Privacy Statement
1) Information on the Collection of Personal Data and Contact Details of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. On the following pages, we inform you about the handling of your personal data when using our website. Personal data is all data with which you can be personally identified.
1.2 The controller in charge of data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is BOS Balance of Storage Systems AG, Böttgerstraße 2/2, 89231 Neu-Ulm, Deutschland, Tel.: 073172544107, E-Mail: [email protected] The controller in charge of the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller). You can recognize an encrypted connection by the character string https:// and the lock symbol in your browser line.
2) Data Collection When You Visit Our Website
When using our website for information only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data that is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the moment of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
Data processing is carried out in accordance with Art. 6 (1) point f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files subsequently, if there are any concrete indications of illegal use.
3) Hosting & Content Delivery Network
3.1 Hosting by Shopify
We use the shop system of the service provider Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify"), for the purpose of hosting and displaying the online shop on the basis of processing on our instructions. All data collected on our website is processed on Shopify's servers. Within the scope of the aforementioned Shopify services, data may also be transferred to Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc. or Shopify (USA) Inc. for further processing on our behalf. In the event that data is transferred to Shopify Inc. in Canada, the appropriate level of data protection is guaranteed by an adequacy decision of the European Commission.
For more information on Shopify's privacy policy, please visit the following website: https://www.shopify.com
Further processing on servers other than the aforementioned servers of Shopify will only take place within the scope of the following information.
3.2 - Cloudflare
On our website we use a content delivery network ("CDN") of the technology service provider Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA ("Cloudflare"). A Content Delivery Network is an online service used to deliver large media files (such as graphics, page content or scripts) through a network of regionally distributed servers connected via the internet. The use of Cloudflare's content delivery network helps us to optimise the loading speeds of our website.
The processing takes place in accordance with Art. 6 (1) point f GDPR on the basis of our legitimate interest in a secure and efficient provision, as well as improvement of the stability and functionality of our website.
For more information about Cloudfare’s privacy policy, please visit https://www.cloudflare.com
4) Cookies
To make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your end device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your terminal and enable us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). If cookies are set, they collect and process specific user information such as browser and location data as well as IP address values according to individual requirements. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can check the duration of the respective cookie storage in the overview of the cookie settings of your web browser.
In some cases, cookies are used to simplify the ordering process by saving settings (e.g. remembering the content of a virtual shopping basket for a later visit to the website). If personal data are also processed by individual cookies set by us, the processing is carried out in accordance with Art. 6 (1) point b GDPR either for the execution of the contract or in accordance with Art. 6 (1) point f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.
Please note that you can set your browser in such a way that you are informed about the setting of cookies and you can decide individually about their acceptance or exclude the acceptance of cookies for certain cases or generally. Each browser differs in the way it manages the cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You will find these for the respective browsers under the following links:
- Microsoft Edge: https://support.microsoft.com
- Firefox: https://support.mozilla.org
- Chrome: https://support.google.com
- Safari: https://support.apple.com
- Opera: https://help.opera.com
Please note that the functionality of our website may be limited if cookies are not accepted.
5) Contacting Us
When you contact us (e.g. via contact form or e-mail), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your request or for establishing contact and for the associated technical administration. The legal basis for processing data is our legitimate interest in responding to your request in accordance with Art. 6 (1) point f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) point b GDPR. Your data will be deleted after final processing of your enquiry; this is the case if it can be inferred from the circumstances that the facts in question have been finally clarified, provided there are no legal storage obligations to the contrary.
6) Use of Client Data for Direct Advertising
6.1 Subscribe to our e-mail newsletter
If you register for our e-mail newsletter, we will regularly send you information about our offers. The only mandatory data for sending the newsletter is your e-mail address. The provision of further data is voluntary and will be used to address you personally. We use the so-called double opt-in procedure for sending the newsletter. This means that we will only send you an e-mail newsletter once you have expressly confirmed that you consent to receiving newsletters. We will then send you a confirmation e-mail asking you to confirm that you wish to receive the newsletter in future by clicking on an appropriate link.
By activating the confirmation link, you give us your consent for the use of your personal data pursuant to Art. 6 (1) point a GPPR. When you register for the newsletter, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration for the purpose of tracing any possible misuse of your e-mail address at a later date. The data collected by us when you register for the newsletter is used exclusively for the promotional purposes by way of the newsletter. You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a corresponding message to the responsible person named at the beginning. After unsubscribing, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data, or we reserve the right to a more extensive use your data which is permitted by law and about which we inform you in this declaration.
6.2 Sending the newsletter to existing customers
If you have provided us with your e-mail address when purchasing products, we reserve the right to regularly send you offers for products similar to those already purchased by e-mail. Pursuant to Section 7 (3) German law against unfair competition, we do not need to obtain separate consent from you. In this respect, data processing is carried out solely on the basis of our legitimate interest in personalized direct advertising pursuant to Art. 6 (1) point f GDPR. If you have initially objected to the use of your e-mail address for this purpose, we will not send you an e-mail. You are entitled to object to the future use of your e-mail address for the aforementioned advertising purpose at any time by notifying the controller named at the beginning of this document. In this regard, you only have to pay the transmission costs according to the basic tariffs. Upon receipt of your objection, the use of your e-mail address for advertising purposes will cease immediately.
6.3 - MailChimp with "open tracking" and "click tracking" function for newsletter creation and dispatch
Our email newsletters are sent via the technical service provider The Rocket Science Group, LLC d/b/a MailChimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA (http://www.mailchimp.com
MailChimp uses this information to send and statistically evaluate newsletters on our behalf. For evaluation purpose, emails sent contain so-called web beacons or tracking pixels, which are single-pixel image files stored on our website. This enables us to determine whether a newsletter message has been opened and which links, if any, have been clicked on. With the help of the web beacons, Mailchimp automatically creates general, non-personal statistics about the response behavior to newsletter campaigns. However, based on our legitimate interest in the statistical evaluation of the newsletter campaigns for the optimization of the advertising communication and the better alignment with recipient interests, the web beacons also collect and utilize data of the respective newsletter recipient (email address, time of retrieval, IP address, browser type and operating system) in accordance with Art. 6 (1) point f GDPR. This data allows an individual conclusion to be drawn about the newsletter recipient and is processed by Mailchimp for the automated creation of statistics indicating whether a specific recipient has opened a newsletter message.
