Privacy · Version v1.1 EN
Privacy Policy
Last updated 23 July 2026 · Effective upon publication on the official website
Summary: The public website does not store the text entered into the contact configurator in its own database. Until a message is sent, the entered information remains locally in the browser. Personal data is processed when the user personally sends a message by email, WhatsApp or Telegram, makes a payment through Stripe, enters into pre-contractual or contractual relations with ABS Studio, or where ABS Studio stores minimal B2B contact details from publicly accessible business sources for individual customer acquisition. Advertising contact is made only through legally permitted channels and under the conditions applicable to those channels.
1. Scope and data protection roles
This Privacy Policy explains how ABS Studio processes personal data in connection with the official website https://abs-studio.de, enquiries and the individual approach of prospective B2B customers, the preparation of offers, the conclusion and performance of B2B contracts, the processing of subscription payments, customer support, the maintenance of customer records, project management and the use of business IT and AI tools. This Privacy Policy applies to website visitors, prospective, current and former customers, sole traders, freelancers and other self-employed persons, as well as business owners, employees, representatives and contact persons of legal entities. The GDPR applies to information relating to an identified or identifiable natural person, including where that person acts in a professional or business capacity. In relation to its own website, business communications, invoicing, CRM and project management, ABS Studio acts as the controller. Where ABS Studio processes personal data during the development or technical maintenance of a customer website solely on the customer's documented instructions, the respective customer remains the controller and ABS Studio acts as a processor. Where required by Article 28 GDPR, a separate data processing agreement (DPA/AVV) is concluded or validly incorporated for this purpose.
2. Controller
The controller within the meaning of the GDPR is: Dmytro Shapovaliuk trading name: ABS Studio Strangstr. 6 58239 Schwerte Germany Email: dmytroshapovaliuk.de@gmail.com Website: https://abs-studio.de No data protection officer has been appointed. Data protection enquiries may be sent directly to the email address stated above.
3. Legal bases
Depending on the specific processing activity, ABS Studio processes personal data on the following legal bases:
Article 6(1)(a) GDPR - consent, in particular for Google Analytics 4 and non-essential external iframe content;
Article 6(1)(b) GDPR - pre-contractual measures taken at the request of the data subject and performance of a contract;
Article 6(1)(c) GDPR - compliance with tax, commercial and other legal obligations;
Article 6(1)(f) GDPR - legitimate interests in the secure operation of the website, handling business enquiries, organising customer relationships, documenting agreements, preventing misuse and protecting legal claims;
Section 25 TDDDG - storing information in the user's terminal equipment or accessing information already stored there. Non-essential technologies are activated only after consent has been given; strictly necessary technologies are used without consent only within the scope of the statutory exemption.
4. Hosting via Netlify and server logs
The website is hosted on the infrastructure of Netlify, Inc. For the technical delivery of pages, ensuring availability, protecting against attacks, diagnosing errors and maintaining stability, Netlify and the infrastructure providers it uses automatically process technical data. This may include in particular:
IP address;
date and time of access;
requested URL, HTTP status and amount of data transferred;
referrer URL, where transmitted by the browser;
browser type and version, operating system, language and device type;
technical identifiers, error logs and security signals. The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in the reliable, available and secure operation of the website. Netlify processes data as a hosting provider on the basis of the applicable contractual terms and a DPA/AVV. International transfers are safeguarded by the mechanisms provided for under the GDPR, in particular Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Further information: Netlify Privacy Statement | Netlify GDPR / DPA
5. HTTPS and technical transmission security
The website uses HTTPS and SSL/TLS encryption. This protects the transmission of data between the user's browser and the server infrastructure against ordinary interception by third parties. Absolute security of data transmission over the internet cannot be guaranteed technically.
6. Cookies, Local Storage and consent management
The website uses necessary browser Local Storage only for abs_cookie_consent_v2 to retain and respect the cookie choice, abs_locale_v1 to retain the language explicitly selected by the user and abs_theme_v1 to retain the explicitly selected light or dark display theme. Language and theme are each retained for six months or until changed or deleted. The contact form's name, business name and message text are stored neither in Local Storage nor in Session Storage. The legal basis for access to the terminal equipment is Section 25(2) no. 2 TDDDG; where the related processing concerns personal data, it is based on Article 6(1)(f) GDPR. Google Analytics 4 and non-essential external iframe content are activated only after the relevant consent has been given. Consent may be withdrawn or changed at any time through the Cookie Settings on the website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Detailed categories, purposes, providers and durations are set out in the Cookie Settings and Cookie Policy.
