Privacy Policy
Privacy Policy
1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy, which is linked below.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. Their contact details can be found in the section "Information on the responsible body" in this privacy policy.
How do we collect your data?
Your data is collected, firstly, because you provide it to us. This could include, for example, data that you enter into a contact form.
Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you access this website.
What do we use your data for?
Some data is collected to ensure the website functions correctly. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other inquiries.
What rights do you have regarding your data?
You have the right to obtain information free of charge at any time regarding the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time with regard to this and other questions concerning data protection.
Analytics tools and third-party tools
When you visit this website, your browsing behavior may be statistically analyzed. This is done primarily using so-called analytics programs.
Detailed information about these analytics programs can be found in the following privacy policy.
2. Hosting and Content Delivery Networks (CDN)
We host the content of our website with the following provider:
All-inclusive
The provider is ALL-INKL.COM - Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf (hereinafter referred to as All-Inkl). For details, please refer to All-Inkl's privacy policy. https://all-inkl.com/datenschutzinformationen/.
The use of All-Inkl is based on Article 6(1)(f) GDPR. We have a legitimate interest in ensuring the most reliable presentation of our website possible. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Cloudflare
We use the service „Cloudflare“. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter „Cloudflare”).
Cloudflare offers a globally distributed Content Delivery Network (CDN) with DNS. Technically, the transfer of information between your browser and our website is routed through the Cloudflare network. This enables Cloudflare to analyze the traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the internet. Cloudflare may also use cookies or other technologies to recognize internet users, but these are used solely for the purpose described here.
The use of Cloudflare is based on our legitimate interest in providing our website in the most error-free and secure way possible (Art. 6 para. 1 lit. f GDPR).
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.
3. General information and mandatory disclosures
Data protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the internet (e.g., when communicating via email) can have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Note regarding the responsible body
The responsible body for data processing on this website is:
Prof. Dr.-Ing. Tim Nosper
RV tech
Technology for motorhomes
Raueneggstraße 29/1
88212 Ravensburg
Germany
Telephone: +49 (0)751 3526122
Email: info@rv-tech.de
The responsible entity is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Storage duration
Unless a more specific retention period is stated within this privacy policy, your personal data will remain with us until the purpose for processing the data no longer applies. If you submit a legitimate request for erasure or withdraw your consent to data processing, your data will be deleted, provided we have no other legally permissible grounds for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the data will be deleted once these grounds cease to apply.
General information on the legal basis for data processing on this website
If you have consented to data processing, we process your personal data on the basis of Article 6(1)(a) GDPR or Article 9(2)(a) GDPR if special categories of data pursuant to Article 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing also takes place on the basis of Article 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing additionally takes place on the basis of Section 25(1) of the German Telemedia Act (TMG). You can withdraw your consent at any time. If your data is required for the performance of a contract or for taking steps prior to entering into a contract, we process your data on the basis of Article 6(1)(b) GDPR. Furthermore, we process your data if it is necessary for compliance with a legal obligation, on the basis of Article 6(1)(c) GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Information on the applicable legal bases in each individual case is provided in the following paragraphs of this privacy policy.
Note regarding data transfers to third countries that do not offer adequate data protection and transfers to US companies that are not DPF-certified.
We use, among other things, tools from companies based in third countries with inadequate data protection laws, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. Please note that a level of data protection comparable to that of the EU cannot be guaranteed in third countries with inadequate data protection laws.
Please note that the USA, as a safe third country, generally offers a level of data protection comparable to that of the EU. Data transfers to the USA are therefore permitted if the recipient is certified under the EU-US Data Privacy Framework (DPF) or has appropriate additional safeguards in place. Information on transfers to third countries, including data recipients, can be found in this privacy policy.
Recipients of personal data
As part of our business activities, we collaborate with various external parties. This sometimes requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Article 6(1)(f) GDPR, or if another legal basis permits the data transfer. When using data processors, we only transfer our customers' personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke your consent at any time. The legality of data processing carried out before the revocation remains unaffected by the revocation.
Right to object to data processing in special cases and to direct marketing (Art. 21 GDPR)
If data processing is based on Article 6(1)(e) or (f) of the GDPR, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you; this also applies to profiling based on these provisions. The specific legal basis for each processing operation can be found in this privacy policy. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing serves the purpose of establishing, exercising or defending legal claims (objection pursuant to Art. 21 para. 1 GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object, your personal data will subsequently no longer be processed for direct marketing purposes (objection pursuant to Article 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged infringement. This right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to receive the data that we process automatically based on your consent or in fulfillment of a contract, either for yourself or for a third party, in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done if technically feasible.
Information, correction and deletion
Under applicable law, you have the right to request information, free of charge, about your stored personal data, its origin and recipients, and the purpose of the data processing, as well as the right to rectification or erasure of this data. You can contact us at any time with regard to this and any other questions concerning personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time to do so. The right to restrict processing exists in the following cases:
- If you dispute the accuracy of your personal data stored with us, we generally need time to verify this. For the duration of the verification process, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you require it for the establishment, exercise or defense of legal claims, you have the right to request restriction of processing of your personal data instead of erasure.
- If you have objected to processing pursuant to Article 21(1) GDPR, a balancing of interests between your interests and ours must be carried out. Until it is determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data – apart from being stored – may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
SSL or TLS encryption
This site uses SSL/TLS encryption for security reasons and to protect the transmission of confidential information, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the lock symbol in your browser's address bar.
When SSL or TLS encryption is enabled, the data you send to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after concluding a paid contract, you are obligated to provide us with your payment details (e.g., account number for direct debit), this data is required for payment processing.
Payments via common payment methods (Visa/MasterCard, direct debit) are processed exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the padlock symbol in your browser's address bar.
With encrypted communication, your payment details that you transmit to us cannot be read by third parties.
Objection to advertising emails
The use of contact details published as part of the legal notice for sending unsolicited advertising and informational materials is hereby prohibited. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising, such as spam emails.
4. Data collection on this website
Cookies
Our website uses so-called "cookies." Cookies are small data packets and do not harm your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted after you leave our website. Persistent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).
Cookies serve various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to analyze user behavior or for advertising purposes.
Cookies that are necessary for carrying out electronic communication, for providing certain functions you have requested (e.g., for the shopping cart function), or for optimizing the website (e.g., cookies for measuring website traffic) (necessary cookies) are stored on the basis of Article 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically flawless and optimized provision of its services. If consent to the storage of cookies and similar recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Article 6(1)(a) GDPR and Section 25(1) TDDDG); this consent can be revoked at any time.
You can configure your browser to notify you when cookies are set and to allow cookies only in individual cases, to accept cookies in certain cases or to generally reject them, and to automatically delete cookies when you close your browser. Disabling cookies may limit the functionality of this website.
If further cookies and services are used on this website, you can find this information in this privacy policy.
Consent with Borlabs Cookie
Our website uses Borlabs Cookie's consent technology to obtain your consent to the storage of certain cookies in your browser or the use of certain technologies, and to document this in accordance with data protection regulations. The provider of this technology is Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg (hereinafter referred to as Borlabs).
When you visit our website, a Borlabs cookie is stored in your browser, which saves your consent preferences or any revocations of consent. This data is not shared with the provider of Borlabs Cookie.
The collected data will be stored until you request its deletion, delete the Borlabs Cookie yourself, or the purpose for data storage no longer applies. Mandatory legal retention periods remain unaffected. Details on Borlabs Cookie's data processing can be found at [link to Borlabs Cookie policy]. https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
The Borlabs Cookie Consent technology is used to obtain the legally required consent for the use of cookies. The legal basis for this is Article 6(1)(c) GDPR.
Server log files
The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This information includes:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of server request
- IP address
This data will not be combined with other data sources.
This data is collected on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in the technically flawless presentation and optimization of its website – for this purpose, the server log files must be recorded.
Contact form
If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provided, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not share this data without your consent.
The processing of this data is based on Article 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for taking steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), if such consent has been obtained; you may withdraw your consent at any time.
The data you enter in the contact form will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions – in particular, retention periods – remain unaffected.
Use of AI on the website
We use AI-powered services and/or applications on our website.