If you wish to deactivate the data analysis for statistical evaluation purposes, you must unsubscribe from the newsletter.
MailChimp may also use this data itself in accordance with Art. 6 (1) point f GDPR based on its own legitimate interest in the needs-based design and optimization of the service as well as for market research purposes, for example to determine which countries recipients come from. However, MailChimp does not use this data of our newsletter recipients to write to them itself or to pass them on to third parties.
To protect your data in the USA, we have concluded a data processing agreement ("Data Processing Agreement") with MailChimp based on the standard contractual clauses of the European Commission to enable the transfer of your personal data to MailChimp. If you are interested, this data processing agreement can be viewed at the following internet address: https://mailchimp.com
You can view MailChimp's privacy policy here:
https://mailchimp.com
6.4 Notification by e-mail of stock availability
If our online shop provides the possibility of informing you by e-mail about the time of availability for selected, temporarily unavailable items, you can subscribe to our e-mail notification service for product availability. If you register for our e-mail notification service for product availability, we will send you a one-time message by e-mail about the availability of the article you have selected. The only mandatory information needed to send this notification is your e-mail address. The indication of further data is voluntary and is used if appropriate, in order to be able to address you personally. We use the so-called double opt-in procedure when sending this notification. This means that we will only send you a corresponding notification after you have expressly confirmed that you agree to receive such a message. We will then send you a confirmation e-mail asking you to click on a link to confirm that you wish to receive such notification.
By activating the confirmation link, you consent to the use of your personal data in accordance with Art. 6 (1) point a GDPR. When you register for our e-mail notification service for product availability, we store your IP address as registered by the internet service provider (ISP) as well as the date and time of registration in order to be able to track any possible misuse of your e-mail address at a later time. The data collected by us when you register for our e-mail notification service regarding the availability of goods is used exclusively for the purpose of informing you about the availability of a particular item in our online shop. You can cancel the e-mail notification service for the availability of goods at any time by sending a corresponding message to the controller in charge of data processing named at the beginning. After you have unsubscribed, your e-mail address will be deleted immediately from our distribution list, unless you have expressly consented to the further use of your data or unless we reserve the right to make further use of your data in accordance with the law about which we inform you in this declaration.
7) Processing of Data for the Purpose of Order Handling
7.1 Insofar as necessary for the processing of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 (1) lit. b GDPR.
If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we will process the contact data (name, address, e-mail address) provided by you when placing the order in order to inform you personally by suitable means of communication (e.g. by post or e-mail) about upcoming updates within the legally stipulated period of time within the framework of our statutory duty to inform pursuant to Art. 6 (1) lit. c GDPR. Your contact details will be used strictly for the purpose of informing you about updates owed by us and will only be processed by us for this purpose to the extent necessary for the respective information.
In order to process your order, we also work together with the following service provider(s), who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.
7.2 Passing on Personal Data to Shipping Service Providers
- Deutsche Post
If delivery of goods takes place by the transport service provider Deutsche Post (Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn), we will pass on your e-mail address to Deutsche Post in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, only if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to Deutsche Post for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with Deutsche Post or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider Deutsche Post.
- DHL
If delivery of goods takes place by the transport service provider DHL (Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn), we will pass on your e-mail address to DHL in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, only if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to DHL for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with DHL or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider DHL.
- DPD
If delivery of goods takes place by the transport service provider DPD (DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg), we will pass on your e-mail address to DPD in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to DPD for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with DPD or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider DPD.
- FedEx
If delivery of goods takes place by the transport service provider FedEx (FedEx Express Germany GmbH, Langer Kornweg 34 k, 65451 Kelsterbach, Germany), we will pass on your e-mail address to FedEx in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, only if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to FedEx for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with FedEx or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider FedEx.
- GLS
If delivery of goods takes place by the transport service provider GLS (General Logistics Systems Germany GmbH & Co. OHG, GLS Germany-Straße 1 – 7, 36286 Neuenstein), we will pass on your e-mail address to GLS in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to GLS for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with GLS or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider GLS.
- Hermes
If delivery of goods takes place by the transport service Hermes (Hermes Logistik Gruppe Deutschland GmbH, Essener Straße 89, 22419 Hamburg), we will pass on your e-mail address to Hermes in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to Hermes for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with Hermes or transmission of status information for shipment delivery is not possible.
The consent can be revoked for futre deliveries at any time, with the controller or with the transport service provider Hermes.
- TNT
If delivery of goods takes place by the transport service provider TNT (TNT Express GmbH, Haberstraße 2, 53842 Troisdorf)), we will pass on your e-mail address to TNT in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, only if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to TNT for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with TNT or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider TNT.
- UPS
If delivery of goods takes place by the transport service UPS (United Parcel Service Deutschland Inc. & Co. OHG, Görlitzer Straße 1, 41460 Neuss), we will pass on your e-mail address to UPS in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to UPS for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with UPS or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider UPS.
- Schenker
If delivery of goods takes place by the transport service provider Schenker (Schenker Deutschland AG, Lyoner Straße 15, 60528 Frankfurt am Main, Germany), we will pass on your e-mail address to Schenker in accordance with Art. 6 (1) point a GDPR, prior to delivery of the goods, for the purpose of coordinating a date of delivery or of a notice about the shipment status, only if you have given your express consent during the ordering process. Otherwise, only the name of the recipient and the delivery address will be passed on to Schenker for the purpose of delivery in accordance with Art. 6 (1) point b GDPR. The data will only be passed on if this is necessary for the delivery of the goods. In this case, prior agreement on the delivery date with Schenker or transmission of status information for shipment delivery is not possible.
The consent can be revoked for future deliveries at any time, either with the controller or with the transport service provider Schenker.
