Skip to content

Data protection

Privacy Policy

Controller responsible for data processing:

Prime Welding GmbH

Heinrich-Uwe Schwart

Ehrmannstraße 2

76135 Karlsruhe

Tel. +49 (0) 561 9845 6572
Mobile +49 (0) 171 43 11 524

E-mail: info@primewelding.eu

Preamble

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also briefly referred to as “data”) that we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”).

The terms used are not gender-specific.

As of: 7 August 2026

Legal text by Dr. Schwenke – click for more information.

Table of contents

Controller

Overview of processing activities

The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects concerned.

Types of data processed

  • Inventory data.
  • Payment data.
  • Location data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication and procedural data.
  • Contact information (Facebook).
  • Event data (Facebook).

Categories of data subjects

  • Customers.
  • Employees.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Contact enquiries and communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement.
  • Tracking.
  • Office and organisational procedures.
  • Remarketing.
  • Conversion measurement.
  • Audience building.
  • Management of and responses to enquiries.
  • Content Delivery Network (CDN).
  • Feedback.
  • Marketing.
  • Profiles with user-related information.
  • Provision of our online offering and user-friendliness.
  • Assessment of creditworthiness and credit rating.
  • Information technology infrastructure.

Automated decisions in individual cases

  • Credit report.

Relevant legal bases

Relevant legal bases under the GDPR: The following provides an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country of residence or registered office, or in ours. If more specific legal bases are relevant in individual cases, we will inform you of these in the privacy policy.

  • Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) – The data subject has given consent to the processing of personal data concerning them for one or more specific purposes.
  • Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. This includes, in particular, the Act on Protection against Misuse of Personal Data in Data Processing (Bundesdatenschutzgesetz – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. In addition, the data protection laws of the individual federal states may apply.

Notice on the applicability of the GDPR and the Swiss FADP: These privacy notices serve to provide information both under the Swiss Federal Act on Data Protection (Swiss FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that, due to their broader territorial application and comprehensibility, the terms used in the GDPR are used. In particular, instead of the terms used in the Swiss FADP, “processing” of “personal data”, “overriding interest” and “particularly sensitive personal data”, the terms used in the GDPR, “processing” of “personal data”, “legitimate interest” and “special categories of data”, are used. However, the legal meaning of the terms continues to be determined under the Swiss FADP within the scope of its applicability.

Security measures

In accordance with the statutory requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood of occurrence and extent of the threat to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, safeguarding of the availability of and separation of the data concerned. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the deletion of data and responses to threats to the data. We also take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principle of data protection, through technology design and data protection-friendly default settings.

IP address truncation: If IP addresses are processed by us or by the service providers and technologies used, and processing a complete IP address is not required, the IP address is truncated (also referred to as “IP masking”). In doing so, the last two digits, or the last part of the IP address after a dot, are removed or replaced with placeholders. Truncating the IP address is intended to prevent or substantially impede the identification of a person based on their IP address.

TLS/SSL encryption (https): To protect the data of users transmitted via our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing internet connections through encryption of the data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is displayed in the URL when a website is secured by an SSL/TLS certificate.

Transmission of personal data

In the course of our processing of personal data, it may happen that the data is transmitted to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, conclude appropriate contracts or agreements serving to protect your data with the recipients of your data.

Data transmission within the corporate group: We may transmit personal data to other companies within our corporate group or grant them access to this data. If this disclosure is for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and business interests or takes place if it is necessary to fulfil our contractual obligations or if the data subjects have given consent or a statutory authorisation exists.

Data transmission within the organisation: We may transmit personal data to other bodies within our organisation or grant them access to this data. If this disclosure is for administrative purposes, the disclosure of the data is based on our legitimate entrepreneurial and business interests or takes place if it is necessary to fulfil our contractual obligations or if the data subjects have given consent or a statutory authorisation exists.

International data transfers

Data processing in third countries: If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if the processing takes place in the context of using third-party services or disclosing or transmitting data to other persons, bodies or companies, this is carried out only in accordance with the statutory requirements. If the level of data protection in the third country has been recognised by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers take place only if the level of data protection is secured by other means, in particular through standard contractual clauses (Art. 46 para. 2 lit. c) GDPR), explicit consent or in the case of contractually or legally required transmission (Art. 49 para. 1 GDPR). Otherwise, we will inform you of the bases for transmission to third countries in the individual information for the providers from the third country, with adequacy decisions taking precedence as a basis. Information on transfers to third countries and existing adequacy decisions can be found in the European Commission’s information offering: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

EU-US Trans-Atlantic Data Privacy Framework: Under the so-called “Data Privacy Framework” (DPF), the EU Commission has also recognised the level of data protection as adequate for certain companies in the USA by means of the adequacy decision of 10.07.2023. The list of certified companies and further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). In the privacy notices, we inform you which service providers used by us are certified under the Data Privacy Framework.

Deletion of data

The data processed by us is deleted in accordance with the statutory requirements as soon as the consents permitted for its processing are revoked or other permissions cease to apply (e.g. if the purpose of processing this data has ceased to apply or the data is not required for the purpose). If the data is not deleted because it is required for other legally permissible purposes, its processing is restricted to those purposes. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax reasons or whose storage is necessary for the assertion, exercise or defence of legal claims or for protecting the rights of another natural or legal person. In our privacy notices, we may provide users with further information on the deletion and retention of data that applies specifically to the respective processing processes.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject under the GDPR, you have various rights, which arise in particular from Art. 15 to 21 GDPR:

  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to processing of personal data concerning you for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw consent given at any time.
  • Right of access: You have the right to request confirmation as to whether relevant data is being processed and to request access to this data as well as further information and a copy of the data in accordance with the statutory requirements.
  • Right to rectification: In accordance with the statutory requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
  • Right to erasure and restriction of processing: In accordance with the statutory requirements, you have the right to request that data concerning you be deleted without undue delay or, alternatively, to request restriction of the processing of the data in accordance with the statutory requirements.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with the statutory requirements, in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller.
  • Right to lodge a complaint with a supervisory authority: In accordance with the statutory requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, your place of work or the place of the alleged infringement, if you should consider that the processing of personal data concerning you infringes the GDPR.

Use of cookies

Cookies are small text files or other storage records that store information on end devices and read information from end devices. For example, they can store the login status in a user account, the contents of a shopping cart in an e-shop, the content accessed or the functions used in an online service. Cookies may also be used for various purposes, e.g. for the functionality, security and convenience of online services and for creating analyses of visitor traffic.

Information on consent: We use cookies in accordance with the statutory provisions. We therefore obtain users' prior consent unless this is not required by law. Consent is in particular not necessary if the storage and reading of information, including cookies, are strictly necessary in order to provide users with a telemedia service expressly requested by them (i.e. our online service). Strictly necessary cookies generally include cookies with functions serving the display and operability of the online service, load balancing, security, storage of users' preferences and choices, or similar purposes connected with the provision of the main and ancillary functions of the online service requested by users. The revocable consent is clearly communicated to users and contains information on the respective use of cookies.

Information on the legal bases under data protection law: The legal basis under data protection law on which we process users' personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the consent given. Otherwise, the data processed with the help of cookies are processed on the basis of our legitimate interests (e.g. in the commercial operation of our online service and improving its usability) or, if this occurs as part of the performance of our contractual obligations, if the use of cookies is necessary to fulfil our contractual obligations. We provide information about the purposes for which we process cookies in the course of this privacy policy or as part of our consent and processing procedures.

