise not used are:
- Embedded posts from social networks – from Instagram, Facebook, LinkedIn and TikTok we merely link to our profiles (see section 12, last paragraph).
- Embedded podcast players – we refer to our podcast on Spotify and other providers exclusively by link; no player is embedded.
- Map services – we do not embed a Google Maps map; address details link at most to a map service.
- External fonts – see section 2.
- Captcha services – see section 8.
Google Analytics 4 – unlike in an earlier version of this privacy policy – is an actively used, consent-based service, see section 10.
13a. Retention periods at a glance
We store personal data only for as long as it is necessary for the respective purpose or as long as statutory retention obligations require. In detail:
- Enquiries from contact and initial-consultation forms (name, contact details, message, company information): for the duration of processing and of the subsequent business relationship. If no cooperation comes about, we delete the enquiry at the latest 24 months after the last contact – this period reflects the long decision-making horizon involved in building a franchise system. If the enquiry leads to a contract, the commercial and tax retention periods of 6 and 10 years respectively apply (§ 257 HGB, § 147 AO), calculated from the end of the relevant calendar year.
- Enquiry data in our CRM system (section 6): the same periods as for the enquiry itself – deletion takes place in both systems together.
- Origin information of an enquiry (campaign parameters "UTM", Google click identifier "GCLID"): 13 months from receipt of the enquiry. After that, attribution to an advertising campaign is no longer possible and the data is no longer required for measuring success.
- Newsletter sign-up (email address, first name where provided, time of sign-up and confirmation): until you unsubscribe. After that we retain the evidence of consent (address, timestamps, time of unsubscription) for a further 3 years in order to be able to demonstrate in a dispute that valid consent existed (Art. 7 (1) GDPR, limitation period § 195 BGB).
- Unconfirmed newsletter sign-ups: the confirmation link is valid for 7 days; unconfirmed sign-ups are deleted afterwards.
- Consent record of the consent management platform (see section 3): according to CCM19's specifications; as evidence under Art. 7 (1) GDPR usually up to 3 years from being given or withdrawn.
- Entries in your browser's local storage (section 4.4): 7 days, until the end of the browser session, or until you clear your browser's storage. The objection entry plausible_ignore deliberately does not expire – it is meant to apply until you withdraw it yourself. These entries are held exclusively with you, not with us.
- Server malfunction and abuse logs (truncated IP addresses only, see section 5): deleted in the course of server maintenance once they are no longer needed for troubleshooting; no targeted evaluation by person takes place.
- Audience measurement with Plausible (section 9): aggregated values without any personal reference – no personal retention period applies. The random value from which the daily counting identifier is derived is discarded after 24 hours; after that, even an attribution within the previous day is no longer possible.
- Google Analytics 4 (section 10): 2 months (Google's default retention period for event data).
- Meta pixel (section 12b): the _fbp cookie expires after up to 90 days. Meta's own retention periods apply to the data within Meta's systems; we have no influence over these.
The periods for enquiries, CRM data, origin information and newsletter consent evidence are implemented organisationally: automatic deletion is not set up in the system, so deletion takes place through regular review in editorial and sales operations.
14. Processors and recipients
We use service providers that process personal data exclusively on our behalf and according to our instructions. We have concluded data processing agreements pursuant to Art. 28 GDPR with all of them:
- IONOS SE – hosting of our website (section 5).
- Papoo Software & Media GmbH – consent management with CCM19 (section 3).
- Cloudflare, Inc. – spam protection of our forms with Turnstile (section 8). [PRÜFEN] Confirm conclusion of the Cloudflare DPA.
- Sendinblue GmbH / Brevo – sending our newsletter (section 7).
- Google Ireland Limited – sending the confirmation and notification email for your contact enquiry through our Google Workspace mailbox (section 6).
- Pipedrive OÜ – our CRM system for documenting the sales contact (section 6); this involves a transfer to the USA to Pipedrive Inc.
For the spam protection of our forms, rate limiting and the honeypot run on our own server without any service provider; the Cloudflare Turnstile captcha, by contrast, transmits data to Cloudflare, Inc. in the USA (section 8).
Google (Tag Manager, Analytics 4, Ads), YouTube, Meta, ProvenExpert and TrustIndex receive data only after your consent, since CCM19 technically blocks their program code until then (see sections 3/4.3/11.1/12/12b). Without your consent no connection to any of these providers is established and no IP address is transmitted. In that respect those providers are not processors but act as controllers in their own right or – in Meta's case – as joint controllers together with us (section 12b). Data is only disclosed to other recipients where there is a legal obligation to do so or where you have consented.
15. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw consent at any time – for cookies and third-party content via the "Privacy settings" link in the footer, otherwise by writing to info@artemis-franchise.com.
No automated decision-making: automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR does not take place. Your enquiry is read and assessed exclusively by people. Our interactive self-assessment of franchise readiness also runs entirely in your browser: your answers are neither stored nor transmitted to us – we only learn what you subsequently choose to tell us via the form.
16. Right to lodge a complaint
Under Art. 77 GDPR you may lodge a complaint with a data protection supervisory authority – in particular with the authority of your habitual residence, your place of work or the place of the alleged infringement. The authority competent for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4, 40213 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
www.ldi.nrw.de
17. Changes to this privacy policy
We adapt this privacy policy when we change our website or the services used on it, or when the legal situation requires it. The version published on this page applies in each case; you will find the date of the last revision at the top. Where a processing operation based on your consent changes materially, we will obtain your consent again.