7.3 Use of Payment Service Providers
- Amazon Pay
If you choose the "Amazon Pay" payment method, payment will be processed by the payment service provider Amazon Payments Europe s.c.a., 38 avenue John F. Kennedy, L-1855 Luxembourg (hereinafter referred to as "Amazon Payments"), to whom we will pass on the information you provided during the order process together with the information about your order in accordance with Art. 6 (1) point b GDPR. Your data will only be passed on for the purpose of payment processing with the payment service provider Amazon Payments and only to the extent necessary. For more information about Amazon Payments' privacy policy, please visit https://pay.amazon.com
- Apple Pay
If you choose the payment method "Apple Pay" of Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, the payment processing is carried out via the "Apple Pay" function of your terminal device operated with iOS, watchOS or macOS by debiting a payment card deposited with "Apple Pay". Apple Pay uses security features built into the hardware and software of your device to protect your transactions. In order to release a payment, it is therefore necessary to enter a code previously defined by you and to verify it using the "Face ID" or "Touch ID" function of your terminal.
For the purpose of payment processing, your information provided during the ordering process, along with information about your order, will be transmitted to Apple in encrypted form. Apple then encrypts this data again with a developer-specific key before the data is transmitted to the payment service provider of the payment card stored in Apple Pay for payment processing. The encryption ensures that only the website from which the purchase was made can access the payment information. After the payment is made, Apple sends your device account number and a transaction-specific dynamic security code to the originating website to confirm the payment.
If personal data is processed in the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 Para. 1 lit. b GDPR.
Apple retains anonymised transaction data, including the approximate amount of the purchase, the approximate date and time and whether the transaction was completed successfully. Anonymisation completely excludes any personal reference. Apple uses the anonymised data to improve Apple Pay and other Apple products and services.
When you use Apple Pay on iPhone or the Apple Watch to complete a purchase made through Safari on Mac, the Mac and the authorization device communicate through an encrypted channel on Apple's servers. Apple does not process or store this information in any format that can identify you personally. You can disable the ability to use Apple Pay on your Mac in your iPhone preferences. Go to "Wallet & Apple Pay" and disable "Allow payments on Mac".
For more information about Apple Pay privacy, please visit the following web address: https://support.apple.com
- Google Pay
If you choose the payment method "Google Pay" of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), the payment processing is carried out via the "Google Pay" application of your mobile device running at least Android 4.4 ("KitKat") and having an NFC function by charging a payment card deposited at Google Pay or a payment system verified there (e.g. PayPal). For the release of a payment via Google Pay in the amount of more than 25,- € the prior unlocking of your mobile device by the respective verification measure (e.g. face recognition, password, fingerprint or pattern) is required.
For the purpose of payment processing, your information provided during the ordering process, together with the information about your order, will be forwarded to Google. Google then transmits your payment information stored in Google Pay in the form of a unique transaction number to the source website, which is used to verify a payment. This transaction number does not contain any information about the real payment data of your means of payment deposited with Google Pay, but is created and transmitted as a uniquely valid numeric token. For all transactions via Google Pay, Google acts merely as an intermediary to process the payment transaction. The transaction is carried out exclusively in the relationship between the user and the source website by debiting the means of payment deposited with Google Pay.
If personal data are processed in the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Google reserves the right to collect, store and evaluate certain transaction-specific information for each transaction made via Google Pay. This includes the date, time and amount of the transaction, the merchant's location and description, a description provided by the merchant of the goods or services purchased, photos that you have attached to the transaction, the name and email address of the seller and buyer or the sender and recipient, the payment method used, your description of the reason for the transaction and, if applicable, the offer associated with the transaction.
According to Google, this processing is carried out exclusively in accordance with Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in proper accounting, verification of transaction data and optimisation and maintenance of the functionality of the Google Pay service.
Google also reserves the right to combine the processed transaction data with other information which is collected and stored by Google when using other Google services.
The terms of use of Google Pay can be found here:
https://payments.google.com
Further information on data protection at Google Pay can be found at the following Internet address:
https://payments.google.com
- Klarna
If the payment method "Klarna invoice purchase" or (if offered) the payment method "Klarna Installment Purchase" is selected, payment is processed by Klarna AB (publ )[https://www.klarna.com
The credit report can contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on recognized scientific, mathematical-statistical methods. The calculation of the score values includes, but is not limited to, address data. Klarna uses the information received on the statistical probability of non-payment for a balanced decision on the establishment, implementation or termination of the contractual relationship.
You can revoke your consent at any time by sending a message to the controller responsible for data processing or to Klarna. However, Klarna may still be entitled to process your personal data if this is necessary to process payments in accordance with the contract.
- Paypal
When you pay via PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "payment by instalments" via PayPal, we transmit your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"). The transfer takes place in accordance with Art. 6 (1) point b GDPR and only to the extent necessary for payment processing.
PayPal reserves the right to carry out credit checks for the payment methods credit card via PayPal, direct debit via PayPal or, if offered, "purchase on account" or "payment by installments" via PayPal. For this purpose, your payment data may be passed on to credit agencies based on PayPal's legitimate interest in determining your solvency pursuant to Art. 6 (1) point f GDPR. PayPal uses the result of the credit assessment in relation to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report can contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on recognized scientific, mathematical-statistical methods. The calculation of the score values includes, but is not limited to, address data. For further information on data protection law, including the credit agencies used, please refer to PayPal's data protection declaration at: https://www.paypal.com
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
- Paypal Checkout
This website uses PayPal Checkout, an online payment system from PayPal, which consists of PayPal's own payment methods and local payment methods from third-party providers.
When paying via PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "Pay Later" via PayPal, we pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. The transfer takes place in accordance with Art. 6 Para. 1 lit. b GDPR and only insofar as this is necessary for the payment processing.
For the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "pay later" via PayPal - PayPal reserves the right to conduct a credit check. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of PayPal's legitimate interest in determining your solvency. PayPal uses the result of the credit check in terms of the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The creditworthiness information may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they have their basis in a scientifically recognised mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for the contractual processing of payments.