Storage period: With regard to the storage period, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online service and closed their end device (e.g. browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the end device has been closed. For example, the login status can be stored or preferred content can be displayed directly when the user visits a website again. The data collected from users with the help of cookies may likewise be used to measure reach. If we do not provide users with explicit information about the type and storage period of cookies (e.g. as part of obtaining consent), users should assume that cookies are permanent and that the storage period may be up to two years.

General information on revocation and objection (so-called “opt-out”): Users can revoke the consent they have given at any time and object to processing in accordance with the statutory requirements. Among other things, users can restrict the use of cookies in their browser settings (which may also restrict the functionality of our online service). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com.

  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO). Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO).

Further information on processing processes, procedures and services:

  • Processing of cookie data on the basis of consent: We use a consent management procedure: a procedure for obtaining, recording, managing and revoking consents, in particular for the use of cookies and similar technologies for storing, reading and processing information on users' end devices and for processing such information, within which users' consents to the use of cookies or to the processing and providers specified in the consent management procedure—a procedure for obtaining, recording, managing and revoking consents, in particular for the use of cookies and similar technologies for storing, reading and processing information on users' end devices and for processing such information—can be obtained and managed and revoked by users. The declaration of consent is stored so that it does not have to be requested again and so that consent can be demonstrated in accordance with the statutory obligation. The storage may take place on the server side and/or in a cookie (so-called opt-in cookie or with the help of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information about the providers of cookie management services, the following information applies: The consent may be stored for up to two years. A pseudonymous user identifier is created and stored together with the time of consent, information on the scope of consent (e.g. which categories of cookies and/or service providers) and the browser, system and end device used; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO).

Business services

We process data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as “contractual partners”), within the scope of contractual and comparable legal relationships and related measures and within the scope of communication with the contractual partners (or pre-contractually), e.g. in order to answer enquiries.

We process this data in order to fulfil our contractual obligations. This includes in particular the obligations to provide the agreed services, any obligations to update, and remedying defects under warranty and other service disruptions. In addition, we process the data to safeguard our rights and for the purpose of the administrative tasks associated with these obligations and the organisation of the company. Furthermore, we process the data on the basis of our legitimate interests in proper and commercially sound business management and in security measures to protect our contractual partners and our business operations against misuse, endangerment of their data, secrets, information and rights (e.g. involving telecommunications, transport and other support services as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities). Within the scope of the applicable law, we only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfil statutory obligations. Contractual partners are informed about other forms of processing, e.g. for marketing purposes, within the scope of this privacy policy.

We inform contractual partners before or during data collection which data are required for the aforementioned purposes, e.g. in online forms, through special labelling (e.g. colours) or symbols (e.g. asterisks or similar), or personally.

We delete the data after the expiry of statutory warranty and comparable obligations, i.e. generally after 4 years, unless the data are stored in a customer account, e.g. for as long as they have to be retained for statutory archiving reasons. The statutory retention period is ten years for documents relevant under tax law and for ledgers, inventories, opening balance sheets, annual financial statements, the work instructions and other organisational documents and accounting records required to understand these documents, and six years for received business and commercial letters and reproductions of sent business and commercial letters. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, opening balance sheet, annual financial statement or management report was prepared, the business or commercial letter was received or sent, or the accounting record was created, and in which the record was made or the other documents were created.

To the extent that we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and the providers.

  • Data categories processed: Master data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. email, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status).
  • Data subjects: Customers; prospective customers. Business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; security measures; contact enquiries and communication; office and organisational procedures. Management and response to enquiries.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); legal obligation (Art. 6 Abs. 1 S. 1 lit. c) DSGVO). Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Further information on processing processes, procedures and services:

  • Customer account: Customers can create an account within our online service (e.g. customer or user account, briefly “customer account”). If registration for a customer account is required, customers are informed of this as well as of the information required for registration. Customer accounts are not public and cannot be indexed by search engines. As part of registration and subsequent logins and uses of the customer account, we store customers' IP addresses together with the access times in order to be able to prove the registration and prevent possible misuse of the customer account. If the customer account is terminated, the customer account data are deleted after the time of termination, provided that they are not retained for purposes other than provision in the customer account or must be retained for legal reasons (e.g. internal storage of customer data, ordering processes or invoices). Customers are responsible for backing up their data when terminating the customer account; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO).
  • Online shop, order forms, e-commerce and delivery: We process our customers' data in order to enable them to select, purchase or order the selected products, goods and related services, and to pay for and have them delivered or carried out. If required to process an order, we use service providers, in particular postal, freight forwarding and shipping companies, to carry out delivery or performance for our customers. We use the services of banks and payment service providers to process payment transactions. The required information is identified as such as part of the order or comparable purchasing process and includes the information required for delivery or provision and billing as well as contact information so that any necessary consultation can take place; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO).

Use of online platforms for offering and sales purposes

We offer our services on online platforms operated by other service providers. In this context, in addition to our privacy notices, the privacy notices of the respective platforms apply. This applies in particular with regard to the execution of the payment transaction and the procedures for reach measurement and interest-based marketing used on the platforms.

  • Data categories processed: Master data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. email, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status).
  • Data subjects: Customers.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations. Marketing.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO). Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Further information on processing processes, procedures and services:

Providers and services used in the course of business activities

In the course of our business activities, and in compliance with the statutory requirements, we use additional services, platforms, interfaces or plug-ins from third-party providers (in short, “services”). Their use is based on our interests in the proper, lawful and economically efficient management of our business operations and our internal organisation.

  • Data categories processed: Master data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); contract data (e.g. subject matter of the contract, term, customer category).
  • Data subjects: Customers; prospective customers; users (e.g. website visitors, users of online services); business and contractual partners; employees (e.g. employees, applicants, former employees).
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations. Office and organisational procedures.
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Further information on processing processes, procedures and services:

Payment procedures

Within the scope of contractual and other legal relationships, on the basis of statutory obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, use other service providers in addition to banks and credit institutions (collectively, “payment service providers”).

The data processed by the payment service providers include master data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, amount and recipient-related information. The information is required to carry out the transactions. However, the data entered are processed and stored only by the payment service providers. This means that we do not receive any account- or credit-card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers transmit the data to credit agencies. This transmission serves the purpose of identity and credit checks. In this regard, we refer to the payment service providers' terms and conditions and privacy notices.

The terms and conditions and privacy notices of the respective payment service providers, which can be accessed on the respective websites or transaction applications, apply to payment transactions. We also refer to these for further information and for exercising rights of revocation, access and other data-subject rights.

  • Data categories processed: Master data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status); contact data (e.g. email, telephone numbers).
  • Data subjects: Customers. Prospective customers.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO).