7. Google Analytics 4
With the user's consent, the website uses Google Analytics 4, a service provided by Google Ireland Limited, to measure reach, analyse website use, identify technical issues and improve the structure and content of the website. Google Analytics may process in particular:
a pseudonymous browser or device identifier;
pages viewed, events, navigation paths, time spent and interactions;
referrer URL and access source;
browser type, operating system and approximate device characteristics;
approximate geographical location information;
IP address during technical transmission. According to Google, IP addresses of users in the EEA, Switzerland and the United Kingdom are used to derive an approximate region and are then discarded before being logged or stored in Analytics. ABS Studio does not transmit names, email addresses, telephone numbers, payment data or other direct identifiers to Google Analytics. The legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Google Analytics is not loaded before consent is given; refusal does not restrict the essential functions of the website. The retention period for user-level and event-level data in Google Analytics 4 is set to 14 months. After this period, the relevant data is automatically deleted in accordance with Google Analytics procedures. This setting does not affect standard aggregated statistical reports. Google Signals, remarketing, ads personalisation and linking with Google Ads or other advertising products are not used. Further information: Google Analytics - Privacy and Data Controls | Google Privacy Policy
8. Google Search Console
ABS Studio uses Google Search Console to review indexing, visibility in Google Search and technical errors. Search Console is an administrative tool and, as such, does not place a separate Search Console cookie in the website visitor's browser. The legal basis for analysing aggregated search and technical data is Article 6(1)(f) GDPR; the legitimate interest lies in maintaining the accessibility and proper indexing of the website.
9. Local contact configurator
The website contains a contact configurator into which the user can enter information and select a communication channel. Under the current technical implementation, the entered data is processed exclusively locally in the browser in order to generate message text or a redirect link. Until the user personally opens email, WhatsApp or Telegram and sends the message:
the data is not transmitted to a server operated by ABS Studio;
the data is not stored in a database of the website;
the data is not sent directly to Netlify Forms, Zoho CRM, ClickUp or an AI service. ABS Studio receives only the information that the user actually sends through the selected external communication channel.
10. Contact by email, WhatsApp and Telegram
10.1 Email When contact is made by email, ABS Studio processes the email address, name, business name, message content, attachments, technical communication metadata and any other information provided voluntarily. The consumer version of Gmail, a Google service, is used for email communication; for users in the EEA, Google Ireland Limited is generally responsible. Within the consumer version of Gmail, Google processes data under its own terms of use and privacy notices and not as a processor for ABS Studio on the basis of a separate DPA. Data may also be processed by the sender's email provider. ABS Studio limits email communications to the information necessary and does not ask users to send passwords, full payment details, special categories of personal data or identity documents by email without first agreeing on a secure transmission method. The purposes are responding to the enquiry, preparing an offer, taking pre-contractual measures, performing the contract, providing support, documenting business communications and protecting legal claims. The legal basis is Article 6(1)(b) GDPR and, for general business enquiries, security and preservation of evidence, additionally Article 6(1)(f) GDPR.
10.2 WhatsApp The website contains an ordinary link to WhatsApp. Before the link is clicked and a message is actually sent, ABS Studio does not receive its content. After sending, the telephone number, name or profile name, a profile image depending on the user's settings, message text, attachments and metadata may be processed. WhatsApp processes data under its own terms and privacy notices. The legal basis for processing by ABS Studio is Article 6(1)(b) or (f) GDPR.