We use artificial intelligence (AI) on our website as follows:
We use AI-based features on our website. These serve to efficiently process inquiries and optimize our customer communication.
AI-supported systems can, in particular, take on the following tasks:
Automatic analysis of contact requests
Identification of concerns and thematic assignment
Support in formulating answers
Optimization of internal service processes
The processing is carried out exclusively for the purpose of handling your request or improving our service offering.
Purely automated decision-making within the meaning of Article 22 GDPR does not take place.
If external technical service providers are used to provide or operate the AI systems, processing is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR. This may require that entered content, such as form data or messages, be transmitted to the respective service provider.
Further information on the specific providers used, the type of data processed, the legal basis and the storage period can be found in the relevant sections of this privacy policy.
When you interact with or come into contact with elements on our website that use artificial intelligence (e.g., chatbot), your input, including metadata, will be processed to generate a suitable answer or reaction.
The use of these AI-powered functions is based on Article 6(1)(f) GDPR. We have a legitimate interest in using modern technologies on our website to improve our services and to identify new opportunities arising from our interactions with our customers. If consent is required, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time.
Further information on the data processing of this tool or service can be found in the relevant section of this privacy policy.
Use of artificial intelligence (AI) to answer customer inquiries
We use AI-powered software to process and respond to customer inquiries. Our AI analyzes the content of your message to generate a suitable response or suggested answer, either autonomously or partially autonomously. In this context, our AI processes all the content of your message, including names, email addresses, communication details, and technical information (e.g., IP addresses, device information).
The use of the AI software employed is based on Article 6(1)(f) GDPR. We have a legitimate interest in the most efficient possible customer communication using modern technical solutions.
We use the following AI applications:
ChatGPT
We use ChatGPT for our customer communication. The provider is OpenAI, 3180 18th St, San Francisco, CA 94110, USA., https://openai.com. Therefore, when you contact us, your requests, including metadata, may be transferred to ChatGPT's servers and processed there to generate a suitable response.
We have configured ChatGPT so that the data we forward to ChatGPT is not used to train the ChatGPT algorithm.
You can find more information here: https://openai.com/policies/privacy-policy.
Inquiries via email, telephone or fax
When you contact us by email, telephone, or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of handling your request. We will not share this data without your consent.
The processing of this data is based on Article 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for taking steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), if such consent has been obtained; you may withdraw your consent at any time.
The data you send us via contact requests will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions – in particular, statutory retention periods – remain unaffected.
Communication via WhatsApp
We use the instant messaging service WhatsApp, among other methods, to communicate with our customers and other third parties. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Communication takes place via end-to-end encryption (peer-to-peer), which prevents WhatsApp or other third parties from accessing the content of the communication. However, WhatsApp does have access to metadata generated during the communication process (e.g., sender, recipient, and time). We would also like to point out that, according to WhatsApp, it shares its users' personal data with its US-based parent company, Meta. Further details on data processing can be found in WhatsApp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy.
The use of WhatsApp is based on our legitimate interest in communicating with customers, prospective customers, and other business and contractual partners as quickly and effectively as possible (Art. 6 para. 1 lit. f GDPR). If corresponding consent has been requested, data processing is carried out exclusively on the basis of this consent; this consent can be revoked at any time with effect for the future.
The content of communications exchanged between you and us on WhatsApp will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions – in particular, retention periods – remain unaffected.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/7735.
Registration on this website
You can register on this website to use additional features. We will only use the data you provide for the purpose of providing the specific offer or service for which you registered. All required information requested during registration must be provided in full. Otherwise, we will reject your registration.
For important changes, such as changes to the scope of services or technically necessary changes, we will use the email address you provided during registration to inform you.
The data entered during registration is processed for the purpose of carrying out the user relationship established by the registration and, if applicable, for initiating further contracts (Art. 6 para. 1 lit. b GDPR).
The data collected during registration will be stored by us for as long as you are registered on this website and will then be deleted. Statutory retention periods remain unaffected.
Registration with Google
Instead of registering directly on this website, you can register with Google. The provider of this service is Google Ireland Limited („Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
To register with Google, you only need to enter your Google username and password. Google will identify you and confirm your identity to our website.
If you sign in with Google, we may be able to use certain information from your account to complete your profile with us. You decide which information this is and what information is shared within your Google security settings, which you can find here: https://myaccount.google.com/security and https://myaccount.google.com/permissions.
The data processing associated with Google registration is based on our legitimate interest in providing our users with the simplest possible registration process (Art. 6 para. 1 lit. f GDPR). Since the use of the registration function is voluntary and users can decide for themselves on the respective access options, no overriding rights of the data subjects are apparent.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
ProvenExpert
We have integrated ProvenExpert rating seals on this website. The provider is Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin., https://www.provenexpert.com.
The ProvenExpert seal allows us to display customer reviews submitted to ProvenExpert about our company on our website as a seal. When you visit our website, a connection is established with ProvenExpert, allowing them to recognize that you have visited our site. ProvenExpert also uses your language settings to display the seal in your chosen language.
The use of ProvenExpert is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in presenting customer reviews in the most transparent way possible. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
5. Social Media
Social media elements with Shariff
This website uses elements from social media (e.g. Facebook, X, Instagram, Pinterest, XING, LinkedIn, Tumblr).
You can usually recognize the social media elements by their respective social media logos. To ensure data protection on this website, we only use these elements in conjunction with the so-called "Shariff" solution. This application prevents the social media elements integrated on this website from transmitting your personal data to the respective provider as soon as you visit the page.
Only when you activate the respective social media element by clicking the corresponding button will a direct connection to the provider's server be established (consent). Once you activate the social media element, the respective provider receives the information that you have visited this website with your IP address. If you are simultaneously logged into your respective social media account (e.g., Facebook), the provider can associate your visit to this website with your user account.
Activating the plugin constitutes consent within the meaning of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. You can revoke this consent at any time with effect for the future.
This service is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Article 6(1)(c) GDPR.
This website integrates elements of the social network Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.
An overview of Facebook's social media elements can be found here: https://developers.facebook.com/docs/plugins/?locale=de_DE.
When the social media element is active, a direct connection is established between your device and the Facebook server. Facebook then receives the information that you have visited this website with your IP address. If you click the Facebook "Like" button while logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to associate your visit to this website with your user account. Please note that as the provider of this website, we have no knowledge of the content of the transmitted data or its use by Facebook. You can find further information in Facebook's privacy policy at: https://de-de.facebook.com/privacy/explanation.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
To the extent that personal data is collected on our website and forwarded to Facebook using the tool described here, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Dublin, D04 X2K5, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook. The subsequent processing by Facebook is not part of this joint responsibility. Our joint obligations are set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for ensuring its data protection-compliant implementation on our website. Facebook is responsible for the data security of its products. You can assert your data subject rights (e.g., requests for access) regarding data processed by Facebook directly with Facebook. If you assert your data subject rights with us, we are obligated to forward them to Facebook.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
X (formerly Twitter)
This website integrates features of the service X (formerly Twitter). These features are offered by the parent company X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. For data processing of individuals residing outside the USA, the branch Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, is responsible.
When the social media element is active, a direct connection is established between your device and the X server. X (formerly Twitter) then receives information about your visit to this website. By using X (formerly Twitter) and the "Retweet" or "Repost" function, the websites you visit are linked to your X (formerly Twitter) account and made public to other users. Please note that as the website provider, we have no knowledge of the content of the transmitted data or how X (formerly Twitter) uses it. Further information can be found in X (formerly Twitter)'s privacy policy at: https://x.com/de/privacy.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://gdpr.x.com/en/controller-to-controller-transfers.html.
You can manage your privacy settings at X (formerly Twitter) in your account settings under https://x.com/settings/account change.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/2710.
This website integrates features of the Instagram service. These features are offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and the Instagram server. Instagram then receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. Please note that as the provider of this website, we have no knowledge of the content of the transmitted data or its use by Instagram.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
To the extent that personal data is collected on our website using the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Dublin, D04 X2K5, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook or Instagram. The subsequent processing by Facebook or Instagram is not part of this joint responsibility. Our joint obligations are set out in a joint processing agreement. You can find the text of the agreement here: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook or Instagram tool and for ensuring the tool's data protection-compliant implementation on our website. Facebook is responsible for the data security of its products. You can assert your data subject rights (e.g., requests for access) regarding data processed by Facebook or Instagram directly with Facebook. If you assert your data subject rights with us, we are obligated to forward them to Facebook.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381.