If you select the PayPal payment method "purchase on account", your payment data will first be transmitted to PayPal in preparation for payment, whereupon PayPal will forward this data to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin ("Ratepay") in order to process the payment. The legal basis in each case is Art. 6 para. 1 lit. b GDPR. In this case, RatePay carries out an identity and creditworthiness check on its own behalf to determine solvency in accordance with the principle already mentioned above and passes on your payment data to credit agencies on the basis of the legitimate interest in determining solvency in accordance with Art. 6 Para. 1 lit. f GDPR. A list of the credit agencies that Ratepay may use can be found here: https://www.ratepay.com
If you use the payment method of a local third-party provider, your payment data will first be passed on to PayPal in preparation for the payment in accordance with Art. 6 para. 1 lit. b GDPR. Depending on your selection of an available local payment method, PayPal will then transmit your payment data to the corresponding provider in order to carry out the payment in accordance with Art. 6 Para. 1 lit. b GDPR:
- Sofort (SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany)
- iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
- giropay (Paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main, Germany)
- bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
- blik (Polski Standard Płatności sp. z o.o., ul. Czerniakowska 87A, 00-718 Warsaw, Poland)
- eps (STUZZA Studiengesellschaft für Zusammenarbeit im Zahlungsverkehr GmbH, Frankgasse 10/8, 1090 Vienna, Austria)
- MyBank (PRETA S.A.S, 40 Rue de Courcelles, F-75008 Paris, France)
- Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)
For further information on data protection, please refer to PayPal's privacy policy: https://www.paypal.com
- Shopify Payments
We use the payment service provider "Shopify Payments", 3rd Floor, Europe House, Harcourt Building, Harcourt Street, Dublin 2. If you choose a payment method offered by the payment service provider Shopify Payments, the payment is processed by the technical service provider Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we will forward the information you have provided in connection with your order (name, address, account number, sort code, credit card number if applicable, invoice amount, currency and transaction number) in accordance with Art. 6 (1) point f GDPR. Your data will only be passed on for the purpose of payment processing with Stripe Payments Europe Ltd. and only to the extent necessary. You can view Shopify Payments' privacy policy at: https://www.shopify.com
You can view more information about the privacy policy of Stripe Payments Europe Ltd. at: https://stripe.com
- SOFORT
If you select the "SOFORT" payment method, payment will be processed by the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter "SOFORT"), to whom we will pass on your information provided during the order process together with the information about your order in accordance with Art. 6 (1) point b GDPR. SOFORT is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Your data will only be passed on for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary. SOFORT's privacy policy can be viewed at: https://www.klarna.com
- Stripe
If you choose a Stripe payment method, payment is processed by the payment service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we pass on your information provided during the order process together with the information about your order (name, address, account number, bank code, bank code if applicable, credit card number, invoice amount, currency and transaction number) in accordance with Art. 6 (1) point b GDPR. Your data will only be passed on for the purpose of payment processing with the payment service provider Stripe Payments Europe Ltd. and only to the extent necessary. For more information about Stripe's privacy policy, please visit: https://stripe.com
8) Online Marketing
8.1 Facebook pixel for creating custom audiences with extended data matching feature (with Cookie Consent Tool)
Within our online offer, the so-called "Facebook pixel" of the social network Facebook in extended data matching mode is applied. It is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (hereinafter "Facebook").
If a user, who has given his explicit consent, clicks on an advertisement placed by us and played on Facebook, an addition is made to the URL of our linked page by Facebook pixels. This URL parameter is then entered into the user's browser via a cookie after it has been forwarded, which is set by our linked page itself. In addition, this cookie collects specific customer information, such as the email address that we collect on our Facebook-associated website during transactions such as purchases, account signups, or registrations (advanced data matching). The cookie is then read by Facebook Pixel and enables the data, including the specific customer data, to be forwarded to Facebook.
With the help of the Facebook pixel with extended data matching feature, Facebook is able to determine visitors of our online offer as a target group for the presentation of ads (so-called "Facebook ads"). Accordingly, the Facebook pixel with extended data matching feature to display Facebook ads placed by us will be presented only to Facebook users who have shown an interest in our online offer or who demonstrate certain characteristics (e.g., interest in certain topics or products determined by means of the websites visited) which we transmit to Facebook (so-called "custom audiences"). When using Facebook pixels, we also want to ensure that our Facebook ads match the potential interest of users and are not annoying. This allows us to evaluate the effectiveness of Facebook ads for statistical and market research purposes by tracking whether users were forwarded to our website after clicking on a Facebook ad ("conversion"). Compared to the standard variant of Facebook Pixel, the extended data matching feature helps us better measure the effectiveness of our advertising campaigns by tracking more associated conversions.
All transmitted data is stored and processed by Facebook to enable a connection to the respective user profile and to allow Facebook to use the data for its own advertising purposes in accordance with the Facebook Data Usage Guidelines (https://www.facebook.com
These processes are subject to express consent in accordance with Art. 6 (1) point a GDPR.
Consent to the use of the Facebook pixel may only be given by users who are older than 13 years of age. If you are younger, please ask your parent or guardian for permission.
The information generated by Facebook is usually transmitted to a Facebook server and stored there; this may also involve transmission to the servers of Meta Platforms Inc. in the USA. You can revoke your consent at any time with effect for the future. To exercise your revocation, remove the tick next to the setting for the "Facebook Pixel" in the "Cookie Consent Tool" embedded on the website.
8.2 - Google AdSense
This website uses Google AdSense, a web ad service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland ("Google"). Google AdSense uses so-called cookies. These are text files are stored on your computer and enable an analysis of your use of the website. In addition, Google AdSense also uses "web beacons" (small invisible graphics) to collect information, which can be used to record, collect and evaluate simple actions such as visitor traffic on the website. The information generated by those cookies and/or web beacons (including your IP address) about your use of this website will normally be transmitted to a server of Google and will be stored there. When using Google AdSense, personal data may also be transmitted to the servers of Google LLC. in the USA.
Google will use the information obtained in this way to analyze your usage of this website with regard to AdSense ads. The IP address transmitted by your browser as part of Google AdSense is not merged with other Google data. The information collected by Google may be transferred to third parties, if this is prescribed by law and/or if third parties process this data by request of Google.