10.3 Telegram The website contains an ordinary link to Telegram. After a message is actually sent, ABS Studio may receive the name, username, telephone number depending on the user's settings, message text, attachments and metadata. Telegram Messenger Inc. processes data under its own Privacy Policy. According to Telegram, the principal cloud data of users in the EEA is stored in data centres in the Netherlands; the company itself is located outside the EEA. The legal basis for processing by ABS Studio is Article 6(1)(b) or (f) GDPR. Provider privacy notices: Google | WhatsApp | Telegram
11. Payments and B2B subscriptions via Stripe
ABS Studio uses Stripe for paid B2B subscriptions, recurring payments, invoices, refunds, payment disputes, fraud prevention and subscription management. For users in Europe, the contracting party is generally Stripe Payments Europe, Limited. After opening a Stripe Payment Link or Stripe Checkout, Stripe may process in particular:
name, business name, email address, telephone number, billing address and country;
VAT identification number or tax number, where provided;
selected plan, amount, currency, date and payment and subscription status;
payment method, bank, card or account data;
IP address, browser, device, cookies and security signals;
information relating to refunds, chargebacks, invoices and fraud prevention. The full card number and CVC code are processed by Stripe and the financial service providers involved. As a rule, ABS Studio does not receive or store these full details. ABS Studio receives only the information required for the contract, invoicing, accounting, support and payment allocation. The legal bases are Article 6(1)(b) GDPR for performance of the contract, Article 6(1)(c) GDPR for tax and accounting obligations and Article 6(1)(f) GDPR for payment security, fraud prevention and protection of legal claims. Depending on the relevant processing activity, Stripe acts as a processor and/or as an independent controller. Further information: Stripe Privacy Center | Stripe Data Processing Agreement
12. Zoho CRM and ClickUp
ABS Studio uses Zoho CRM as the central system for customer and contract records and ClickUp to organise projects, tasks, deadlines, changes and working time. Zoho CRM and ClickUp are internal work services; their scripts or cookies are not loaded in the browser of a visitor to abs-studio.de.
12.1 Zoho CRM Zoho CRM may store in particular:
surname, first name, business name, role and business contact details;
country, business address, website and communication channels;
source of the contact and history of business communications;
plan, price, contract start date, minimum term and contract status;
Stripe Customer ID, Subscription ID, Invoice ID and payment status, but no full card details;
information relating to an early paid Buyout, transfer after 24 fully paid billing periods, support, complaints and agreements.
12.2 ClickUp ClickUp may store in particular:
internal Project ID, business or project name;
tasks, statuses, priorities, deadlines and responsible persons;
brief, agreed scope of services, technical notes and change history;
time tracking and links to work resources;
limited contact or contract information only where required for a specific task. The purposes are handling enquiries, concluding and performing contracts, organising work, monitoring deadlines, providing support, documenting agreements, recording working time and protecting contractual rights. The legal bases are Article 6(1)(b), (c) and (f) GDPR. ABS Studio follows the principle of data minimisation: Stripe is the authoritative system for actual payment status, Zoho CRM for customer and contract data, and ClickUp for tasks and working time. Records are linked using a Project ID and technical Stripe IDs. Zoho and ClickUp are subject to the DPAs/AVVs incorporated into the relevant terms of use or accepted separately. Official documents: Zoho Privacy / DPA | Zoho CRM GDPR | ClickUp DPA | ClickUp Subprocessors
13. Prospective B2B customers and data from publicly accessible sources
ABS Studio may identify prospective business customers using publicly accessible information, in particular Google Maps, Google Business Profiles, official business websites, business directories, professional social networks and other lawfully accessible business sources. Depending on the source, the following may be processed in particular:
business name, industry, location, business address, website or the fact that no dedicated website is available;
publicly stated business telephone number, email address or another business communication channel;
name, role or position of a contact person only where that information is publicly linked to the person's professional activity;