You can find more information about this in Instagram's privacy policy: https://privacycenter.instagram.com/policy/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
This website uses elements of the social network Pinterest, which is operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
When you visit a page containing such an element, your browser establishes a direct connection to Pinterest's servers. This social media element transmits log data to Pinterest's server in the USA. This log data may include your IP address, the address of the websites you visit that also contain Pinterest features, your browser type and settings, the date and time of your request, your use of Pinterest, and cookies.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
For more information about the purpose, scope and further processing and use of data by Pinterest, as well as your related rights and options for protecting your privacy, please see Pinterest's privacy policy: https://policy.pinterest.com/de/privacy-policy.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4203.
6. Analytics tools and advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is a tool that allows us to integrate tracking and analytics tools and other technologies into our website. The Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It serves solely to manage and deploy the tools integrated through it. However, the Google Tag Manager does collect your IP address, which may also be transferred to Google's parent company in the United States.
The use of Google Tag Manager is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in the quick and easy integration and management of various tools on their website. If corresponding consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics allows website operators to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, time spent on the site, operating systems used, and the user's origin. This data is aggregated into a user ID and assigned to the respective device of the website visitor.
Furthermore, we can use Google Analytics to record your mouse movements, scrolling, and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data and employs machine learning technologies for data analysis.
Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to and stored on a Google server in the USA.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
IP anonymization
Google Analytics IP anonymization is activated. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
For more information on how Google Analytics handles user data, please see Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Google Signals
We use Google Signals. When you visit our website, Google Analytics collects, among other things, your location, search history, YouTube history, and demographic data (visitor data). This data can be used for personalized advertising with the help of Google Signals. If you have a Google account, the visitor data from Google Signals will be linked to your Google account and used for personalized advertising messages. The data is also used to create anonymized statistics on the user behavior of our users.
Google Analytics E-Commerce Measurement
This website uses the "E-commerce Measurement" feature of Google Analytics. E-commerce measurement allows the website operator to analyze the purchasing behavior of website visitors to improve their online marketing campaigns. Information such as orders placed, average order values, shipping costs, and the time from viewing to purchasing a product are collected. This data can be aggregated by Google under a transaction ID that is assigned to the respective user or their device.
Microsoft Advertising
The website operator uses Microsoft Advertising. Microsoft Advertising is an online advertising program of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.
Microsoft Advertising allows us to display ads in the Bing search engine or on third-party websites when users enter specific search terms into Bing (keyword targeting). Furthermore, targeted ads can be displayed based on user data held by Microsoft (e.g., location data and interests) (audience targeting). As website operators, we can quantitatively evaluate this data by, for example, analyzing which search terms led to the display of our ads and how many ads resulted in clicks.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://learn.microsoft.com/de-de/compliance/regulatory/offering-eu-model-clauses.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474.
Hotjar
This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (Website: https://www.hotjar.com).
Hotjar is a tool for analyzing your user behavior on this website. With Hotjar, we can record your mouse movements, scrolling, and clicks, among other things. Hotjar can also determine how long you hover your mouse over a specific area. From this information, Hotjar creates heatmaps that show which areas of the website are most frequently viewed by visitors.
Furthermore, we can determine how long you stayed on a page and when you left it. We can also determine at which point you abandoned your entries in a contact form (so-called conversion funnels).
Furthermore, Hotjar allows you to collect direct feedback from website visitors. This feature helps improve the website operator's online offerings.
Hotjar uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting).
Where consent has been obtained, the aforementioned service is used exclusively on the basis of Article 6(1)(a) GDPR and Section 25 TDDDG. This consent can be revoked at any time. Where no consent has been obtained, this service is used on the basis of Article 6(1)(f) GDPR; the website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.
Disabling Hotjar
If you wish to disable data collection by Hotjar, click on the following link and follow the instructions there: https://www.hotjar.com/policies/do-not-track/
Please note that Hotjar must be deactivated separately for each browser and each device.
For more information about Hotjar and the data collected, please see Hotjar's privacy policy at the following link: https://www.hotjar.com/privacy
WP Statistics
This website uses the analytics tool WP Statistics to statistically evaluate visitor access. The provider is Veronalabs, Tatari 64, 10134, Tallinn, Estonia (https://veronalabs.com).
WP Statistics allows us to analyze the use of our website. WP Statistics collects, among other things, log files (IP address, referrer, browser used, user origin, search engine used) and actions taken by website visitors on the site (e.g., clicks and views).
The data collected with WP Statistics is stored exclusively on our own server.
The use of this analytics tool is based on Article 6(1)(f) GDPR. We have a legitimate interest in the anonymized analysis of user behavior in order to optimize both our website and our advertising. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads allows us to display advertisements in the Google search engine or on third-party websites when users enter specific search terms into Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available to Google (e.g., location data and interests) (audience targeting). As website operators, we can quantitatively evaluate this data by, for example, analyzing which search terms led to the display of our advertisements and how many advertisements resulted in clicks.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google AdSense
This website uses Google AdSense, a service for integrating advertisements. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google AdSense, we can display targeted advertisements from third-party companies on our website. The content of these advertisements is based on your interests, which Google determines based on your previous browsing behavior. Furthermore, contextual information such as your location, the content of the website you visited, and the Google search terms you entered are also taken into account when selecting the most relevant advertisement.
Google AdSense uses cookies, web beacons (invisible graphics) and similar tracking technologies. This allows information such as visitor traffic on these pages to be analyzed.
The information collected by Google AdSense about your use of this website (including your IP address) and the delivery of advertising formats is transmitted to and stored on a Google server in the USA. This information may be shared by Google with its partners. However, Google will not combine your IP address with other data stored by Google.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Ads Remarketing
This website uses the features of Google Ads Remarketing. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
With Google Ads Remarketing, we can assign people who interact with our online offering to specific target groups in order to subsequently display interest-based advertising to them in the Google advertising network (remarketing or retargeting).
Furthermore, advertising audiences created with Google Ads Remarketing can be linked to Google's cross-device features. This allows interest-based, personalized advertising messages, tailored to you based on your previous usage and browsing behavior on one device (e.g., mobile phone), to also be displayed on another of your devices (e.g., tablet or PC).
If you have a Google account, you can opt out of personalized advertising via the following link: https://adssettings.google.com/anonymous?hl=de.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Further information and the data protection regulations can be found in Google's privacy policy at: https://policies.google.com/technologies/ads?hl=de.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Target group formation with customer matching
To create target audiences, we use, among other things, the customer matching feature of Google Ads Remarketing. In this process, we transfer certain customer data (e.g., email addresses) from our customer lists to Google. If the customers in question are Google users and logged into their Google account, they will be shown relevant advertising messages within the Google network (e.g., on YouTube, Gmail, or in the search engine).
Google Conversion Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google conversion tracking, Google and we can recognize whether a user has performed certain actions. For example, we can analyze which buttons on our website are clicked most frequently and which products are viewed or purchased most often. This information is used to create conversion statistics. We learn the total number of users who clicked on our ads and what actions they performed. We do not receive any information that allows us to personally identify the user. Google itself uses cookies or similar recognition technologies for identification.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
For more information about Google Conversion Tracking, please see Google's privacy policy: https://policies.google.com/privacy?hl=de.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Meta-Pixel (formerly Facebook Pixel)
This website uses the Meta pixel for conversion tracking. The provider of this service is Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland. According to Meta, the collected data is also transferred to the USA and other third countries.
This allows the behavior of website visitors to be tracked after they have been redirected to the provider's website by clicking on a meta ad. This enables the effectiveness of meta ads to be evaluated for statistical and market research purposes and future advertising campaigns to be optimized.