Further information on processing processes, procedures and services:

  • Amazon Payments: Payment services (technical connection of online payment methods); Service provider: Amazon Payments Europe S.C.A. 38 avenue J.F. Kennedy, L-1855 Luxemburg; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://pay.amazon.de/. Privacy policy: https://pay.amazon.de/help/201212490.
  • American Express: Payment services (technical connection of online payment methods); Service provider: American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Deutschland; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.americanexpress.com/de/. Privacy policy: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
  • Apple Pay: Payment services (technical connection of online payment methods); Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.apple.com/de/apple-pay/. Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
  • Giropay: Payment services (technical connection of online payment methods); Service provider: giropay GmbH, An der Welle 4, 60322 Frankfurt, Deutschland; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.giropay.de. Privacy policy: https://www.giropay.de/rechtliches/datenschutzerklaerung/.
  • Google Pay: Payment services (technical connection of online payment methods); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://pay.google.com/intl/de_de/about/. Privacy policy: https://policies.google.com/privacy.
  • Klarna: Payment services (technical connection of online payment methods); Service provider: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Schweden; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.klarna.com/de. Privacy policy: https://www.klarna.com/de/datenschutz.
  • Mastercard: Payment services (technical connection of online payment methods); Service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgien; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.mastercard.de/de-de.html. Privacy policy: https://www.mastercard.de/de-de/datenschutz.html.
  • PayPal: Payment services (technical connection of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.paypal.com/de. Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
  • Shop Pay (Shopify): Payment services (technical connection of online payment methods); Service provider: Shopify International Limited, Victoria Buildings, 2. Etage,1-2 Haddington Road, Dublin 4, D04 XN32, Irland; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.shopify.de. Privacy policy: https://www.shopify.de/legal/datenschutz.
  • Stripe: Payment services (technical connection of online payment methods); Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://stripe.com; Privacy policy: https://stripe.com/de/privacy. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
  • Visa: Payment services (technical connection of online payment methods); Service provider: Visa Europe Services Inc., Zweigniederlassung London, 1 Sheldon Square, London W2 6TT, GB; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO); Website: https://www.visa.de. Privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

Credit assessment

If we make advance payments or assume comparable economic risks (e.g. when ordering on account), we reserve the right, in order to safeguard our legitimate interests, to obtain identity and credit information for assessing the credit risk on the basis of mathematical-statistical procedures from service companies specialised in this area (credit agencies).

We process the information received from the credit agencies about the statistical probability of a payment default as part of a proper discretionary decision on the establishment, implementation and termination of the contractual relationship. We reserve the right, in the event of a negative result of the credit assessment, to refuse payment on account or another advance payment.

The decision as to whether we make an advance payment is made in accordance with the statutory requirements solely on the basis of an automated decision in an individual case, which our software makes using the information provided by the credit agency.

If we obtain express consent from contractual partners, the legal basis for the credit information and the transmission of the customer's data to the credit agencies is consent. If no consent is obtained, the credit information is provided on the basis of our legitimate interests in the protection against failure of our payment claims.

  • Data categories processed: Master data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. email, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times).
  • Data subjects: Customers; prospective customers. Business and contractual partners.
  • Purposes of processing: Assessment of solvency and creditworthiness.
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO). Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO).
  • Automated decisions in individual cases: Credit information (decision based on a credit assessment).

Further information on processing processes, procedures and services:

  • Credit assessment as a prerequisite for providing payment options: The provision of payment options, e.g. payment on account or payment by instalments, may be made dependent on the result of the customer's credit assessment. In this case, we ask customers to consent to the credit assessment procedure; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO).
  • Verband der Vereine Creditreform e.V.: Credit agency; Service provider: Verband der Vereine Creditreform e.V., Hellersbergstraße 12, D-41460 Neuss, Deutschland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.creditreform.de/. Privacy policy: https://www.creditreform.de/datenschutz.

Provision of the online service and web hosting

We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the users' browser or end device.

  • Data categories processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status); content data (e.g. entries in online forms).
  • Data subjects: Users (e.g. website visitors, users of online services). Business and contractual partners.
  • Purposes of processing: Provision of our online service and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.).); security measures. Content Delivery Network (CDN).
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Further information on processing processes, procedures and services:

  • Provision of online service on rented storage space: To provide our online service, we use storage space, computing capacity and software that we rent or otherwise obtain from an appropriate server provider (also known as a “web hoster”); Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).
  • Collection of access data and log files: Access to our online service is logged in the form of so-called “server log files”. The server log files may include the address and name of the websites and files accessed, the date and time of access, the amount of data transferred, a message indicating successful retrieval, the browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files may be used on the one hand for security purposes, e.g. to prevent the servers from being overloaded (in particular in the event of abusive attacks, so-called DDoS attacks), and on the other hand to ensure server utilisation and stability; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO). Deletion of data: Log file information is stored for a maximum period of 30 days and then deleted or anonymised. Data whose further retention is necessary for evidentiary purposes are excluded from deletion until the respective incident has been finally clarified.
  • Amazon Web Services (AWS): Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacities); Service provider: Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxemburg; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://aws.amazon.com/de/; Privacy policy: https://aws.amazon.com/de/privacy/; Data processing agreement: https://aws.amazon.com/de/compliance/gdpr-center/. Basis for third-country transfer: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://aws.amazon.com/service-terms/).
  • STRATO: Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacities); Service provider: STRATO AG, Pascalstraße 10,10587 Berlin, Deutschland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.strato.de; Privacy policy: https://www.strato.de/datenschutz/. Data processing agreement: Provided by the service provider.
  • Cloudflare: Content delivery network (CDN)—a service that enables the content of an online service, in particular large media files such as graphics or program scripts, to be delivered faster and more securely with the help of regionally distributed servers connected via the internet; Service provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.cloudflare.com; Privacy policy: https://www.cloudflare.com/privacypolicy/; Data processing agreement: https://www.cloudflare.com/cloudflare-customer-dpa/. Basis for third-country transfer: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://www.cloudflare.com/cloudflare-customer-scc/).

Contact and enquiry management

When contacting us (e.g. by post, contact form, email, telephone or via social media) and within the scope of existing user and business relationships, the information provided by the enquiring persons is processed insofar as this is necessary to answer contact enquiries and any requested measures.

  • Data categories processed: Contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact enquiries and communication; management and response to enquiries; feedback (e.g. collecting feedback via an online form). Provision of our online service and user-friendliness.
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO). Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO).

Further information on processing processes, procedures and services:

  • Contact form: When users contact us via our contact form, email or other means of communication, we process the data provided to us in this context to process the stated matter; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Cloud services

We use software services accessible via the internet and operated on the servers of their providers (so-called “cloud services”, also known as “Software as a Service”) for storing and managing content (e.g. document storage and management, exchanging documents, content and information with specific recipients, or publishing content and information).

In this context, personal data may be processed and stored on the providers' servers insofar as such data are part of communication processes with us or are otherwise processed by us as described in this privacy policy. This data may include in particular master data and contact data of users, data relating to transactions, contracts and other processes and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and to optimise the service.

If we use the cloud services to provide forms or other documents and content for other users or publicly accessible websites, the providers may store cookies on users' devices for the purposes of web analysis or to remember users' settings (e.g. in the case of media control).

  • Data categories processed: Master data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status).
  • Data subjects: Customers; employees (e.g. employees, applicants, former employees); prospective customers. Communication partners.
  • Purposes of processing: Office and organisational procedures. Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.).).
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Further information on processing processes, procedures and services:

Newsletter and electronic notifications

We send newsletters, emails and other electronic notifications (hereinafter “newsletters”) only with the recipients’ consent or a legal authorization. If the contents of the newsletter are specifically described as part of a newsletter subscription, they are decisive for the users’ consent. Otherwise, our newsletters contain information about our services and about us.

To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name for personal address in the newsletter, or further information if this is required for the purposes of the newsletter.

