EAA Privacy Policy

General information

The operators of this website take the protection of your personal data very seriously. We treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy policy.

The following gives an overview of what happens to your personal information when you visit our website. To provide the functions and services of our website, it is necessary that we collect personal data about you. Personal information is any data with which you could be personally identified. Below we explain which data we collect and use, what this is necessary for, and what rights you have in relation to your data.

Please note that data transmitted via the internet (e.g. via email communication) may be subject to security breaches. Complete protection of your data from third-party access is not possible.

Notice concerning the party responsible for this website

The party responsible for processing data on this website is:

Erste Abwicklungsanstalt
Friedrichstraße 84
40217 Düsseldorf
Telefon: +49 211 91345 780
Fax: +49 211 91345 789
E-Mail:

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (names, email addresses, etc.).

Statutory data protection officer

If you have any questions about data protection, you can also contact our data protection officer at any time.

Oliver Walter
Erste Abwicklungsanstalt
Friedrichstraße 84
40217 Düsseldorf
Tel.: +49 211 91345 925
E-Mail:

Data collection on our website

How do we collect your data?

Some data are collected automatically by our IT systems when you visit the website. These data are primarily technical data a.o.

  • IP address
  • Date and time of the request
  • Content of the request
  • Access status/HTTP status code
  • Browser type
  • Language and version of browser software
  • Operating system

The collection of this data is technically necessary to display our website to you. We also use the data to ensure the security and stability of our website. The legal basis for the collection is Art. 6 para. 1 lit. f DSGVO.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze how visitors use the site.

Why are cookies used?

Some of our web pages use cookies. Cookies do not harm your computer and do not contain any viruses. Cookies help make our website more user-friendly, efficient, and secure. A distinction is made between technically necessary cookies and cookies for analytical purposes. Cookies are small text files that are stored on your computer and saved by your browser. Most of the technically necessary cookies we use are so-called “session cookies.” They are automatically deleted after your visit. Other cookies are stored on your device until you delete them. These cookies allow us to recognize your browser when you visit the site the next time.

You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions, or to always reject them, or to automatically delete cookies when closing your browser. Disabling cookies may limit the functionality of this website.

Cookies which are necessary to allow electronic communications or to provide certain functions you wish to use (such as the language settings) are stored pursuant to Art. 6 paragraph 1, letter f of DSGVO. The website operator has a legitimate interest in the storage of cookies to ensure an optimized service provided free of technical errors. If other cookies (Matomo statistics cookie for analyzing your surfing behavior) are also stored, they will be treated separately in this privacy policy and need to be approved by opt-in.

What is the disclaimer on the investor relations pages used for

The use of the Investor Relations page requires acceptance of a disclaimer. Your acceptance or rejection is stored in a cookie so that you are not asked to confirm your consent again on every subpage.

While the technically necessary cookies (such as Borlabs cookies) are preset and cannot be disabled, the Disclaimer cookie requires your consent via opt-in by clicking the “Yes, I agree” button. Alternatively, you can also use the “Accept all” button. If you click the “No, I do not agree” button, the Investor Relations pages will not be displayed. In this case, if you are interested in the information, you will need to contact our Investor Relations department. If you leave the page without clicking either button, no cookie will be stored.

You can also prevent the use of cookies by deleting existing cookies and preventing cookies from being stored in your browser. If you prevent the storage of cookies, however, we point out that you may not be able to use this website in full. In addition, if you use a different computer or a different web browser, you will have to complete the deactivation procedure again.

Use of the Sucuri Web Application Firewall (WAF)

To ensure the security and availability of our website, we use the Sucuri Web Application Firewall (WAF) from Sucuri LLC (GoDaddy Group).

The Sucuri WAF protects our website from cyberattacks, particularly DDoS attacks, malicious code, automated attacks, and other security threats. To do this, data traffic between your device and our website is routed through Sucuri’s infrastructure, where it is checked for security-related characteristics. [sucuri.net], [docs.sucuri.net]

Data Processed

In connection with the provision of the WAF, the following data in particular may be processed:

  • IP address of the requesting device,
  • date and time of access,
  • URL accessed,
  • information about the browser and operating system used,
  • referrer URL,
  • HTTP header information,
  • security-related log data (log files).

Processing is carried out exclusively for the purpose of detecting, analyzing, and defending against attacks, as well as ensuring the stability and integrity of our website. [sucuri.net], [docs.sucuri.net]

Legal Basis

Processing is based on Art. 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring information security, safeguarding the availability of our website, and protecting against unauthorized access and cyberattacks.

Recipients of the data

The recipient of the data is

Sucuri LLC
c/o GoDaddy Operating Company, LLC
2155 E. GoDaddy Way
Tempe, Arizona 85284
USA

Transfers to Third Countries

Personal data may also be processed in the United States. To the extent that personal data is transferred to a third country in this context, such transfers are based on appropriate safeguards in accordance with Art. 44 et seq. of the GDPR, in particular on the Standard Contractual Clauses approved by the European Commission or an existing adequacy decision, as applicable.

For more information on data protection at Sucuri, please visit: https://sucuri.net/privacy/

What are server log files?

The website provider automatically collects and stores information that your browser automatically transmits to us in “server log files”. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

These data will not be combined with data from other sources.

The basis for data processing is Art. 6 (1) (f) DSGVO, which allows the processing of data by the balancing in interests.

What rights do you have regarding your data?

Information, correction, restriction of processing, deletion

You always have the right to request information about your stored data, its origin, its recipients, and the purpose of its collection at no charge. You also have the right to request that it be corrected, blocked, or deleted. You can contact us at any time using the address given in the legal notice or contact our data protection officer if you have further questions about the issue of privacy and data protection. You may also, of course, file a complaint with the competent regulatory authorities.

Revocation of your consent to the processing of your data

Many data processing operations are only possible with your express consent. You may revoke your consent at any time with future effect. To change your given consent for Matomo a simple opt-out is sufficient. The data processed before we receive your request may still be legally processed.

Right to file complaints with regulatory authorities

If there has been a breach of data protection legislation, the person affected may file a complaint with the competent regulatory authorities. The competent regulatory authority for matters related to data protection legislation is the Federal Commissioner for Data Protection and Freedom of Information. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and for the protection of the transmission of confidential content, such as the inquiries or orders you send to us as the site operator. You can recognize an encrypted connection in your browser’s address line when it changes from “http://” to “https://” and the lock icon displayed in your browser’s address bar.

If SSL or TLS encryption is activated, the data you transfer to us cannot be read by third parties.