The data collected is anonymous for us as the operators of this website; we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Meta, so a connection to the respective user profile on Facebook or Instagram is possible, and Meta uses the data for its own advertising purposes, in accordance with the Meta Data Usage Policy (https://de-de.facebook.com/about/privacy/Meta can use this data. This allows Meta to display advertisements on Facebook or Instagram pages and other advertising channels. We, as the page operator, have no control over this use of data.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
To the extent that personal data is collected on our website using the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Dublin, D04 X2K5, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transfer to Meta. The processing carried out by Meta after the transfer is not part of the joint responsibility. Our joint obligations are set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Meta tool and for ensuring its data protection-compliant implementation on our website. Meta is responsible for the data security of its products. You can assert your data subject rights (e.g., requests for information) regarding data processed by Facebook or Instagram directly with Meta. If you assert your data subject rights with us, we are obligated to forward them to Meta.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
You can find further information on protecting your privacy in Meta's privacy policy: https://de-de.facebook.com/about/privacy/.
You can also use the "Custom Audiences" remarketing feature in the ad settings section under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen deactivate. You must be logged into Facebook to do this.
If you do not have a Facebook or Instagram account, you can disable interest-based advertising from Meta on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
Meta Conversion API
We have integrated the Meta Conversion API into this website. The provider of this service is Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland. According to Meta, the collected data is also transferred to the USA and other third countries.
The Meta Conversion API allows us to capture the interactions of website visitors with our website and pass them on to Meta in order to improve advertising performance on Facebook and Instagram.
For this purpose, the following data is collected: the time of access, the website accessed, your IP address and user agent, and possibly other specific data (e.g., purchased products, shopping cart value, and currency). A complete overview of the data collected can be found here: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
To the extent that personal data is collected on our website using the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Dublin, D04 X2K5, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transfer to Meta. The processing carried out by Meta after the transfer is not part of the joint responsibility. Our joint obligations are set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Meta tool and for ensuring its data protection-compliant implementation on our website. Meta is responsible for the data security of its products. You can assert your data subject rights (e.g., requests for information) regarding data processed by Facebook or Instagram directly with Meta. If you assert your data subject rights with us, we are obligated to forward them to Meta.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
You can find further information on protecting your privacy in Meta's privacy policy: https://de-de.facebook.com/about/privacy/.
You can also use the "Custom Audiences" remarketing feature in the ad settings section under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen deactivate. You must be logged into Facebook to do this.
If you do not have a Facebook or Instagram account, you can disable interest-based advertising from Meta on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
Meta Custom Audiences
We use Meta Custom Audiences. The provider of this service is Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland.
When you visit or use our websites and apps, take advantage of our free or paid services, submit data to us, or interact with our company's Facebook or Instagram content, we collect your personal data. If you give us your consent to use Meta Custom Audiences, we will transfer this data to Meta, which can then use it to show you relevant advertising. Furthermore, your data can be used to define target groups (Lookalike Audiences).
Meta processes this data as our data processor. Details can be found in Meta's terms of service. https://www.facebook.com/legal/terms/customaudience.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
TikTok Pixel
We have integrated the TikTok pixel on this website. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter referred to as TikTok).
Using the TikTok Pixel, we can display interest-based advertising on TikTok (TikTok Ads) to website visitors who have viewed our offers. At the same time, the TikTok Pixel allows us to determine the effectiveness of our advertising on TikTok. This enables us to evaluate the effectiveness of TikTok ads for statistical and market research purposes and optimize future advertising campaigns. Various usage data is processed, such as IP address, page views, time spent on the site, operating system used, user origin, information about the ad a person clicked on on TikTok, or an event that was triggered (timestamp). This data is aggregated into a user ID and assigned to the respective device of the website visitor.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.
Data transfers to third countries are based on the EU Commission's standard contractual clauses. Details can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/de-DE and https://ads.tiktok.com/i18n/official/policy/controller-to-controller.
LinkedIn Insight Tag
This website uses the LinkedIn Insight Tag. The provider of this service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Data processing by LinkedIn Insight Tag
Using the LinkedIn Insight Tag, we receive information about visitors to our website. If a website visitor is registered with LinkedIn, we can analyze their professional data (e.g., career level, company size, country, location, industry, and job title) and thus better tailor our site to the respective target groups. Furthermore, LinkedIn Insight Tags allow us to measure whether visitors to our website make a purchase or take another action (conversion tracking). Conversion tracking can also be performed across devices (e.g., from PC to tablet). LinkedIn Insight Tag also offers a retargeting function, which allows us to display targeted advertising to visitors of our website outside of our site. According to LinkedIn, the recipient of the advertisement is not identified.
LinkedIn itself also collects so-called log files (URL, referrer URL, IP address, device and browser characteristics, and time of access). The IP addresses are shortened or (if used to reach LinkedIn members across devices) hashed (pseudonymized). The direct identifiers of LinkedIn members are deleted by LinkedIn after seven days. The remaining pseudonymized data is then deleted within 180 days.
The data collected by LinkedIn cannot be linked to specific individuals by us as website operators. LinkedIn will store the collected personal data of website visitors on its servers in the USA and use it for its own advertising purposes. For details, please see LinkedIn's privacy policy at [link to LinkedIn privacy policy]. https://www.linkedin.com/legal/privacy-policy#choices-oblig.
Legal basis
Where consent has been obtained, the aforementioned service is used exclusively on the basis of Article 6(1)(a) GDPR and Section 25 TDDDG. This consent can be revoked at any time. Where no consent has been obtained, this service is used on the basis of Article 6(1)(f) GDPR; the website operator has a legitimate interest in effective advertising measures, including those on social media.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5448.
Objection to the use of LinkedIn Insight Tag
You can object to the analysis of user behavior and targeted advertising by LinkedIn via the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Furthermore, LinkedIn members can control the use of their personal data for advertising purposes in their account settings. To prevent LinkedIn from linking data collected on our website with your LinkedIn account, you must log out of your LinkedIn account before visiting our website.
Pinterest tag
We have integrated the Pinterest tag on this website. The provider is Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
The Pinterest tag is used to track certain actions you perform on our website. This data can then be used to display interest-based advertising to you on our website or on other sites within the Pinterest tag advertising network.
For this purpose, the Pinterest tag collects, among other things, a tag ID, your location, and the referrer URL. Furthermore, action-specific data such as order value, order quantity, order number, category of purchased items, and video views can be collected.
The Pinterest tag uses technologies that enable cross-site user recognition for the analysis of user behavior (e.g., cookies or device fingerprinting).
Where consent has been obtained, the aforementioned service is used exclusively on the basis of Article 6(1)(a) GDPR and Section 25 TDDDG. This consent can be revoked at any time. Where no consent has been obtained, this service is used on the basis of Article 6(1)(f) GDPR; the website operator has a legitimate interest in the most effective marketing measures possible.
Pinterest is a global company, so data may be transferred to the USA. According to Pinterest, this data transfer is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://policy.pinterest.com/de/privacy-policy.
You can find more information about the Pinterest tag here: https://help.pinterest.com/de/business/article/track-conversions-with-pinterest-tag.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4203.
7. Newsletter and postal advertising
Newsletter data
If you wish to subscribe to the newsletter offered on this website, we require your email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use newsletter service providers, described below, to process the newsletters.
Mailchimp with performance tracking disabled
This website uses Mailchimp for sending newsletters. The provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
Mailchimp is a service that can be used, among other things, to organize the sending of newsletters. If you enter data for the purpose of subscribing to the newsletter (e.g., email address), this data will be stored on Mailchimp's servers in the USA. We have deactivated performance tracking in Mailchimp, so Mailchimp will not analyze your behavior when you open our newsletters.
If you do not want your data transferred to Mailchimp, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter email.
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time by unsubscribing from the newsletter. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
The data you provided for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be deleted from the newsletter distribution list. Data stored for other purposes will remain unaffected.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://mailchimp.com/eu-us-data-transfer-statement/ and https://mailchimp.com/legal/data-processing-addendum/#Annex_C_-_Standard_Contractual_Clauses.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
For more information, please see Mailchimp's privacy policy at: https://mailchimp.com/legal/terms/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/7693.
Mailjet
This website uses Mailjet for sending newsletters. The provider is Mailjet Technologies Inc., 112 E Pecan Sr. #1135, San Antonio, Texas 78205, USA.