Double opt-in procedure: Subscription to our newsletter generally takes place using a so-called double opt-in procedure. This means that after subscribing, you receive an email asking you to confirm your subscription. This confirmation is necessary so that no one can subscribe using someone else’s email address. Newsletter subscriptions are logged so that we can demonstrate that the subscription process was completed in accordance with legal requirements. This includes storing the time of subscription and confirmation as well as the IP address. Changes to your data stored with the email service provider are also logged.

Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove that consent was previously given. The processing of this data is restricted to the purpose of potentially defending against claims. An individual request for deletion is possible at any time, provided that the previous existence of consent is confirmed at the same time. In the event of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist (so-called “blocklist”).

The logging of the subscription procedure takes place on the basis of our legitimate interests for the purpose of proving that it was properly completed. If we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure dispatch system.

Contents:

Information about us, our services, campaigns and offers.

  • Processed data types: Master data (e.g. names, addresses); contact data (e.g. email, telephone numbers); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status); usage data (e.g. visited websites, interest in content, access times).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g. by email or post).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Right to object (opt-out): You can unsubscribe from receiving our newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find a link to unsubscribe from the newsletter either at the end of every newsletter, or you can use one of the contact options listed above, preferably email, for this purpose.

Further information on processing operations, procedures and services:

  • Measuring open and click rates: The newsletters contain a so-called “web beacon”, i.e. a pixel-sized file that is retrieved from our server when the newsletter is opened or, if we use an email service provider, from that provider’s server. As part of this retrieval, technical information such as information about your browser and your system, as well as your IP address and the time of retrieval, is initially collected.

This information is used to technically improve our newsletter on the basis of the technical data or the target groups and their reading behavior, based on their retrieval locations (which can be determined with the help of the IP address) or access times. This analysis also includes determining whether the newsletters are opened, when they are opened and which links are clicked. This information is assigned to the individual newsletter recipients and stored in their profiles until they are deleted. The evaluations help us identify the reading habits of our users and adapt our content to them or send different content according to the interests of our users.

The measurement of open and click rates, the storage of the measurement results in users’ profiles and their further processing are carried out on the basis of users’ consent.

A separate withdrawal of consent to performance measurement is unfortunately not possible; in this case, the entire newsletter subscription must be cancelled or objected to. In this case, the stored profile information is deleted; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

  • Reminder emails for the ordering process: If users do not complete an ordering process, we can remind users by email about the ordering process and send them a link to continue it. This function can be useful, for example, if the purchasing process could not be continued due to a browser crash, an oversight or forgetfulness. The emails are sent on the basis of consent, which users can withdraw at any time; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
  • ActiveCampaign: Email dispatch and automation services; Service provider: ActiveCampaign, Inc., 1 N Dearborn, 5th Floor Chicago, Illinois 60602, USA; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.activecampaign.com; Privacy policy: https://www.activecampaign.com/privacy-policy/. Basis for transfer to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://www.activecampaign.com/legal/newscc).
  • CleverReach: Email dispatch and automation services; Service provider: CleverReach GmbH & Co. KG, //CRASH Building, Schafjückenweg 2, 26180 Rastede, Deutschland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.cleverreach.com/de; Privacy policy: https://www.cleverreach.com/de/datenschutz/. Data processing agreement: Provided by the service provider.
  • Clickfunnels: Email dispatch and automation services; Service provider: Etison LLC, 3443 W. Bavaria Street, Eagle, Idaho 83616, USA; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.clickfunnels.com/; Privacy policy: https://signup.clickfunnels.com/privacy-policy; Data processing agreement: https://signup.clickfunnels.com/dpa. Basis for transfer to third countries: Standard contractual clauses (https://signup.clickfunnels.com/dpa).
  • Mailchimp: Email dispatch and email dispatch and automation services; Service provider: Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://mailchimp.com; Privacy policy: https://mailchimp.com/legal/; Data processing agreement: https://mailchimp.com/legal/; Basis for transfer to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (provided by the service provider). Further information: Special security measures: https://mailchimp.com/de/help/mailchimp-european-data-transfers/.

Advertising communication by email, post, fax or telephone

We process personal data for the purposes of advertising communication, which may take place via various channels, such as email, telephone, post or fax, in accordance with legal requirements.

Recipients have the right to withdraw consent they have given at any time or to object to advertising communication at any time.

After withdrawal or objection, we store the data required to prove the previous authorization for contacting or sending items for up to three years after the end of the year in which the withdrawal or objection took place, on the basis of our legitimate interests. The processing of this data is restricted to the purpose of potentially defending against claims. On the basis of the legitimate interest in permanently observing users’ withdrawal or objection, we also store the data required to prevent renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).

  • Processed data types: Master data (e.g. names, addresses); contact data (e.g. email, telephone numbers).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g. by email or post).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Web analytics, monitoring and optimization

Web analytics (also referred to as “reach measurement”) serves to evaluate visitor flows to our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can determine, for example, at what time our online offering or its functions or contents are used most frequently or invite reuse. We can also identify which areas require optimization.

In addition to web analytics, we may also use testing procedures to test and optimize different versions of our online offering or its components, for example.

Unless otherwise stated below, profiles, i.e. data combined into a usage process, may be created for these purposes, and information may be stored in a browser or on an end device and read from it. The information collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information about usage times. If users have consented to the collection of their location data by us or by the providers of the services we use, location data may also be processed.

Users’ IP addresses are also stored. However, we use an IP masking procedure (i.e. pseudonymization by shortening the IP address) to protect users. Generally, no clear data of users (such as email addresses or names) is stored as part of web analytics, A/B testing and optimization, but pseudonyms. This means that neither we nor the providers of the software used know the users’ actual identity, but only the information stored for the purposes of the respective procedures in their profiles.

  • Processed data types: Usage data (e.g. visited websites, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Remarketing; audience building; reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles). Provision of our online offering and user-friendliness.
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

Further information on processing operations, procedures and services:

  • Google Analytics: We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain unique data such as names or email addresses. It is used to assign analysis information to an end device in order to determine which content users accessed during one or various usage processes, which search terms they used, whether they accessed them again or interacted with our online offering. The time of use and its duration are also stored, as are the sources of users who refer to our online offering and technical aspects of their end devices and browsers.

Pseudonymous profiles of users are created using information from the use of different devices, and cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides approximate geographic location data by deriving the following metadata from IP addresses: city (and the city’s derived latitude and longitude), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, the IP address data is used exclusively to derive this geolocation data before being immediately deleted. It is not logged, is not accessible and is not used for any other purposes. When Google Analytics collects measurement data, all IP lookups are performed on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for transfer to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms); Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertising: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and the data processed).