source and date of collection, reason why ABS Studio's services may be relevant, contact status and information relating to an objection. Where a record relates solely to a legal entity and a general business contact, the GDPR may not apply to that record as such. By contrast, where the information makes it possible to identify a sole trader, self-employed person, owner, employee or other natural contact person, it is processed as personal data. The purposes are individual B2B customer acquisition, assessing a possible need, preparing a factually relevant approach, documenting the contact and preventing renewed contact after an objection. The legal basis for storing minimal professional contact data is Article 6(1)(f) GDPR, namely ABS Studio's legitimate interest in acquiring business customers. Before the data is used, necessity, the data subject's reasonable expectations and the balancing of interests are taken into account. Where personal data has not been obtained directly from the data subject, the information required under Article 14 GDPR is provided at the latest at the time of first contact and in any event no later than one month after collection, unless a statutory exemption applies. The notice identifies ABS Studio, the purpose, the legal basis, the categories of data, the source and a link to this Privacy Policy. Advertising contact is made only through a channel and under conditions permitted by Section 7 UWG and other applicable law. The publication of an email address, telephone number, WhatsApp contact or other contact option in a public business profile does not in itself constitute consent to electronic advertising. Following an objection, the data is no longer used for direct marketing. Legal sources: Article 14 GDPR | Article 21 GDPR | Section 7 UWG
14. ChatGPT Plus and Codex
ABS Studio uses a personal ChatGPT Plus subscription and Codex for programming, code analysis, technical documentation, troubleshooting, preparing technical drafts and handling technical tasks. ChatGPT Plus and Codex are not directly integrated into the public website abs-studio.de. Data from the contact configurator, Stripe, Zoho CRM or ClickUp is not automatically transmitted to OpenAI. For technical tasks, the following may be used in particular:
extracts of source code, configurations and general technical documentation;
pseudonymous Project IDs and neutral names and descriptions of technical tasks;
technical logs only after removal of IP addresses, email addresses, names, tokens and other identifiers or secrets;
publicly accessible content of a customer website only to the extent required for its technical implementation. As a binding internal rule, ABS Studio does not transmit non-public personal customer data to ChatGPT Plus or Codex, in particular names or contact details, private correspondence, contracts, invoices, Stripe IDs, payment information, user databases, identity documents, special categories of personal data, passwords, API keys or other secrets. Pseudonyms, Project IDs, shortened descriptions and anonymised extracts are used for technical tasks. ChatGPT Plus and Codex are consumer services provided under OpenAI's terms of use and privacy notices. This personal subscription is not covered by a standard DPA under which OpenAI processes identified customer data as a processor for ABS Studio. These services are therefore not used as a central work system for processing such data. “Improve the model for everyone” is disabled in the account settings; for Codex, the separate use of full environments for model training is also disabled. New chats and tasks are therefore not used for model training. ABS Studio does not submit feedback on work conversations where doing so could transmit the associated content to OpenAI for model improvement. For users in the EEA, OpenAI Ireland Limited is responsible for processing user data under OpenAI's own EU Privacy Policy. If, despite data minimisation, personal data is inadvertently contained in technical material, ABS Studio's purpose of processing is technical development, security and service quality; depending on the situation, the legal basis is Article 6(1)(b) and/or (f) GDPR. OpenAI may process data in the United States and other countries using the transfer mechanisms described in its Privacy Policy. Official OpenAI documents: EU Privacy Policy | Data Controls | Use of data to improve model performance | Retention of chats and files | Retention of Codex chats
15. Iframe portfolio and external content
The website contains interactive previews of individual customer websites or technology pages through iframes. Before activation, a local card or placeholder from ABS Studio is displayed; the external domain is not loaded. Before activation, the user sees the exact external domain and a notice that a direct connection will be established. After consent has been given, the operator of the external website may receive the IP address, date and time, browser, device, referrer, technical identifiers and interaction data and may set its own cookies or Local Storage entries. Further processing is governed by the Privacy Policy of the respective operator. The legal basis for activating non-essential external content is consent under Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. The user may decline to activate the iframe and can use the essential content of the website without restriction.
16. Ordinary external links
The website contains ordinary links to GitHub, Netlify, OpenAI, documentation, messenger services and other external websites. Before a link is clicked, the target page is not loaded within abs-studio.de. After a link is clicked, the browser establishes a direct connection with the respective operator, which may receive the IP address, time of access, browser, device, referrer and other technical data. The privacy notices of the external websites apply.