All processing described above, in particular the reading of information on the end device used, is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GPDR. Without this consent, Google AdSense will not be used during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
For more information about Google's privacy policy, please visit: https://privacy.google.com
- Google Ads Conversion-Tracking
This website uses the online advertising program "Google Ads" and, within the scope of Google Ads, the conversion tracking of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use Google Ads to draw attention to our attractive offers on external websites with the help of advertising media (so-called Google Adwords). We can determine how successful the individual advertising measures are in relation to the data of the advertising campaigns. Our aim is to show you advertising that is of interest to you, to make our website more interesting for you and to achieve a fair calculation of the advertising costs incurred.
The conversion tracking cookie is set when a user clicks on an ad placed by Google. Cookies are small text files that are stored on your end device. These cookies usually lose their validity after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Cookies cannot therefore be tracked across Google Ads clients' websites. The information obtained using the conversion cookie is used to create conversion statistics for Google Ads customers who have opted in to conversion tracking. Clients learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
The use of Google Ads may also result in the transmission of personal data to the servers of Google LLC. in the USA.
Details on the processing triggered by Google Ads Conversion Tracking and on Google's handling of data from websites can be found here: https://policies.google.com
All of the processing described above, in particular the setting of cookies for reading out information on the end device used, will only be carried out if you have given us your express consent to do so in accordance with Art. 6 (1) a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.
You can also permanently object to the setting of cookies by Google Ads conversion tracking by downloading and installing the Google browser plug-in available at the following link:
https://www.google.com
In order to address users whose data we have received in the context of business or business-like relationships in a more interest-oriented advertising manner, we use a customer matching function in the context of Google Ads. For this purpose, we transmit one or more files with aggregated customer data (primarily email addresses and telephone numbers) electronically to Google. Google does not have access to clear data, but automatically encrypts the information in the customer files during the transmission process using a special algorithm. The encrypted information can then only be used by Google to assign it to existing Google accounts that the data subjects have set up. This enables personalized advertising to be played via all Google services linked to the respective Google account.
Customer data will only be transferred to Google if you have given us your express consent to do so in accordance with Art. 6 (1) a GDPR You can revoke this consent at any time with effect for the future. Further information on Google's data protection measures in relation to the customer matching function can be found here: https://support.google.com
Google's privacy policy can be viewed here: https://policies.google.com
- Google Marketing Platform
This website uses the online marketing tool Google Marketing Platform of the operator Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("GMP").
GMP uses cookies to serve ads relevant to users, to improve campaign performance reports or to prevent a user from seeing the same ads more than once. Google uses a cookie ID to identify which ads are shown in which browser and to prevent them from being shown more than once.
In addition, GMP can use cookie IDs to record so-called conversions that relate to ad requests. This is the case, for example, when a user sees a GMP advertisement and later, using the same browser, calls up the advertiser's website and makes a purchase via this website. According to Google, GMP cookies contain no personal information.
Due to the marketing tools used, your browser automatically establishes a direct connection with the Google server. We have no influence on the scope and further use of the data collected by Google through the use of these tools and therefore inform you as follows according to our state of knowledge: By integrating GMP, Google receives the information that you have called up the corresponding part of our website or clicked on an advertisement from us. If you are registered with a Google service, Google can allocate the visit to your account. Even if you are not registered with Google or have not logged in, it is possible that the provider will find out and save your IP address. In the context of the use of GMP, personal data may also be transmitted to the servers of Google LLC. in the USA.
All processing described above, in particular the reading of information on the end device used, is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GPDR. Without this consent, GMP will not be used during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
You can obtain further information about the data protection regulations of GMP by Google at the following Internet address: https://policies.google.com
- LinkedIn Marketing Solutions
We use "LinkedIn Marketing Solutions" on our website, a service provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (hereinafter "LinkedIn"). This service enables visitors to our website to be directed to other content of their own that is likely to be of interest to them, based on their usage patterns on the LinkedIn social network. The display of this content is based on a cookie-based analysis of previous usage behavior, but no personal data is stored. For this interest-based content determination, cookies, i.e., small text files, are stored on your computer or mobile device to collect pseudonymized data about your surfing behavior and thus to adapt the content individually to the stored information.
The information can be assigned to the user's person with the help of further information that LinkedIn has stored about the user, e.g., due to the ownership of an account on the social network "LinkedIn". LinkedIn uses an algorithm to analyze the surfing behavior and can then display targeted product recommendations as personalized advertising banners on the user's LinkedIn account. LinkedIn may also combine the information collected via the cookies with other information LinkedIn has collected via other websites and/or in connection with the use of the "LinkedIn" social network, thus creating pseudonymous user profiles. Under no circumstances, however, can the information collected be used to personally identify visitors to this website.
All processing described above, in particular the reading of information on the end device used, is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GPDR. Without this consent, LinkedIn Marketing Solution will not be used during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
Further information on LinkedIn's data protection provisions can be found on the following website: https://www.linkedin.com
- LinkedIn Insight
This website uses the retargeting and conversion tool of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. This service enables personalized advertisements on the Linkedin platform to be displayed to visitors to this website.
For this purpose, a cookie, a small text file, is set on the browser of your end device when you visit our website, which loses its validity after 120 days. If the user visits certain pages of this website and is logged into his LinkedIn account at the same time, a connection is established to the LinkedIn servers, via which interest-based advertising can be displayed on the platform. At the same time, the cookie enables anonymous reports on the performance of the advertisements on LinkedIn as well as information on website interaction to be generated, which are provided to us and LinkedIn.
The display of advertisements and the creation of statistical reports will not take place if the user is not logged in to this LinkedIn account at the same time when visiting this website.
The information obtained with the aid of the cookie never permits personal identification of the respective user.
All processing described above, in particular the reading of information on the end device used, is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GPDR. Without this consent, LinkedIn Insight will not be used during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
You can deactivate the LinkedIn Insight Tool and the display of interest-based advertising on LinkedIn by additionally setting an opt-out cookie at the following link: https://www.linkedin.com
This opt-out cookie only works regarding this browser and only for this domain. If you delete your cookies in this browser, you must click on the above link again.