  • Information on consent recipients: Consent given by users as part of a consent dialog (also known as “cookie opt-in/consent”, “cookie banner”, etc.) serves several purposes. Firstly, it serves to fulfill our obligation to obtain consent to the storage and reading of information on and from users’ end devices (in accordance with the ePrivacy guidelines). Secondly, it covers the processing of users’ personal data in accordance with data protection requirements. This consent also applies to Google, as the company is required under the Digital Markets Act to obtain consent for personalized services. We therefore share the status of users’ consents with Google. Our consent management software informs Google whether consent has been given or not. The aim is to ensure that users’ consents, whether given or not, are taken into account when using Google Analytics and integrating functions and external services. This allows users’ consent and its withdrawal to be dynamically adjusted within Google Analytics and other Google services in our online offering depending on the user’s selection; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://support.google.com/analytics/answer/9976101?hl=de. Privacy policy: https://policies.google.com/privacy.
  • Google Analytics (server-side use): We use Google Analytics to measure and analyze users’ use of our online services. Although users’ data is processed, it is not transmitted directly from users’ end devices to Google. In particular, users’ IP addresses are not transmitted to Google. Instead, the data is first transmitted to our server, where users’ data records are assigned to our internal user identification number. The subsequent transmission takes place from our server to Google only in this pseudonymized form. The identification number does not contain unique data such as names or email addresses. It is used to assign analysis information to an end device in order to determine which content users accessed during one or various usage processes, which search terms they used, whether they accessed them again or interacted with our online offering. The time of use and its duration are also stored, as are the sources of users who refer to our online offering and technical aspects of their end devices and browsers. Pseudonymous profiles of users are created using information from the use of different devices, and cookies may be used. In Analytics, higher-level geographic location data is provided by collecting the following metadata based on the IP lookup: “city” (and the city’s derived latitude and longitude), “continent”, “country”, “region”, “subcontinent” (and the ID-based counterparts); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for transfer to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms/). Further information: https://business.safety.google/adsservices/ (types of processing and the data processed).
  • Google Signals (Google Analytics function): Google Signals are session data from websites and apps that Google associates with users who are signed in to their Google accounts and have enabled ad personalization. This association of data with these signed-in users is used to enable cross-device reports, cross-device remarketing and cross-device conversion measurement. This includes: Cross-platform reports – linking data about devices and activities from different sessions using your User ID or Google Signals data, enabling an understanding of user behavior at every step of the conversion process, from the first contact to conversion and beyond; remarketing with Google Analytics – creating remarketing audiences from Google Analytics data and sharing these audiences with linked advertising accounts; demographics and interests – Google Analytics collects additional information about the demographics and interests of users who are signed in to their Google accounts and have enabled ad personalization; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://support.google.com/analytics/answer/7532985?hl=de; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms; Basis for transfer to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms). Further information: https://business.safety.google/adsservices/ (types of processing and the data processed).
  • Audience building with Google Analytics: We use Google Analytics to display ads placed within Google’s and its partners’ advertising services only to users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products, determined on the basis of the websites visited) that we transmit to Google (so-called “remarketing” or “Google Analytics audiences”). With the help of remarketing audiences, we also want to ensure that our ads correspond to users’ potential interests; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com; Legal bases: https://business.safety.google/adsprocessorterms/; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for transfer to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and the data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products and standard contractual clauses for third-country transfers of data: https://business.safety.google/adsprocessorterms.
  • Google Tag Manager: Google Tag Manager is a solution that allows us to manage so-called website tags via an interface and thus integrate other services into our online offering (for this purpose, reference is made to further information in this privacy policy). The Tag Manager itself (which implements the tags) therefore does not yet create user profiles or store cookies. Google only learns the user’s IP address, which is necessary to execute Google Tag Manager; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms. Basis for transfer to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms).
  • Google Tag Manager (server-side use): Google Tag Manager is an application that allows us to manage so-called website tags via an interface and thereby integrate other services into our online offering (see also the further information in this privacy policy). The Tag Manager itself (which implements the tags) therefore stores neither user profiles nor cookies. The other services are integrated server-side. This means that users’ data is not transmitted directly from their end devices to the respective service or Google. In particular, users’ IP addresses are not transmitted to the other service. Instead, the data is first transmitted to our server, where users’ data records are assigned to our internal user identification number. The subsequent transmission of the data from our server to the servers of the respective service providers takes place only in this pseudonymized form. The user identification number does not contain unique data such as names or email addresses; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for transfer to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms). Further information: https://business.safety.google/adsservices/ (types of processing and the data processed).

Online marketing

We process personal data for the purposes of online marketing, which may include, in particular, the marketing of advertising space or the presentation of advertising and other content (collectively referred to as "content") based on users' potential interests, as well as measuring its effectiveness.

For these purposes, so-called user profiles are created and stored in a file (a so-called "cookie"), or similar procedures are used to store information about the user that is relevant to the presentation of the aforementioned content. This information may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical information such as the browser used, the computer system used, and information on usage times and functions used. If users have consented to the collection of their location data, this data may also be processed.

Users' IP addresses are also stored. However, we use available IP masking procedures (i.e. pseudonymization by shortening the IP address) to protect users. In general, within the framework of online marketing procedures, no cleartext data of users (such as e-mail addresses or names) is stored, but rather pseudonyms. In other words, neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.

The information in the profiles is generally stored in cookies or using similar procedures. These cookies can later generally also be read on other websites that use the same online marketing procedure, analyzed for the purpose of presenting content, supplemented with further data, and stored on the server of the provider of the online marketing procedure.

In exceptional cases, cleartext data may be assigned to the profiles. This is the case if, for example, users are members of a social network whose online marketing procedure we use and the network links the users' profiles with the aforementioned information. Please note that users may enter into additional agreements with the providers, for example by giving consent during registration.

As a rule, we only receive access to aggregated information about the success of our advertisements. However, as part of so-called conversion measurement, we can determine which of our online marketing procedures led to a so-called conversion, i.e. for example, to the conclusion of a contract with us. Conversion measurement is used solely to analyze the success of our marketing measures.

Unless otherwise stated, please assume that the cookies used are stored for a period of two years.

  • Data processed: Content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status); Event Data (Facebook) ("Event Data" means data that may be transmitted by us to Facebook, e.g. via the Facebook Pixel (via apps or by other means), and that relates to persons or their actions; the data includes, for example, information about visits to websites, interactions with content, functions, app installations, purchases of products, etc.; the Event Data is processed for the purpose of creating target groups for content and advertising information (Custom Audiences); Event Data does not include the actual content (such as comments written), login information or contact information (i.e. no names, e-mail addresses or telephone numbers). Event Data is deleted by Facebook after a maximum of two years, and the target groups created from it when our Facebook account is deleted); contact information (Facebook) ("Contact information" means data that (clearly) identifies data subjects, such as names, e-mail addresses and telephone numbers, which may be transmitted to Facebook, e.g. via the Facebook Pixel or by uploading data for matching purposes in order to create Custom Audiences. After matching for the purpose of creating target groups, the contact information is deleted).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest- or behavior-based profiling, use of cookies); conversion measurement (measuring the effectiveness of marketing measures); target group creation; marketing; profiles with user-related information (creating user profiles); provision of our online offering and user-friendliness. Remarketing.
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO). Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).
  • Right to object (opt-out): We refer to the privacy notices of the respective providers and the opt-out options specified for the providers (so-called "opt-outs"). If no explicit opt-out option has been specified, you can disable cookies in your browser settings. However, this may restrict the functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered collectively for the respective areas:<br><br>a) Europe: https://www.youronlinechoices.eu.<br>b) Canada: https://www.youradchoices.ca/choices.<br>c) USA: https://www.aboutads.info/choices.<br>d) Cross-territorial: https://optout.aboutads.info.