Mailjet is a service that can be used, among other things, to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on Mailjet's servers.
Data analysis by Mailjet
Mailjet allows us to analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links, if any, were clicked. This way, we can determine, among other things, which links were clicked most frequently.
Furthermore, we can track whether certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see if you made a purchase after clicking on the newsletter.
Mailjet also allows us to segment ("cluster") newsletter recipients based on various categories. For example, recipients can be segmented by age, gender, or location. This allows us to better tailor the newsletters to specific target groups. If you do not want Mailjet to analyze your data, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message.
Detailed information about Mailjet's features can be found at the following link: https://www.mailjet.de/funktion/.
Mailjet's privacy policy can be found at: https://www.mailjet.de/sicherheit-datenschutz/.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.mailjet.de/av-vertrag/.
Storage duration
The data you provided for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be deleted from the newsletter distribution list. Data stored for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
ActiveCampaign
This website uses ActiveCampaign for sending newsletters. The provider is ActiveCampaign, Inc., 1 N Dearborn, 5th Floor, Chicago, Illinois 60602, USA.
ActiveCampaign is a service that can be used, among other things, to organize and analyze the distribution of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on ActiveCampaign's servers in the USA.
Data analysis by ActiveCampaign
ActiveCampaign allows us to analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links, if any, were clicked. This way, we can determine, among other things, which links were clicked most frequently.
Furthermore, we can see whether certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see whether you made a purchase after clicking on the newsletter.
ActiveCampaign also allows us to segment (“cluster”) newsletter recipients based on various categories. For example, recipients can be segmented by age, gender, or location. This allows us to better tailor the newsletters to specific target groups. If you do not want ActiveCampaign to analyze your data, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message.
Detailed information about ActiveCampaign's features can be found at the following link: https://www.activecampaign.com/email-marketing.
ActiveCampaign's privacy policy can be found at: https://www.activecampaign.com/privacy-policy.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.activecampaign.com/legal/newscc and https://www.activecampaign.com/de/legal/gdpr-updates/privacy-shield.
Storage duration
The data you provided for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be deleted from the newsletter distribution list. Data stored for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4495.
CleverReach
This website uses CleverReach for sending newsletters. The provider is CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany (hereinafter "CleverReach"). CleverReach is a service that allows us to organize and analyze newsletter distribution. The data you enter for newsletter subscription (e.g., email address) is stored on CleverReach's servers in Germany and Ireland.
Our newsletters, sent via CleverReach, allow us to analyze the behavior of newsletter recipients. This includes analyzing how many recipients opened the newsletter and how often each link within the newsletter was clicked. Using conversion tracking, we can also analyze whether a predefined action (e.g., purchasing a product on this website) occurred after clicking a link in the newsletter. Further information about data analysis through CleverReach newsletters can be found here: https://www.cleverreach.com/de/funktionen/reporting-und-tracking/.
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time by unsubscribing from the newsletter. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
If you do not want your data analyzed by CleverReach, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter email.
The data you provided for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be deleted from the newsletter distribution list. Data stored for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
For more information, please refer to CleverReach's privacy policy at: https://www.cleverreach.com/de/datenschutz/.
Rapidmail
This website uses Rapidmail for sending newsletters. The provider is rapidmail GmbH, Augustinerplatz 2, 79098 Freiburg i.Br., Germany.
Rapidmail is a service that, among other things, allows you to organize and analyze the distribution of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on Rapidmail's servers in Germany.
Data analysis by Rapidmail
For analysis purposes, emails sent via Rapidmail contain a so-called "tracking pixel" that connects to Rapidmail's servers when the email is opened. This allows Rapidmail to determine whether a newsletter message has been opened.
Furthermore, we can use Rapidmail to determine if and which links in the newsletter are clicked. All links in the email are so-called tracking links, which allow us to count your clicks. If you do not want Rapidmail to analyze your activity, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter.
For more information about Rapidmail's analysis functions, please see the following link: https://de.rapidmail.wiki/kategorien/statistiken/.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
Storage duration
The data you provided for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be deleted from the newsletter distribution list. Data stored for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
For more information, please refer to Rapidmail's data security guidelines at: https://www.rapidmail.de/datensicherheit.
Brevo
This website uses Brevo for sending newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
Brevo is a service that, among other things, allows you to organize and analyze the distribution of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on the servers of Sendinblue GmbH in Germany.
Data analysis by Brevo
With the help of Brevo, we can analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links, if any, were clicked. This allows us to determine, among other things, which links were clicked most frequently.
Furthermore, we can track whether certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see if you made a purchase after clicking on the newsletter.
Brevo also allows us to segment ("cluster") newsletter recipients based on various categories. For example, recipients can be segmented by age, gender, or location. This allows us to better tailor newsletters to specific target groups.
If you do not want your data analyzed by Brevo, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter email.
Detailed information about Brevo's functions can be found at the following link: https://www.brevo.com/de/newsletter-software/.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
Storage duration
The data you provided for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be deleted from the newsletter distribution list. Data stored for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
For more information, please see Brevo's privacy policy at: https://www.brevo.com/de/datenschutz-uebersicht/ as well as https://www.brevo.com/de/legal/privacypolicy/.
GetResponse
This website uses GetResponse for sending newsletters. The provider is GetResponse Sp. z o.o., with its registered office in Gdansk, Poland, ul. Arkonska 6, A3, 80-387 Gdansk, website: https://www.getresponse.de (hereinafter referred to as „GetResponse“).
GetResponse is a service that, among other things, allows you to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on GetResponse's servers. GetResponse uses servers in the USA, meaning your newsletter data may be transferred to the USA. The USA is considered a non-safe third country under data protection law.
Data analysis using GetResponse
Our newsletters, sent via GetResponse, allow us to analyze the behavior of newsletter recipients. This includes analyzing how many recipients opened the newsletter and how often each link within the newsletter was clicked. Using conversion tracking, we can also determine whether a predefined action (e.g., purchasing a product, sharing information on social media, unsubscribing) occurred after clicking links in the newsletter. Furthermore, we can track when a newsletter was opened. This enables us to deliver newsletters when the recipient is likely to be most active. The recipient's time zone can also be taken into account. GetResponse also allows us to segment newsletter recipients into groups based on their interests. This way, we can provide our newsletter recipients with content that is as relevant to their interests as possible.
For more information about GetResponse's features, please visit: https://www.getresponse.de/email-marketing/funktionen/e-mail-marketing.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.getresponse.com/de/legal/standard-contractual-clauses.
Storage duration
The data you provided for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be deleted from the newsletter distribution list. Data stored for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
For more information, please see GetResponse's privacy policy at: https://www.getresponse.de/email-marketing/legal/datenschutz.html.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4993.
MailerLite
This website uses MailerLite for sending newsletters. The provider is MailerLite Limited, “MailerLite”, 38 Mount Street Upper, Dublin 2, D02PR89 Ireland (hereinafter „MailerLite“).
MailerLite is a service that can be used, among other things, to organize and analyze the distribution of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on MailerLite's servers.
If you do not want your data analyzed by MailerLite, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message.
Data analysis by MailerLite
MailerLite allows us to analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links, if any, were clicked. This way, we can determine, among other things, which links were clicked most frequently.
Furthermore, we can track whether certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see if you made a purchase after clicking on the newsletter.
MailerLite also allows us to segment („cluster”) newsletter recipients based on various categories. For example, recipients can be segmented by age, gender, or location. This allows us to better tailor newsletters to specific target groups.
Detailed information about MailerLite's features can be found at the following link: https://www.mailerlite.com/features.
MailerLite's privacy policy can be found at: https://www.mailerlite.com/legal/privacy-policy.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time for the future.
Storage duration
The data you provide for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be removed from the newsletter distribution list or deleted once the purpose for which it was collected no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion, based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Data stored by us for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
Zoho Campaigns
This website uses Zoho Campaigns for sending newsletters. The provider is Zoho Corporation Pvt. Ltd., Estancia IT Park, Plot No. 140 151, GST Road, Vallancherry Village, Chengalpattu Taluk, Kanchipuram District 603 202, India (hereinafter referred to as "Zoho Campaigns").