17. Recipients and processors
Within the scope of the relevant purpose, personal data may be made accessible to the following recipients or categories of recipients:
Netlify and providers of hosting, CDN and security infrastructure;
Google in connection with the use of the consumer version of Gmail, Google Analytics 4 and Search Console;
Stripe, banks, payment networks and payment method providers;
Zoho CRM for customer and contract management;
ClickUp for project, task and working-time management;
OpenAI for permitted technical tasks within ChatGPT Plus and Codex, subject to the restrictions described in Section 14;
WhatsApp, Telegram and email providers where the user selects the respective communication channel;
operators of external domains opened by the user or activated in an iframe;
tax advisers, accountants, legal advisers, IT service providers and public authorities where necessary or legally required. Recipients receive only the data required for the relevant purpose. Where a service provider processes data on behalf of ABS Studio, a DPA/AVV under Article 28 GDPR applies. Where a provider, in particular the consumer version of Gmail or ChatGPT Plus/Codex, acts as an independent controller under its own terms, no DPA is identified as the legal and contractual basis of that processing; at the same time, the amount of data transmitted is further minimised.
18. Transfers of data to third countries
Certain providers, their corporate groups or subprocessors may process data outside the EEA, in particular in the United States, India, the United Kingdom, Switzerland or other countries. A transfer takes place only where a mechanism under Chapter V GDPR is available, for example an adequacy decision of the European Commission, the recipient's participation in the EU-U.S. Data Privacy Framework, Standard Contractual Clauses or another legal basis. ABS Studio limits the amount of data transferred, uses pseudonymous Project IDs and restricts integration permissions. For providers acting as processors, DPAs/AVVs, subprocessors and transfer mechanisms are reviewed. For consumer services acting as independent controllers under their own privacy notices, in particular Gmail and ChatGPT Plus/Codex, the published international transfer mechanisms are taken into account and data is minimised particularly strictly. Information on a specific transfer mechanism or available safeguards may be requested using the contact details in Section 2.
19. Requirement to provide data
For a simple visit to the website, the user does not have to voluntarily provide a name or contact details; technical data required to deliver the website is transmitted automatically through the browser. Consent to Google Analytics 4 and non-essential iframe content is voluntary. Refusal does not restrict the essential content of the website. At least one suitable communication channel and the content of the enquiry are required in order to respond to an enquiry. To conclude and perform a paid B2B contract, a name or business name, contact details, billing details, the selected plan and the payment information requested by Stripe are required. Without the necessary contract and payment data, ABS Studio cannot conclude a contract, issue a proper invoice or provide a paid service. Additional information is voluntary. Data relating to prospective B2B customers from public sources is collected without active participation by the data subject; use for direct marketing may be objected to at any time.
20. Retention periods
ABS Studio stores personal data only for as long as necessary for the relevant purpose, unless a longer retention period is required by law. In particular, the following periods and criteria apply:
server and security logs - for the period required for technical operation, protection and investigation of security incidents in accordance with the Netlify configuration;
cookie consent, language and technical settings - until the selection is changed, consent is withdrawn, browser data is deleted or the duration stated in the Cookie Settings expires;
Google Analytics 4 - 14 months for user-level and event-level data;
data relating to prospective B2B customers from public sources where no contact takes place - generally up to six months after collection; after substantive contact without a contract, generally up to twelve months after the last interaction, unless there is an objection, a dispute or another legal basis;
active customer, CRM and project records - for the term of the contract and afterwards until the expiry of the periods required to protect claims; the standard limitation period in Germany is generally three years and usually begins at the end of the relevant calendar year;
invoices, accounting records and tax-relevant documents - generally eight years; individual accounting documents subject to a longer statutory retention period up to ten years; commercial and business correspondence generally six years;
technical notes, drafts and completed ClickUp tasks that are no longer required - earlier deletion or reduction as soon as they are no longer needed for the respective purpose;
chats and tasks in ChatGPT Plus and Codex are stored in the account until ABS Studio deletes them. Work conversations and technical objects are reviewed regularly and deleted once they are no longer required for the relevant purpose. According to OpenAI, after deletion they are generally scheduled for permanent removal from its systems within 30 days, unless they have previously been de-identified and disassociated from the account or longer retention is required for security or legal reasons. Temporary Chats are automatically deleted within 30 days; files in Library, Projects or other separate objects may need to be deleted separately;
a minimal suppression record relating to an objection to direct marketing - for as long as necessary to reliably prevent renewed advertising contact;
data relating to claims, disputes or legal proceedings - until final resolution and expiry of the applicable periods. After the applicable period has expired, the data is deleted, anonymised or blocked from ordinary use where further retention is required by law.