Further information on processing operations, procedures and services:

  • Meta Pixel and target group creation (Custom Audiences): With the help of the Meta Pixel (or comparable functions for transmitting Event Data or contact information by means of interfaces in apps), the company Meta can, on the one hand, determine visitors to our online offering as a target group for the presentation of advertisements (so-called "Meta Ads"). Accordingly, we use the Meta Pixel to display the Meta Ads placed by us only to users on Meta's platforms and within the services of partners cooperating with Meta (the so-called "Audience Network" https://www.facebook.com/audiencenetwork/) who have also shown an interest in our online offering or who have certain characteristics (e.g. an interest in certain topics or products apparent from the websites visited) that we transmit to Meta (so-called "Custom Audiences"). With the help of the Meta Pixel, we also want to ensure that our Meta Ads correspond to users' potential interests and are not intrusive. With the help of the Meta Pixel, we can also track the effectiveness of the Meta Ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta Ad (so-called "conversion measurement"); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Further information: Users' Event Data, i.e. behavioral and interest-related information, is processed for the purposes of targeted advertising and target group creation on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Advanced matching for the Meta Pixel: In addition to the processing of Event Data in the context of using the Meta Pixel (or comparable functions, e.g. in apps), contact information (data identifying individual persons, such as names, e-mail addresses and telephone numbers) is also collected by Meta within our online offering or transmitted to Meta. The processing of contact information serves to create target groups (so-called "Custom Audiences") for the presentation of content and advertising information oriented toward users' presumed interests. The collection or transmission and matching with data held by Meta do not take place in cleartext, but as so-called "hash values", i.e. mathematical representations of the data (this method is used, for example, when storing passwords). After matching for the purpose of creating target groups, the contact information is deleted; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Privacy policy: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum). Further information: https://www.facebook.com/legal/terms/data_security_terms.
  • Meta – target group creation via data upload: Creation of target groups for marketing purposes – We transmit contact information (names, e-mail addresses and telephone numbers) to Meta in list form for the purpose of creating target groups (so-called "Custom Audiences") for the presentation of content and advertising information oriented toward users' presumed interests. The transmission and matching with data held by Meta do not take place in cleartext, but as so-called "hash values", i.e. mathematical representations of the data (this method is used, for example, when storing passwords). After matching for the purpose of creating target groups, the contact information is deleted; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing. Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
  • Facebook Ads: Placement of advertisements within the Facebook platform and evaluation of the advertising results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Right to object (opt-out): We refer to the privacy and advertising settings in users' profiles on the Facebook platforms, as well as Facebook's consent procedures and contact options for exercising rights of access and other data subject rights, as described in Facebook's privacy policy; Further information: Users' Event Data, i.e. behavioral and interest-related information, is processed for the purposes of targeted advertising and target group creation on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Google Ad Manager: We use the "Google Ad Manager" service to place advertisements in the Google advertising network (e.g. in search results, in videos, on websites, etc.). Google Ad Manager is characterized by the fact that advertisements are displayed in real time based on users' presumed interests. This allows us to display advertisements for our online offering to users who may have a potential interest in our offering or who have previously been interested in it, and to measure the success of the advertisements; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/; Data processing terms for Google advertising products: information on the services, data processing terms between controllers and standard contractual clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms; if Google acts as a processor, data processing terms for Google advertising products and standard contractual clauses for transfers of data to third countries: https://business.safety.google/adsprocessorterms.
  • Google Ads and conversion measurement: Online marketing procedure for the purpose of placing content and advertisements within the service provider's advertising network (e.g. in search results, in videos, on websites, etc.), so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether users took them as an occasion to interact with the advertisements and use the advertised offers (so-called conversion). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms.
  • Google Ads Remarketing: Google Remarketing, also called retargeting, is a technology whereby users who use an online service are added to a pseudonymous remarketing list, so that advertisements can be displayed to users on other online offerings based on their visit to the online service; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms.
  • Enhanced conversions for Google Ads: If customers click on our Google advertisements and subsequently use the advertised service (so-called "conversion"), the data entered by the user, such as the e-mail address, name, home address or telephone number, may be transmitted to Google. The hash values are then matched with existing Google accounts of users in order to better evaluate and improve users' interaction with the advertisements (e.g. clicks or views) and thus their performance; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO). Website: https://support.google.com/google-ads/answer/9888656.
  • Google Adsense with personalized ads: We use the Google Adsense service with personalized ads, with the help of which advertisements are displayed within our online offering and we receive remuneration for their display or other use; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: information on the services, data processing terms between controllers and standard contractual clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms.
  • Google Adsense with non-personalized ads: We use the Google Adsense service with non-personalized ads, with the help of which advertisements are displayed within our online offering and we receive remuneration for their display or other use; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Google Ads Controller-Controller Data Protection Terms and standard contractual clauses for data transfers to third countries: https://business.safety.google/adscontrollerterms.
  • Instagram Ads: Placement of advertisements within the Instagram platform and evaluation of the advertising results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO); Website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Right to object (opt-out): We refer to the privacy and advertising settings in users' profiles on the Instagram platform, as well as Instagram's consent procedures and Instagram's contact options for exercising rights of access and other data subject rights in Instagram's privacy policy; Further information: Users' Event Data, i.e. behavioral and interest-related information, is processed for the purposes of targeted advertising and target group creation on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Microsoft Advertising: Online marketing procedure for the purpose of placing content and advertisements within the service provider's advertising network (e.g. in search results, in videos, on websites, etc.), so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether users took them as an occasion to interact with the advertisements and use the advertised offers (so-called conversion). However, we only receive anonymous information and no personal information about individual users; Service provider: Microsoft Irland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Irland; Legal bases: Consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO), legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://about.ads.microsoft.com/en-us; Privacy policy: https://privacy.microsoft.com/de-de/privacystatement; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Right to object (opt-out): https://account.microsoft.com/privacy/ad-settings/. Further information: https://about.ads.microsoft.com/de-de/policies/legal-privacy-and-security.

Customer reviews and rating procedures

We participate in review and rating procedures in order to evaluate, optimize and promote our services. If users rate us via the participating rating platforms or procedures or otherwise provide feedback, the providers' General Terms and Conditions or Terms of Use and privacy notices also apply. As a rule, the rating also requires registration with the respective providers.

To ensure that the persons submitting ratings have actually used our services, with the customers' consent we transmit the data required for this purpose concerning the customer and the service used to the respective rating platform (including name, e-mail address and order number or article number). This data is used solely to verify the authenticity of the user.

  • Data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status).
  • Data subjects: Customers; users (e.g. website visitors, users of online services).
  • Purposes of processing: Feedback (e.g. collecting feedback via an online form). Marketing.
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Further information on processing operations, procedures and services:

  • Rating widget: We integrate so-called "rating widgets" into our online offering. A widget is a functional and content element integrated into our online offering that displays changeable information. It may, for example, be displayed in the form of a seal or comparable element, sometimes also called a "badge". The corresponding content of the widget is displayed within our online offering, but at that moment it is retrieved from the servers of the respective widget provider. This is the only way to always display the current content, especially the current rating. For this purpose, a data connection must be established from the website accessed within our online offering to the server of the widget provider, and the widget provider receives certain technical data (access data, including the IP address) that is necessary for the widget content to be delivered to the user's browser. The widget provider also receives information that users have visited our online offering. This information may be stored in a cookie and used by the widget provider to identify which online offerings participating in the rating procedure the user has visited. The information may be stored in a user profile and used for advertising or market research purposes; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).
  • Google Customer Reviews: Service for obtaining and/or displaying customer satisfaction and customer opinions; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF); Further information: As part of obtaining customer reviews, an identification number and the time of the business transaction to be reviewed are processed; in the case of review requests sent directly to customers, the customer's e-mail address and their indication of the country of residence, as well as the review information itself, are processed; further information on the types of processing and the data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products: information on the services, data processing terms between controllers and standard contractual clauses for transfers of data to third countries: https://business.safety.google/adscontrollerterms.
  • Judge.me: We use Judge.me to collect, verify and display product and shop reviews. In this context, in particular, name, email address, order and product data, the content of the review and technical usage data may be processed. Judge.me processes customer data as our processor in the context of the review function; when directly using Judge.me’s own services, Judge.me may be the controller. Service provider: Judge.me Ltd, c/o Buckworths, 2nd Floor, 1-3 Worship Street, London EC2A 2AB, United Kingdom; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 Abs. 1 S. 1 lit. b) DSGVO), consent (Art. 6 Abs. 1 S. 1 lit. a) DSGVO), legitimate interests in quality assurance and the authentic presentation of customer reviews (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://judge.me; Privacy policy: https://judge.me/privacy; Further information: Data processing agreement.