Zoho Campaigns is a service that can be used to organize and analyze newsletter distribution, among other things. The data you enter for the purpose of subscribing to the newsletter is stored on Zoho Campaigns' servers.
Data analysis by Zoho Campaigns
Zoho Campaigns allows us to analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links, if any, were clicked. This way, we can determine, among other things, which links were clicked most frequently.
Furthermore, we can track whether certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see if you made a purchase after clicking on the newsletter. If you do not want Zoho Campaigns to analyze your data, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message. Zoho Campaigns also allows us to segment ("cluster") newsletter recipients based on various categories. For example, recipients can be segmented by age, gender, or location. This allows us to better tailor the newsletters to specific target groups. If you do not want Zoho Campaigns to analyze your data, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message.
Data localization
Zoho Campaigns uses data localization. Customer data from the European Union is stored and processed exclusively in data centers within Europe. The data region is assigned automatically based on the domain chosen during registration and the IP address. When logging in via campaigns.zoho.eu, the European data center is assigned by default. Further information about data localization at Zoho and the data centers used can be found at [link to Zoho's data localization policy]. https://www.zoho.com/know-your-datacenter.html and https://www.zoho.com/campaigns/help/developers/data-centers.html.
Detailed information about the features of Zoho Campaigns can be found at the following link: https://www.zoho.com/campaigns/features.html.
Zoho Campaigns' privacy policy can be found at: https://www.zoho.com/privacy.html and https://www.zoho.com/gdpr.html.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time for the future.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.zoho.com/privacy.html.
Storage duration
The data you provide for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe, your data will be removed from the newsletter distribution list or deleted once the purpose for which it was collected no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion, based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Data stored by us for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
MailPoet
This website uses MailPoet for sending newsletters. The provider is Aut O'Mattic A8C Ireland Ltd., Business Centre, No.1 Lower Mayor Street, International Financial Services Centre, Dublin 1, Ireland, whose parent company is based in the USA (hereinafter referred to as MailPoet).
MailPoet is a service that, among other things, allows you to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on our servers but sent via MailPoet's servers, meaning MailPoet processes your newsletter-related data (MailPoet Sending Service). Details can be found here: https://account.mailpoet.com/.
Data analysis by MailPoet
MailPoet allows us to analyze our newsletter campaigns. For example, we can see whether a newsletter message was opened and which links, if any, were clicked. This way, we can determine, among other things, which links were clicked most frequently.
Furthermore, we can see whether certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see whether you made a purchase after clicking on the newsletter.
MailPoet also allows us to segment ("cluster") newsletter recipients based on various categories. For example, recipients can be segmented by age, gender, or location. This allows us to better tailor the newsletters to specific target groups. If you do not want MailPoet to analyze your data, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message.
Detailed information about MailPoet's features can be found at the following link: https://account.mailpoet.com/ and https://www.mailpoet.com/mailpoet-features/.
MailPoet's privacy policy can be found at: https://www.mailpoet.com/privacy-notice/.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw this consent at any time for the future.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://automattic.com/de/privacy/.
Storage duration
The data you provide for the purpose of subscribing to our newsletter will be stored by us until you unsubscribe. After you unsubscribe, your data will be removed from the newsletter distribution list or deleted when the purpose for which it was collected no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion, based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Data stored for other purposes will remain unaffected.
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to the storage of your data if your interests outweigh our legitimate interest.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/4709.
Newsletter distribution to existing customers
When you order goods or services from us and provide your email address, we may subsequently use this email address to send you newsletters, provided we inform you of this beforehand. In such a case, the newsletter will only contain direct advertising for our own similar goods or services. You can unsubscribe from this newsletter at any time. A corresponding link is included in every newsletter for this purpose. The legal basis for sending the newsletter in this case is Article 6(1)(f) GDPR in conjunction with Section 7(3) of the German Unfair Competition Act (UWG).
After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist to prevent future mailings to you. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to this storage if your interests outweigh our legitimate interest.
Direct advertising
We use your address for sending postal advertising (postal advertising) in compliance with all legal regulations.
The legal basis for this is our legitimate interest in direct marketing pursuant to Article 6(1)(f) in conjunction with Recital 47 of the GDPR. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR; this consent can be revoked at any time. More specific regulations may be communicated to you during data collection and take precedence over this regulation.
Your address will remain with us until the purpose for data processing no longer applies. If you submit a legitimate request for erasure or withdraw your consent to postal advertising, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will occur once these grounds cease to apply.
We use the following service provider for sending our direct mail campaigns:
If you submit your address to us via our website, we reserve the right to use this data to send you postal advertising, provided this is legally permissible.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in direct marketing of our own products and services.
For sending direct mail advertising, an external service provider may be used. In this case, your data will be processed exclusively within the framework of commissioned data processing in accordance with Article 28 GDPR. A corresponding data processing agreement will be concluded with the service provider, ensuring that your data is processed only according to our instructions and in compliance with applicable data protection regulations.
The specific service providers used and their full contact details will be added to this privacy policy as soon as they are determined.
You have the right to object to the use of your personal data for direct marketing purposes at any time. An informal notification to the contact address provided in the legal notice is sufficient. After receiving your objection, your data will no longer be used for advertising purposes.
8. Plugins and Tools
YouTube
This website embeds videos from YouTube. The website is operated by Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of our websites that includes embedded YouTube videos, a connection is established to YouTube's servers. This informs the YouTube server which of our pages you have visited.
Furthermore, YouTube may store various cookies on your device or use similar technologies for recognition (e.g., device fingerprinting). In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to compile video statistics, improve user-friendliness, and prevent fraud. The collected data is also processed within the Google advertising network.
If you are logged into your YouTube account, you are allowing YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account.
The use of YouTube is in our legitimate interest in presenting our online content in an appealing way. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be withdrawn at any time.
Further information on how user data is handled can be found in YouTube's privacy policy at: https://policies.google.com/privacy?hl=de.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Vimeo
This website uses plugins from the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.
When you visit one of our pages that includes a Vimeo video, a connection is established to Vimeo's servers. This informs the Vimeo server which of our pages you have visited. Vimeo also receives your IP address. This applies even if you are not logged into Vimeo or do not have a Vimeo account. The information collected by Vimeo is transmitted to Vimeo's servers in the USA.
If you are logged into your Vimeo account, you are allowing Vimeo to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your Vimeo account.
Vimeo uses cookies or similar recognition technologies (e.g. device fingerprinting) to recognize website visitors.
The use of Vimeo is in our legitimate interest in presenting our online content in an appealing way. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be withdrawn at any time.
Data transfers to the USA are based on the EU Commission's standard contractual clauses and, according to Vimeo, on "legitimate business interests." Details can be found here: https://vimeo.com/privacy.
Further information on how Vimeo handles user data can be found in their privacy policy at: https://vimeo.com/privacy.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5711.
Google Fonts
This website uses Google Fonts, provided by Google, for consistent font display. When you visit a page, your browser loads the necessary fonts into its browser cache to display text and fonts correctly.
For this purpose, the browser you are using must connect to Google's servers. This allows Google to know that this website was accessed via your IP address. The use of Google Fonts is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the uniform presentation of the typeface on their website. If corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
If your browser does not support Google Fonts, a standard font from your computer will be used.
You can find more information about Google Fonts at https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=de.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Adobe Fonts
This website uses web fonts from Adobe for the consistent display of certain fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe).
When you visit this website, your browser loads the necessary fonts directly from Adobe to display them correctly on your device. In doing so, your browser establishes a connection to Adobe's servers in the USA. This allows Adobe to know that this website was accessed via your IP address. According to Adobe, no cookies are stored when providing the fonts.
The data is stored and analyzed based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in the uniform presentation of the typeface on its website. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.adobe.com/de/privacy/eudatatransfers.html.
For more information about Adobe Fonts, please visit: https://www.adobe.com/de/privacy/policies/adobe-fonts.html.
Adobe's privacy policy can be found at: https://www.adobe.com/de/privacy/policy.html
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5660.
Font Awesome
This website uses Font Awesome for the consistent display of fonts and icons. The provider is Fonticons, Inc., 6 Porter Road Apartment 3R, Cambridge, Massachusetts, USA.