You can obtain further information on LinkedIn's data protection provisions at the following Internet address: https://www.linkedin.com
9) Web Analysis Services
9.1 Google Analytics 4
This website uses Google Analytics 4, a service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which can be used to analyze the use of websites.
When using Google Analytics 4, so-called "cookies" are used as standard. Cookies are text files that are stored on your terminal device and enable an analysis of your use of a website. The information collected by cookies about your use of the website (including the IP address transmitted by your terminal device, shortened by the last digits, see below) is usually transmitted to a Google server and stored and processed there. This may also result in the transmission of information to the servers of Google LLC, a company based in the USA, where the information is further processed.
When using Google Analytics 4, the IP address transmitted by your terminal device when you use the website is always collected and processed by default and automatically only in an anonymized manner, so that a direct personal reference of the collected information is excluded. This automatic anonymization is carried out by shortening the IP address transmitted by your terminal device by Google within member states of the European Union (EU) or other contracting states of the Agreement on the European Economic Area (EEA) by the last digits.
On our behalf, Google uses this and other information to evaluate your use of the website, to compile reports (reports) on your website activities or your usage behavior and to provide us with other services related to your website usage and internet usage. In this context, the IP address transmitted and shortened by your terminal device within the scope of Google Analytics 4 will not be merged with other data from Google. The data collected in the context of the use of Google Analytics 4 will be retained for 2 months and then deleted.
Google Analytics 4 also enables the creation of statistics with statements about age, gender and interests of website users on the basis of an evaluation of interest-based advertising and with the involvement of third-party information via a special function, the so-called "demographic characteristics". This makes it possible to determine and distinguish user groups of the website for the purpose of targeting marketing measures. However, data collected via the "demographic characteristics" cannot be assigned to a specific person and thus not to you personally. This data collected via the "demographic characteristics" function is retained for two months and then deleted.
All processing described above, in particular the setting of Google Analytics cookies for the storage and reading of information on the terminal device used by you for the use of the website, will only take place if you have given us your express consent for this in accordance with Art. 6 (1) lit. a GDPR. Without your consent, Google Analytics 4 will not be used during your use of the website. You can revoke your consent once given at any time with effect for the future. To exercise your revocation, please deactivate this service via the "Cookie Consent Tool" provided on the website.
In connection with this website, the "UserIDs" function is also used as an extension of Google Analytics 4. By assigning individual UserIDs, we can have Google create cross-device reports (so-called "cross-device tracking"). This means that your usage behavior can also be analyzed across devices if you have given your corresponding consent to the use of Google Analytics 4 in accordance with Art. 6 (1) lit. a GDPR, if you have set up a personal account by registering on this website and are logged into your personal account on different end devices with your relevant login data. The data collected in this way shows, among other things, on which end device you clicked on an ad for the first time and on which end device the relevant conversion took place.
In connection with this website, the Google Signals service is also used as an extension of Google Analytics 4. With Google Signals, we can have Google create cross-device reports (so-called "cross-device tracking"). If you have activated "personalized ads" in your Google account settings and linked your Internet-enabled end devices to your Google account, Google can analyze usage behavior across devices and create database models based on this if you have given your consent to the use of Google Analytics 4 in accordance with Art. 6 (1) a GDPR. The logins and device types of all website users who were logged into a Google account and executed a conversion are taken into account. The data shows, among other things, on which device you clicked on an ad for the first time and on which device the relevant conversion took place. We do not receive any personal data from Google in this regard, but only statistics compiled on the basis of Google Signals. You have the option of deactivating the "personalized ads" function in the settings of your Google account and thus turning off the cross-device analysis in connection with Google Signals. To do this, follow the instructions on this page: https://support.google.com
You can find more information about Google Signals at the following link: https://support.google.com
We have concluded a so-called data processing agreement with Google for our use of Google Analytics 4, by which Google is obliged to protect the data of our website users and not to pass it on to third parties.
To ensure compliance with the European level of data protection, even in the event of any transfer of data from the EU or EEA to the USA and possible further processing there, Google refers to the so-called standard contractual clauses of the European Commission, which we have contractually agreed with Google.
Further legal information on Google Analytics 4, including a copy of the aforementioned standard contractual clauses, can be found at the following link: https://policies.google.com
Details on the processing triggered by Google Analytics 4 and Google's handling of data from websites can be found here: https://policies.google.com
9.2 - This website uses the "Google Tag Manager", a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google"). The Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analysis services, and for calibrating, controlling and attaching conditions to them via a uniform user interface.
Google Tag Manager itself does not store any information on user end devices or read them. The service also does not perform any independent data analyses.
However, the Google Tag Manager transmits your IP address to Google when you visit a page and may store it there. Also a transmission to servers of Google LLC in the USA is possible.
This processing is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GDPR. Without this consent, Google Tag Manager will not be used during your visit to the website.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
We have concluded an order processing agreement with Google, which obliges Google to protect the data of our website visitors and not to pass it on to third parties.
For the transfer of data from the EU to the USA, Google invokes so-called standard data protection clauses of the European Commission, which are intended to ensure compliance with the European level of data protection in the USA.
Further privacy information on Google Tag Manager can be found here: https://support.google.com
You will find separate information on data protection-relevant services and applications that have been merged in Google Tag Manager in the corresponding sections of this privacy policy.
10) Retargeting/Remarketing/ Referral Advertising
Google Ads Remarketing
This website uses the online advertising program "Google Ads" and, within the scope of Google Ads, the conversion tracking of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use Google Ads to draw attention to our attractive offers on external websites with the help of advertising media (so-called Google Adwords). We can determine how successful the individual advertising measures are in relation to the data of the advertising campaigns. In this way, we pursue the concern of showing you advertising that is of interest to you, making our website more interesting for you and achieving a fair calculation of the advertising costs incurred
The conversion tracking cookie is set when a user clicks on an ad placed by Google. Cookies are small text files that are stored on your terminal device. These cookies usually lose their validity after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize if the user has clicked on the ad and has been directed to this page. Each Google Ads customer receives a different cookie. Cookies therefore cannot be tracked across Google Ads customers’ websites. The information obtained using the conversion cookie is used to create conversion statistics for Google Ads customers who have chosen conversion tracking. Customers learn the total number of users who clicked on their ad and who were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users. The use of Google Ads may also result in the transmission of personal data to the servers of Google LLC. in the USA.