21. Rights of data subjects
Subject to the conditions of the GDPR, the data subject has, in particular, the right to:
obtain information about and access to their personal data;
obtain available information about the source of the data where it was not collected directly from the data subject;
request correction of inaccurate data and completion of incomplete data;
request deletion of personal data;
request restriction of processing;
receive data in a portable format where the right to data portability applies;
object to processing based on Article 6(1)(e) or (f) GDPR;
withdraw consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal;
lodge a complaint with a competent data protection supervisory authority. To exercise these rights, the data subject may contact ABS Studio using the contact details in Section 2. To protect against unauthorised disclosure, ABS Studio may request information necessary for a reasonable verification of identity.
22. Right to object
Where personal data is processed on the basis of Article 6(1)(f) GDPR, the data subject has the right to object to such processing at any time on grounds relating to their particular situation. Following an objection, the processing will cease unless ABS Studio demonstrates compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or the processing is necessary for the establishment, exercise or defence of legal claims. The data subject may object to the processing of personal data for direct marketing at any time without giving reasons. Following the objection, personal data will no longer be used for advertising contact. ABS Studio may retain a minimal suppression record of the contact method and objection in order to prevent renewed contact. ABS Studio does not use a newsletter or an automated mass direct-marketing system; only individual B2B customer acquisition in accordance with Section 13 may take place.
23. Right to lodge a complaint with a supervisory authority
The data subject has the right to lodge a complaint with a data protection supervisory authority, in particular in the place of habitual residence, place of work or place of the alleged infringement. For ABS Studio, the following authority is particularly competent at the place of business: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW) Postfach 20 04 44 40102 Düsseldorf Germany Email: poststelle@ldi.nrw.de Website: https://www.ldi.nrw.de
24. Technical and organisational measures
ABS Studio implements risk-based technical and organisational measures in accordance with Article 32 GDPR. These include in particular HTTPS/TLS, strong and unique passwords, a password manager, two-factor authentication for critical services, access restrictions based on the principle of least privilege, updates to devices and software, backups, data minimisation, pseudonymous Project IDs, review of integrations and DPAs/AVVs, retention rules and a procedure for responding to security incidents. Detailed TOMs are maintained as internal documentation and are not published in full because excessive disclosure of technical safeguards could create additional security risks. No system can guarantee absolute security. Users should not send passwords, full payment details, special categories of personal data or other particularly confidential information through unencrypted email or messenger services without first agreeing on a secure transmission method.
25. Automated decision-making and profiling
ABS Studio does not make decisions that produce legal effects concerning a person or similarly significantly affect that person solely on the basis of automated processing within the meaning of Article 22 GDPR. AI tools may assist with technical tasks; however, decisions concerning a contract, plan, payment, payment default, Buyout, transfer, termination of contract or legally significant communication are reviewed by a human. Stripe may use automated systems for fraud detection, risk assessment and payment authentication under its own terms.
26. Data relating to minors
The website and paid services of ABS Studio are directed at business customers and not at children. ABS Studio does not knowingly request children's data through the website. If ABS Studio becomes aware that data relating to a minor has been submitted without a sufficient legal basis, it will be deleted unless continued retention is required by law.
27. Changes to this Privacy Policy
ABS Studio updates this Privacy Policy where the actual processing activities, the website, the providers used or legal requirements change. The current version is published on the official website together with the date of the latest update. Where changes materially affect processing or consent previously given, ABS Studio provides additional information or obtains renewed consent where legally required.
28. Related documents and official legal sources
This Privacy Policy should be read together with the current public documents of ABS Studio:
Legal Notice (Impressum);
General Terms and Conditions (AGB);
Cookie Policy and Cookie Settings. Where ABS Studio processes personal data on behalf of a customer as a processor, the parties separately conclude or accept a DPA/AVV in accordance with Article 28 GDPR. That document is not a general public Privacy Policy for the website, but is made available to the respective customer within the contractual relationship. ABS Studio's internal data protection organisation is additionally documented through the record of processing activities, TOMs, retention rules, a provider and DPA register and other internal records. These internal documents are not part of the public Privacy Policy, but may be made available to a competent authority or contractual partner to the extent required. Key official legal sources: GDPR | Section 25 TDDDG | Section 7 UWG