When you visit a page, your browser loads the necessary fonts into its cache to display text, fonts, and icons correctly. For this purpose, your browser must connect to Font Awesome's servers. This allows Font Awesome to know that this website was accessed via your IP address. The use of Font Awesome is based on Article 6(1)(f) GDPR. We have a legitimate interest in the consistent presentation of the typeface on our website. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be withdrawn at any time.
If your browser does not support Font Awesome, a standard font from your computer will be used.
Further information about Font Awesome can be found in Font Awesome's privacy policy at: https://fontawesome.com/privacy.
MyFonts
This website uses MyFonts. These are fonts that are loaded into your browser when you visit our website to ensure a consistent font display. The provider is Monotype Imaging Holdings Inc., 600 Unicorn Park Drive, Woburn, Massachusetts 01801, USA.
To verify compliance with the license terms and the number of monthly page views, MyFonts transfers your IP address, along with the URL of our website and our contract data, to its servers in the USA. According to Monotype, your IP address is anonymized immediately after the transfer, so that no personal identification is possible (anonymization).
For details, please refer to Monotype's privacy policy at https://www.monotype.com/de/rechtshinweise/datenschutzrichtlinie/datenschutzrichtlinie-zum-tracking-von-webschriften.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/6347.
Google Maps
This website uses the Google Maps service. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to embed maps on our website.
To use the functions of Google Maps, it is necessary to store your IP address. This information is generally transmitted to and stored on a Google server in the USA. The provider of this website has no influence on this data transfer. When Google Maps is activated, Google may use Google Fonts for the purpose of consistent font display. When you access Google Maps, your browser loads the required web fonts into its browser cache to display texts and fonts correctly.
The use of Google Maps is in our legitimate interest in presenting our online services in an appealing manner and ensuring the easy location of the places we indicate on the website. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be withdrawn at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
For more information on how user data is handled, please see Google's privacy policy: https://policies.google.com/privacy?hl=de.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
OpenStreetMap
We use the map service from OpenStreetMap (OSM).
We integrate map data from OpenStreetMap, hosted on the server of the OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The United Kingdom is considered a data protection-safe third country. This means that the UK has a level of data protection equivalent to that of the European Union. When using OpenStreetMap maps, a connection is established to the servers of the OpenStreetMap Foundation. This may involve the transmission of your IP address and other information about your activity on this website to the OSMF. OpenStreetMap may store cookies in your browser or use similar tracking technologies for this purpose.
The use of OpenStreetMap serves the purpose of presenting our online services in an appealing manner and ensuring the easy location of the places we indicate on the website. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be withdrawn at any time.
Google reCAPTCHA
We use „Google reCAPTCHA“ (hereinafter „reCAPTCHA“) on this website. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to verify whether data entry on this website (e.g., in a contact form) is done by a human or an automated program. To do this, reCAPTCHA analyzes the website visitor's behavior based on various characteristics. This analysis begins automatically as soon as the visitor enters the website. For the analysis, reCAPTCHA evaluates various pieces of information (e.g., IP address, the visitor's time spent on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analysis runs entirely in the background. Website visitors are not notified that an analysis is taking place.
The data is stored and analyzed based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its website from abusive automated access and spam. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be withdrawn at any time.
For more information about Google reCAPTCHA, please see the Google Privacy Policy and the Google Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Wordfence
We have integrated Wordfence into this website. The provider is Defiant Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter referred to as "Wordfence").
Wordfence protects our website from unwanted access or malicious cyberattacks. For this purpose, our website maintains a persistent connection to Wordfence's servers so that Wordfence can compare its databases with the access data on our website and block any unauthorized access.
The use of Wordfence is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its website from cyberattacks as effectively as possible. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.wordfence.com/help/general-data-protection-regulation/.
9. eCommerce and payment providers
Processing of customer and contract data
We collect, process, and use personal customer and contract data to establish, define the content of, and modify our contractual relationships. We collect, process, and use personal data relating to the use of this website (usage data) only to the extent necessary to enable the user to access the service or for billing purposes. The legal basis for this is Article 6(1)(b) GDPR.
The collected customer data will be deleted after completion of the order or termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected.
Data transfer during contract conclusion for online shops, retailers and shipping companies
When you order goods from us, we share your personal data with the transport company responsible for delivery and the payment service provider handling your payment. Only the data required by each service provider to fulfill their task will be shared. The legal basis for this is Article 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or for taking steps prior to entering into a contract. If you have given your consent in accordance with Article 6(1)(a) GDPR, we will share your email address with the transport company responsible for delivery so that they can inform you about the shipping status of your order via email; you can withdraw this consent at any time.
Data transfer upon conclusion of contracts for services and digital content
We only transfer personal data to third parties if this is necessary for the execution of the contract, for example to the credit institution commissioned with processing the payment.
Your data will not be transmitted further, or only if you have expressly consented to such transmission. Your data will not be shared with third parties without your express consent, for example for advertising purposes.
The legal basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.
Payment services
We integrate payment services from third-party companies on our website. When you make a purchase with us, your payment data (e.g., name, payment amount, bank account details, credit card number) is processed by the payment service provider for the purpose of payment processing. The respective terms and conditions and privacy policies of the respective providers apply to these transactions. The use of these payment service providers is based on Article 6(1)(b) GDPR (contractual necessity) and in the interest of ensuring the smoothest, most convenient, and most secure payment process possible (Article 6(1)(f) GDPR). Where your consent is requested for specific actions, Article 6(1)(a) GDPR serves as the legal basis for data processing; consent can be withdrawn at any time for the future.
We use the following payment services/payment providers on this website:
PayPal
The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as „PayPal“).
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
For details, please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Apple Pay
The payment service provider is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple's privacy policy can be found at: https://www.apple.com/legal/privacy/de-ww/.
Google Pay
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy policy can be found here: https://policies.google.com/privacy.
Stripe
The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter referred to as "Stripe").
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://stripe.com/de/privacy and https://stripe.com/de/guides/general-data-protection-regulation.
You can find more details in Stripe's privacy policy at the following link: https://stripe.com/de/privacy.
Klarna
The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers various payment options (e.g., installment payments). If you choose to pay with Klarna (Klarna Checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the Klarna Checkout solution. Details on the use of Klarna cookies can be found at the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
You can find more details in Klarna's privacy policy at the following link: https://www.klarna.com/de/datenschutz/.
Paydirekt
The provider of this payment service is Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main, Germany (hereinafter "Paydirekt"). When you make a payment using Paydirekt, Paydirekt collects various transaction data and forwards it to the bank with which you are registered with Paydirekt. In addition to the data required for the payment, Paydirekt may collect further data during the transaction processing, such as your delivery address or individual items in your shopping cart. Paydirekt then authenticates the transaction using the authentication method stored with your bank. The payment amount is then transferred from your account to our account. Neither we nor any third parties have access to your account details. For details on payment with Paydirekt, please refer to Paydirekt's Terms and Conditions and Privacy Policy at: https://www.paydirekt.de/agb/index.html.
Instant bank transfer
The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter referred to as "Sofort GmbH"). Using the "Sofortüberweisung" (instant bank transfer) method, we receive real-time payment confirmation from Sofort GmbH and can immediately begin fulfilling our obligations. If you have chosen the "Sofortüberweisung" payment method, you will submit your PIN and a valid TAN to Sofort GmbH, which they will use to log into your online banking account. After logging in, Sofort GmbH automatically checks your account balance and executes the transfer to us using the TAN you provided. They then immediately send us a transaction confirmation. After logging in, your transactions, overdraft limit, and the existence and balances of any other accounts you may have are also automatically checked. In addition to your PIN and TAN, the payment details you enter and your personal data are also transmitted to Sofort GmbH. The personal data we collect includes your first and last name, address, telephone number(s), email address, IP address, and any other data required for payment processing. This data is necessary to verify your identity beyond doubt and to prevent fraud. For details on payment via instant bank transfer, please see the following link: https://www.klarna.com/sofort/.
Amazon Pay
The provider of this payment service is Amazon Payments Europe SCA, 38 avenue JF Kennedy, L-1855 Luxembourg.