Details on the processing operations initiated by Google Ads conversion tracking and on Google's handling of data collected from websites can be found here: https://policies.google.com
All processing described above, in particular the setting of cookies for the reading of information on the end device used, will only be carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GDPR. Without this consent, Google Conversion Tracking will not be used during your visit to the website.
You can permanently disable the setting of cookies by Google Ads Conversion Tracking for advertising preferences. You may download and install the browser plug-in available at the following link: https://support.google.com
Please note that certain functions of this website may not be available or may be restricted if you have deactivated the use of cookies.
Further information about Google’s privacy policy can be viewed at:
http://www.google.com
11) Site Functionalities
11.1 Use of YouTube Videos
This website uses the YouTube embedding function for display and playback of videos offered by the provider YouTube, which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland ("Google").
To this end, the extended data protection mode is used to ensure, according to provider information, that user information will only be stored once the playback function of the video is started. When the playback of embedded YouTube videos is started, the provider sets "YouTube" cookies to collect information about user behavior. According to indications from YouTube, the use of those cookies is intended, among other things, to record video statistics, to improve user-friendliness and to avoid improper actions. If you are logged in to Google, your information will be directly associated with your account when you click on a video. If you do not wish to be associated with your profile on YouTube, you must log out before activating the button. Google saves your data (even for users who are not logged in) as usage profiles and evaluates them. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right. When using YouTube, personal data may also be transmitted to the servers of Google LLC. in the USA.
Regardless of whether the embedded video is played back, a connection to the Google network "double click" is established when visiting this website. This may trigger further data processing beyond our control.
All processing described above, in particular the setting of cookies for the reading of information on the end device used, will only be carried out if you have given us your express consent to do so in accordance with Art. 6 (1) point a GDPR. Without this consent, Youtube-Videos will not be used during your visit to the website.
You can revoke your consent at any time with effect for the future. If you wish to exercise your right of revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
Further information on YouTube's privacy policy can be found at: www.google.com/policies/privacy/.
11.2 Google Web Fonts
This site uses web fonts provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") to uniformly display fonts. When you call up a page, your browser loads the required web fonts into its browser cache to display texts and fonts correctly.
To do this, the browser you are using must have a connection to Google's servers. When using Google Maps, personal data may also be transmitted to the servers of Google LLC. in the USA. In this way, Google will be informed that our website has been accessed via your IP address. Google Web Fonts are used for the purpose of a uniform and attractive presentation of our online offers and its use is in our legitimate interest within the meaning of Art. 6 (1) point f GDPR. If your browser does not support web fonts, a default font is used by your computer.
Further information about Google Web Fonts can be found at https://developers.google.com
On this website we also use the reCAPTCHA function of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This function is mainly used to distinguish whether an entry is made by a natural person or misused by automatic and automated processing. The service includes the sending of the IP address and possibly other data required by Google for the reCAPTCHA service to Google. The use of Google reCAPTCHA may also result in the transmission of personal data to the servers of Google LLC. in the USA and is carried out in accordance with Art. 6 (1) point f GDPR, on the basis of our legitimate interest in determining the individual willingness of actions on the Internet and avoiding misuse and spam.
Further information about Google reCAPTCHA and Google's privacy policy can be found at: https://policies.google.com
12) Tools and Miscellaneous
12.1 This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users in the form of an interactive user interface when they access the page, on which consent for certain cookies and/or cookie-based applications can be given by ticking the appropriate box. Using the tool, all cookies/services requiring consent are only loaded if the respective user provides the corresponding consent by ticking the corresponding box. This ensures that such cookies are only set on the respective end device of the user if consent has been granted.
The tool sets technically necessary cookies to save your cookie preferences. Personal user data is generally not processed.
If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 (1) point GDPR based on our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.
Further legal basis for the processing is Art. 6 (1) point c GDPR. As the responsible party, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user consent.
Further information on the operator and the setting options of the cookie consent tool can be found directly in the corresponding user interface on our website.
12.2 - Cloudflare
For security purposes, this website uses the firewall service provided by Cloudflare, Inc, 101 Townsend St. San Francisco, CA 94107, USA ("Cloudflare").
Cloudfare protects the website and related IT infrastructure from unauthorised third-party access, cyber-attacks, and viruses and malware. Cloudflare collects the IP addresses of users and, where applicable, other data about your behaviour on our website (in particular URLs called up and header information) in order to detect and prevent illegitimate page accesses and threats. In doing so, the collected IP address is compared with a list of known attackers. If the captured IP address is identified as a security risk, Cloudflare can automatically block it from accessing the site. The information collected in this way is transferred to a server of Cloudflare Tech, Inc. in the USA and stored there.
The described data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interests in protecting the website from harmful cyber attacks and in maintaining structural and data integrity and security.
Cloudflare, Inc. invokes the standard data protection clauses according to Art. 46 para. 2 lit. c GDPR as the legal basis for the transfer of data to the USA.
We have concluded a data processing agreement with Cloudflare, Inc. which obliges the company to protect the data of site visitors and not to pass it on to third parties.
For more information about Cloudflare's use of data, please visit https://www.cloudflare.com
12.3 Microsoft Power BI
For internal visualization of business processes and user-defined analyses of business processes, we use the "Microsoft Power BI" service of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Where applicable, personal customer data may be the subject of visualization and analysis processes and may be processed by Microsoft BI for this purpose. In this case, Microsoft processes personal data as a processor bound by instructions in accordance with Art. 28 GDPR. Microsoft has made a contractual commitment to us to protect this data in accordance with the legal requirements. For this purpose, Microsoft uses state-of-the-art encryption procedures and guarantees the exclusive use of data processing procedures in billing centers within the EU.
You can find out more about the data protection measures for Power BI at https://www.microsoft.com
12.4 - Google Maps
Our website uses Google Maps (AP’I) of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). Google Maps is a web service for displaying interactive (country) maps in order to display geographical information visually. Using this service will show you our location and will make it easier for you to find us.