Details on how your data is handled can be found in the Amazon Pay privacy policy at the following link: https://pay.amazon.de/help/201212490?ld=APDELPADirect.
Mollie
The provider of this payment service is Mollie BV, Keizersgracht 126, 1015CW Amsterdam, Netherlands (hereinafter "Mollie"). Mollie allows us to integrate various payment methods into our website. For details, please see Mollie's privacy policy. https://www.mollie.com/de/privacy.
PayOne
The provider of this payment service is PAYONE GmbH, Lyoner Straße 9, 60528 Frankfurt am Main (hereinafter referred to as "PayOne"). For details, please refer to PayOne's privacy policy. https://www.payone.com/DE-de/datenschutz.
giropay
The provider of this payment service is paydirekt GmbH, Stephanstraße 14 – 16, 60313 Frankfurt am Main (hereinafter referred to as „giropay“).
For details, please refer to giropay's privacy policy: https://www.paydirekt.de/agb/index.html.
Unzer
The provider of this payment service is Unzer GmbH, Vangerowstraße 18, 69115 Heidelberg (hereinafter referred to as "Unzer").
For details, please refer to Unzer's privacy policy: https://www.unzer.com/de/datenschutz/.
CopeCart
The provider of this payment service is CopeCart GmbH, Ufnaustraße 10, 10553 Berlin (hereinafter referred to as "CopeCart"). For details, please refer to CopeCart's privacy policy. https://www.copecart.com/de/datenschutz.
Shopify Payment
The provider of this payment service in the EU is Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter referred to as „Shopify Payment“).
For details, please refer to the Shopify Payment privacy policy: https://www.shopify.de/legal/datenschutz.
Etsy Payments
For payments in euros, Etsy Ireland UC, 66/67 Great Strand Street, Dublin 1, Ireland, is the provider of this payment service. For payments in US dollars or Canadian dollars, the payment service provider is Etsy Inc., 117 Adams Street, Brooklyn, New York 11201, USA (both hereinafter also referred to as "Etsy Payments").
For further details, please refer to the Etsy Payments privacy policy: https://www.etsy.com/de/legal/etsy-payments/.
American Express
The provider of this payment service is American Express Europe SA, Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter referred to as "American Express").
American Express may transfer data to its parent company in the USA. This data transfer to the USA is based on the Binding Corporate Rules. Details can be found here: https://www.americanexpress.com/en-cz/company/legal/privacy-centre/binding-corporate-rules/.
For further information, please refer to the American Express privacy statement: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter referred to as „Mastercard“).
Mastercard may transfer data to its parent company in the USA. This data transfer to the USA is based on Mastercard's Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
VISA
The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter referred to as „VISA“).
The UK is considered a safe third country with regard to data protection. This means that the UK has a level of data protection equivalent to that of the European Union.
VISA may transfer data to its parent company in the USA. This data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.
For further information, please refer to VISA's privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
10. Audio and video conferences
Data processing
We use online conferencing tools, among other methods, to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference over the internet, your personal data will be collected and processed by us and the provider of the respective conferencing tool.
The conference tools collect all data that you provide/use to access the tools (email address and/or your phone number). Furthermore, the conference tools process the duration of the conference, the start and end times of your participation, the number of participants, and other "contextual information" related to the communication process (metadata).
Furthermore, the tool provider processes all technical data necessary for handling online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.
If content is exchanged, uploaded, or otherwise made available within the tool, it will also be stored on the tool provider's servers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared during the use of the service.
Please note that we do not have full control over the data processing operations of the tools used. Our options are largely determined by the respective provider's company policy. Further information on data processing by the conference tools can be found in the privacy policies of the respective tools, which we have listed below this text.
Purpose and legal basis
The conference tools are used to communicate with prospective or existing business partners or to offer certain services to our customers (Art. 6 para. 1 lit. b GDPR). Furthermore, the use of these tools serves to generally simplify and expedite communication with us or our company (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Where consent has been requested, the use of the relevant tools is based on this consent; this consent can be revoked at any time with effect for the future.
Storage duration
The data we collect directly via video and conferencing tools will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal retention periods remain unaffected.
We have no control over how long your data is stored by the operators of the conference tools for their own purposes. For details, please contact the operators of the conference tools directly.
Conference tools used
We use the following conference tools:
zoom
We use Zoom. The provider of this service is Zoom Communications Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Details regarding data processing can be found in Zoom's privacy policy. https://www.zoom.com/de/trust/privacy/privacy-statement/.
Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.zoom.com/de/trust/privacy/privacy-statement/.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5728.
TeamViewer
We use TeamViewer. The provider is TeamViewer Germany GmbH, Jahnstr. 30, 73037 Göppingen. Details regarding data processing can be found in TeamViewer's privacy policy. https://www.teamviewer.com/de/datenschutzerklaerung/.
Microsoft Teams
We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please see the Microsoft Teams privacy policy. https://privacy.microsoft.com/de-de/privacystatement.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474.
Google Meet
We use Google Meet. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For details on data processing, please see Google's privacy policy: https://policies.google.com/privacy?hl=de.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
BigBlueButton
We use BigBlueButton. When you communicate with us via BigBlueButton, all data associated with this communication process is processed exclusively on servers within the European Union or a third country with a secure data protection policy.
Recording of conferences
We can record the video and audio conferences we conduct using BigBlueButton.
11. Own services
Handling of applicant data
We offer you the opportunity to apply to us (e.g., by email, post, or via our online application form). Below, we inform you about the scope, purpose, and use of your personal data collected during the application process. We assure you that the collection, processing, and use of your data will be carried out in accordance with applicable data protection law and all other legal provisions, and that your data will be treated with strict confidentiality.
Scope and purpose of data collection
When you submit an application to us, we process your associated personal data (e.g., contact and communication data, application documents, notes from job interviews, etc.) to the extent necessary for deciding whether to establish an employment relationship. The legal basis for this is Section 26 of the German Federal Data Protection Act (BDSG) (initiation of an employment relationship), Article 6 Paragraph 1 Letter b of the GDPR (general contract initiation), and – if you have given your consent – Article 6 Paragraph 1 Letter a of the GDPR. You can withdraw your consent at any time. Within our company, your personal data will only be shared with individuals involved in processing your application.
If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Section 26 BDSG and Article 6 Paragraph 1 Letter b GDPR for the purpose of carrying out the employment relationship.
As part of the application process, we may also conduct online research about you. This primarily includes Google searches, LinkedIn, and Xing. The legal basis for this type of processing is our legitimate interest in gaining an overall impression of you based on publicly available information, pursuant to Article 6(1)(f) GDPR.
Data retention period
If we are unable to offer you a position, you decline a job offer, or you withdraw your application, we reserve the right to retain the data you submitted for up to six months from the conclusion of the application process (rejection or withdrawal of the application) based on our legitimate interests (Art. 6 para. 1 lit. f GDPR). After this period, the data will be deleted and any physical application documents destroyed. This retention serves, in particular, as evidence in the event of legal proceedings. If it becomes apparent that the data will be required after the six-month period (e.g., due to threatened or pending legal proceedings), deletion will only occur once the purpose for the extended retention no longer applies.
Longer storage may also take place if you have given your consent (Art. 6 para. 1 lit. a GDPR) or if legal retention obligations preclude deletion.
OneDrive
We have integrated OneDrive into this website. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as "OneDrive").
OneDrive allows us to integrate an upload area into our website where you can upload content. When you upload content, it is stored on OneDrive's servers. Additionally, when you visit our website, a connection to OneDrive is established so that OneDrive can recognize that you have visited our site.
The use of OneDrive is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in a reliable upload area on their website. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR; this consent can be revoked at any time.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474.
Google Drive
We have integrated Google Drive into this website. The provider is Google Ireland Limited („Google“), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Drive allows us to integrate an upload area into our website where you can upload content. When you upload content, it is stored on Google Drive's servers. Furthermore, when you visit our website, a connection to Google Drive is established, allowing Google Drive to recognize that you have visited our site.
The use of Google Drive is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in a reliable upload area on their website. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR; this consent can be revoked at any time.
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.