When you access the sub-pages that contain the Google Maps map, information about your use of our website (such as your IP address) is transmitted to and stored by Google on servers. When using Google Maps, personal data may also be transmitted to the servers of Google LLC. in the USA. This is regardless of whether Google provides a user account that you are logged in with or whether no user account exists. If you are logged in to Google, your information will be directly associated with your account. If you do not wish to be associated with your profile on Google, you must log out before activating the button. Google saves your data (even for users who are not logged in) as usage profiles and evaluates them. Such an evaluation takes place according to Art. 6 (1) point f GDPR, on the basis of the legitimate interests of Google in the insertion of personalized advertising, market research and/or demand-oriented design of its website. You have the right to object to the creation of these user profiles. If you want to do so, you must contact Google to exercise this right.
If you do not agree to the future transmission of your data to Google in the context of using Google Maps, you may completely deactivate the Google Maps web service by switching off the JavaScript application in your browser. In this case, Google Maps as well as the map display on this website cannot be used.
The Google terms of use can be found at: https://policies.google.com
You can find detailed information on data protection in connection with the use of Google Maps on Google's website ("Google Privacy Policy") at: https://policies.google.com
To the extent required by law, we have obtained your consent to the processing of your data as described above in accordance with Art. 6 (1) point a GDPR. You can revoke your consent at any time with effect for the future. In order to exercise your revocation, please follow the procedure described above for submitting an objection.
12.5 - DATEV
We use the cloud-based accounting software of DATEV eG, Paumgartnerstr. 6-14, 90429 Nuremberg, Germany ("DATEV") to handle our accounting.
DATEV processes incoming and outgoing invoices and, if applicable, also the bank transactions of our business in order to automatically record invoices, match them to the transactions and create the financial accounting from this in a semi-automated process.
If personal data is also processed in this process, the processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in the efficient organization and documentation of our business transactions.
You can find more information about DATEV, the automated processing of data and its privacy policy at https://www.datev.de
13) Rights of the Data Subject
13.1 The applicable data protection law grants you the following comprehensive rights of data subjects (rights of information and intervention) vis-à-vis the data controller with regard to the processing of your personal data:
- Right of access by the data subject pursuant to Art. 15 GDPR: You shall have the right to receive the following information: The personal data processed by us; the purposes of the processing; the categories of processed personal data; the recipients or categories of recipients to whom the personal data have been or will be disclosed; the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing personal data concerning the data subject or to object to such processing; the right to lodge a complaint with a supervisory authority; where the personal are not collected from the data subject, any available information as to their source; the existence of automated decision-making, including profiling and at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject; the appropriate safeguards pursuant to Article 46 when personal data is transferred to a third country.
- Right to rectification pursuant to Art. 16 GDPR: You have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning you and/or the right to have incomplete personal data completed which are stored by us.
- Right to erasure (“right to be forgotten”) pursuant to Art. 17 GDPR: You have the right to obtain from the controller the erasure of personal data concerning you if the conditions of Art. 17 (2) GDPR are fulfilled. However, this right will not apply for exercising the freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defense of legal claims.
- Right to restriction of processing pursuant to Art. 18 GDPR: You have the right to obtain from the controller restriction of processing your personal data for the following reasons: As long as the accuracy of your personal data contested by you will be verified. If you oppose the erasure of your personal data because of unlawful processing and you request the restriction of their use instead. If you require the personal data for the establishment, exercise or defense of legal claims, once we no longer need those data for the purposes of the processing. If you have objected to processing on grounds relating to your personal situation pending the verification whether our legitimate grounds override your grounds.
- Right to be informed pursuant to Art. 19 GDPR: If you have asserted the right of rectification, erasure or restriction of processing against the controller, he is obliged to communicate to each recipient to whom the personal date has been disclosed any rectification or erasure of personal data or restriction of processing, unless this proves impossible or involves disproportionate effort. You have the right to be informed about those recipients.
- Right to data portability pursuant to Art. 20 GDPR: You shall have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format or to require that those data be transmitted to another controller, where technically feasible.
- Right to withdraw a given consent pursuant to Art. 7 (3) GDPR: You have the right to withdraw your consent for the processing of personal data at any time with effect for the future. In the event of withdrawal, we will immediately erase the data concerned, unless further processing can be based on a legal basis for processing without consent. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint pursuant to Art. 77 GDPR: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR.
13.2 RIGHT TO OBJECT
IF, WITHIN THE FRAMEWORK OF A CONSIDERATION OF INTERESTS, WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR PREDOMINANT LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE ON THE GROUNDS THAT ARISE FROM YOUR PARTICULAR SITUATION.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO FURTHER PROCESSING IF WE CAN PROVE COMPELLING REASONS WORTHY OF PROTECTION FOR PROCESSING WHICH OUTWEIGH YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS.
IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA WHICH ARE USED FOR DIRECT MARKETING PURPOSES. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT ADVERTISING PURPOSES.
14) Duration of Storage of Personal Data
The duration of the storage of personal data is based on the respective legal basis, the purpose of processing and - if relevant – on the respective legal retention period (e.g. commercial and tax retention periods).
If personal data is processed basis on an express consent pursuant to Art. 6 (1) point a GDPR, this data is stored until the data subject revokes his consent.
If there are legal storage periods for data that is processed within the framework of legal or similar obligations on the basis of Art. 6 (1) point b GDPR, this data will be routinely deleted after expiry of the storage periods if it is no longer necessary for the fulfillment of the contract or the initiation of the contract and/or if we no longer have a justified interest in further storage.
When processing personal data on the basis of Art. 6 (1) point f GDPR, this data is stored until the data subject exercises his right of objection in accordance with Art. 21 (1) GDPR, unless we can provide compelling grounds for processing worthy of protection which outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims.
If personal data is processed for the purpose of direct marketing based on Art. 6 (1) point f GDPR, this data is stored until the data subject exercises his right of objection pursuant to Art. 21 (2) GDPR.
Unless otherwise stated in the information contained in this declaration on specific processing situations, stored personal data will be deleted if it is no longer necessary for the purposes for which it was collected or otherwise processed.