Presences on social networks (social media)

We maintain online presences within social networks and process users' data in this context in order to communicate with users active there or to provide information about us.

We would like to point out that users' data may be processed outside the European Union in this context. This may create risks for users, because, for example, it could make it more difficult to enforce users' rights.

Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users' usage behavior and the resulting interests. The usage profiles may in turn be used to place advertisements within and outside the networks that presumably correspond to users' interests. For these purposes, cookies are generally stored on users' computers, in which users' usage behavior and interests are stored. In addition, data may be stored in the usage profiles independently of the devices used by users (in particular if users are members of the respective platforms and are logged in to them).

For a detailed presentation of the respective forms of processing and opt-out options, please refer to the privacy policies and information provided by the operators of the respective networks.

Also in the case of requests for information and the assertion of data subject rights, we would like to point out that these can be asserted most effectively with the providers. Only the providers have access to users' data in each case and can take appropriate measures and provide information directly. If you nevertheless need assistance, you can contact us.

  • Data processed: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Contact requests and communication; feedback (e.g. collecting feedback via an online form). Marketing.
  • Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO).

Further information on processing operations, procedures and services:

  • Instagram: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy. Basis for transfers to third countries: EU-US Data Privacy Framework (DPF).
  • Facebook Pages: Profiles within the Facebook social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Further information: We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not the further processing) of data of visitors to our Facebook page (so-called "fan page"). This data includes information on the types of content users view or interact with, or actions they take (see under "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see under "Device information" in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information to provide analytics services, so-called "Page Insights", for page operators, so that they can gain insights into how people interact with their pages and the content associated with them. We have concluded a special agreement with Facebook ("Information on Page Insights", https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfill data subject rights (i.e. users can submit requests for information or deletion directly to Facebook, for example). Users' rights (in particular to access, deletion, objection and lodging a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the "Information on Page Insights" (https://www.facebook.com/legal/terms/information_about_page_insights_data). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transmission of the data to the parent company Meta Platforms, Inc. in the USA.
  • Facebook Groups: We use the "Groups" function of the Facebook platform to create interest groups within which Facebook users can contact each other or us and exchange information. In this context, we process users' personal data in our groups insofar as this is necessary for the purpose of using and moderating the groups. Our guidelines within the groups may contain further requirements and information on the use of the respective group. This data includes information on first and last names, published or privately communicated content, as well as values relating to group membership status or group-related activities, such as joining or leaving, and the time details relating to the aforementioned data. We also refer to Facebook's own processing of users' data. This data includes information on the types of content users view or interact with, or actions they take (see under "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/privacy/policy/), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see under "Device information" in the Facebook Data Policy: https://www.facebook.com/privacy/policy/). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information to provide analytics services, so-called "Insights", for group operators, so that they can gain insights into how people interact with their groups and the content associated with them; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy. Basis for transfers to third countries: EU-US Data Privacy Framework (DPF).
  • Facebook Events: Event profiles within the Facebook social network – We use the "Events" function of the Facebook platform to draw attention to events and appointments, to contact users (participants and interested parties), and to exchange information. In this context, we process users' personal data on our event pages insofar as this is necessary for the purpose of the event page and its moderation. This data includes information on first and last names, published or privately communicated content, values relating to participation status, and the time details relating to the aforementioned data. We also refer to Facebook's own processing of users' data. This data includes information on the types of content users view or interact with, or actions they take (see under "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see under "Device information" in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information to provide analytics services, so-called "Insights", for event operators, so that they can gain insights into how people interact with their event pages and the content associated with them; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy. Basis for transfers to third countries: EU-US Data Privacy Framework (DPF).
  • Pinterest: Social network; Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Website: https://www.pinterest.com. Privacy policy: https://policy.pinterest.com/de/privacy-policy.
  • YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Legitimate interests (Art. 6 Abs. 1 S. 1 lit. f) DSGVO); Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: EU-US Data Privacy Framework (DPF). Right to object (opt-out): https://myadcenter.google.com/personalizationoff.

Plugins and Embedded Functions and Content

We incorporate function and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos or city maps (hereinafter uniformly referred to as “content”).

The integration always requires the third-party providers of this content to process the users’ IP address, since without the IP address they could not send the content to their browsers. The IP address is therefore required for the presentation of this content or these functions. We make every effort to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the users’ devices and may include, among other things, technical information about the browser and operating system, referring websites, the time of the visit and other information on the use of our online offering, as well as be combined with such information from other sources.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, consent status); inventory data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); location data (information on the geographical position of a device or a person); event data (Facebook) (“Event Data” means data that may be transmitted by us to Facebook, e.g. via the Facebook Pixel (via apps or in other ways), and that relates to persons or their actions; the data includes, for example, information about visits to websites, interactions with content, functions, app installations, purchases of products, etc.; the event data is processed for the purpose of creating audiences for content and advertising information (Custom Audiences); Event Data does not include the actual content (such as comments written), login information or contact information (i.e. no names, email addresses or telephone numbers). Event Data is deleted by Facebook after a maximum of two years, and the audiences created from it are deleted when our Facebook account is deleted).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and user-friendliness; provision of contractual services and fulfillment of contractual obligations; marketing. Profiles with user-related information (creation of user profiles).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing operations, procedures and services:

  • Integration of third-party software, scripts or frameworks (e.g. jQuery): We integrate software into our online offering that we retrieve from the servers of other providers (e.g. function libraries that we use for the presentation or user-friendliness of our online offering). In this process, the respective providers collect the users’ IP address and may process it for the purpose of transmitting the software to the users’ browsers, for security purposes, and for evaluating and optimizing their offering. - We integrate software into our online offering that we retrieve from the servers of other providers (e.g. function libraries that we use for the presentation or user-friendliness of our online offering). In this process, the respective providers collect the users’ IP address and may process it for the purpose of transmitting the software to the users’ browsers, for security purposes, and for evaluating and optimizing their offering; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Facebook plugins and content: Facebook social plugins and content - This may include, for example, content such as images, videos or texts and buttons with which users can share content from this online offering within Facebook. The list and appearance of the Facebook social plugins can be viewed here: https://developers.facebook.com/docs/plugins/ - Together with Meta Platforms Ireland Limited, we are jointly responsible for the collection or receipt in the context of a transmission (but not for further processing) of “Event Data” that Facebook collects by means of the Facebook social plugins (and embedding functions for content) that are operated on our online offering, or receives in the context of a transmission, for the following purposes: a) displaying content and advertising information that corresponds to the presumed interests of users; b) delivering commercial and transactional messages (e.g. contacting users via Facebook Messenger); c) improving ad delivery and personalizing functions and content (e.g. improving the recognition of which content or advertising information presumably corresponds to users’ interests). We have concluded a special agreement with Facebook (“Controller Addendum”, https://www.facebook.com/legal/controller_addendum), which in particular regulates which security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfill data subject rights (i.e. users can, for example, send requests for information or deletion directly to Facebook). Note: If Facebook provides us with measurements, analyses and reports (which are aggregated, i.e. contain no information about individual users and are anonymous to us), this processing does not take place within the scope of joint responsibility, but on the basis of a data processing agreement (“Data Processing Terms”, https://www.facebook.com/legal/terms/dataprocessing), the “Data Security Terms” (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the USA, on the basis of standard contractual clauses (“Facebook-EU Data Transfer Addendum”, https://www.facebook.com/legal/EU_data_transfer_addendum). Users’ rights (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
  • Google Fonts (provision on own server): Provision of font files for user-friendly presentation of our online offering; Service provider: Google Fonts are hosted on our server; no data is transmitted to Google; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Google Fonts (retrieval from Google server): Retrieval of fonts (and symbols) for the purpose of technically secure, maintenance-free and efficient use of fonts and symbols with regard to up-to-dateness and loading times, their uniform presentation and consideration of possible licensing restrictions. The user’s IP address is communicated to the font provider so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted that is necessary for providing the fonts depending on the devices used and the technical environment. This data may be processed on a server of the font provider in the USA - When visiting our online offering, users’ browsers send their browser HTTP requests to the Google Fonts Web API (i.e. a software interface for retrieving the fonts). The Google Fonts Web API provides users with Google Fonts’ Cascading Style Sheets (CSS) and then with the fonts specified in the CCS. These HTTP requests include (1) the IP address used by the respective user to access the Internet, (2) the URL requested on the Google server and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of website visitors, as well as the referring URL (i.e. the website on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers and are not analyzed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user agent and referring URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families that the user wants to load. This data is logged so that Google can determine how often a particular font family is requested. In the Google Fonts Web API, the user agent must adapt the font generated for the respective browser type. The user agent is primarily logged for debugging and used to generate aggregated usage statistics with which the popularity of font families is measured. These aggregated usage statistics are published on the “Analytics” page of Google Fonts. Finally, the referring URL is logged so that the data can be used for production maintenance and an aggregated report on the top integrations based on the number of font requests can be generated. According to its own information, Google does not use any of the information collected by Google Fonts to create profiles of end users or serve targeted ads; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://fonts.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF). Further information: https://developers.google.com/fonts/faq/privacy?hl=de.
  • Google Maps: We integrate the maps of the “Google Maps” service provided by Google. The data processed may include, in particular, users’ IP addresses and location data; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).
  • Instagram plugins and content: Instagram plugins and content - This may include, for example, content such as images, videos or texts and buttons with which users can share content from this online offering within Instagram. - Together with Meta Platforms Ireland Limited, we are jointly responsible for the collection or receipt in the context of a transmission (but not for further processing) of “Event Data” that Facebook collects by means of Instagram functions (e.g. embedding functions for content) that are operated on our online offering, or receives in the context of a transmission, for the following purposes: a) displaying content and advertising information that corresponds to the presumed interests of users; b) delivering commercial and transactional messages (e.g. contacting users via Facebook Messenger); c) improving ad delivery and personalizing functions and content (e.g. improving the recognition of which content or advertising information presumably corresponds to users’ interests). We have concluded a special agreement with Facebook (“Controller Addendum”, https://www.facebook.com/legal/controller_addendum), which in particular regulates which security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfill data subject rights (i.e. users can, for example, send requests for information or deletion directly to Facebook). Note: If Facebook provides us with measurements, analyses and reports (which are aggregated, i.e. contain no information about individual users and are anonymous to us), this processing does not take place within the scope of joint responsibility, but on the basis of a data processing agreement (“Data Processing Terms”, https://www.facebook.com/legal/terms/dataprocessing), the “Data Security Terms” (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the USA, on the basis of standard contractual clauses (“Facebook-EU Data Transfer Addendum”, https://www.facebook.com/legal/EU_data_transfer_addendum). Users’ rights (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.instagram.com. Privacy policy: https://instagram.com/about/legal/privacy/.
  • Pinterest plugins and content: Pinterest plugins and content - This may include, for example, content such as images, videos or texts and buttons with which users can share content from this online offering within Pinterest; Service provider: Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.pinterest.com. Privacy policy: https://policy.pinterest.com/de/privacy-policy.
  • reCAPTCHA: We integrate the “reCAPTCHA” function in order to be able to recognize whether entries (e.g. in online forms) are made by humans and not by automatically operating machines (so-called “bots”). The data processed may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, time spent on websites, previously visited websites, interactions with ReCaptcha on other websites, cookies in some cases, as well as results of manual detection procedures (e.g. answering questions asked or selecting objects in images). The data processing is based on our legitimate interest in protecting our online offering against abusive automated crawling and spam; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.google.com/recaptcha/; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertising: https://myadcenter.google.com/personalizationoff.
  • YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertising: https://myadcenter.google.com/personalizationoff.
  • YouTube videos: Video content; YouTube videos are embedded via a special domain (recognizable by the component “youtube-nocookie”) in the so-called “enhanced privacy mode”, whereby no cookies relating to user activities are collected in order to personalize video playback. Nevertheless, information on users’ interaction with the video (e.g. remembering the last playback position) may be stored; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy. Basis for third-country transfer: EU-US Data Privacy Framework (DPF).

Amendment and Updating of the Privacy Policy

We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.

If we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and check the information before contacting them.

Definitions

In this section, you will find an overview of the terminology used in this privacy policy. To the extent that the terminology is legally defined, its legal definitions apply. The explanations below, on the other hand, are intended primarily to aid understanding.

  • Credit report: Automated decisions are based on automated data processing without human intervention (e.g. in the case of an automatic rejection of a purchase on account, an online credit application or an online application process without any human intervention). Such automated decisions are only permissible under Art. 22 GDPR if data subjects consent, if they are necessary for the performance of a contract or if national laws permit these decisions.
  • Content Delivery Network (CDN): A “Content Delivery Network” (CDN) is a service that can be used to deliver the content of an online offering, in particular large media files such as graphics or program scripts, more quickly and securely with the help of regionally distributed servers connected via the Internet.
  • Conversion measurement: Conversion measurement (also referred to as “visit action analysis”) is a method for determining the effectiveness of marketing measures. For this purpose, a cookie is generally stored on users’ devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, this enables us to determine whether the advertisements we place on other websites were successful.
  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more special characteristics that express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles with user-related information: The processing of “profiles with user-related information”, or “profiles” for short, includes any kind of automated processing of personal data consisting of using this personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include different information concerning demographics, behavior and interests, such as interaction with websites and their content, etc.) (e.g. interest in certain content or products, click behavior on a website or location). Cookies and web beacons are often used for profiling purposes.
  • Reach measurement: Reach measurement (also known as web analytics) is used to analyze the visitor flows of an online offering and may include the behavior or interests of visitors in relation to certain information, such as website content. With the help of reach analysis, operators of online offerings can, for example, identify when users visit their websites and which content they are interested in. This enables them, for example, to better adapt the content of websites to the needs of their visitors. Pseudonymous cookies and web beacons are often used for reach analysis purposes in order to recognize returning visitors and thus obtain more accurate analyses of the use of an online offering.
  • Remarketing: “Remarketing” or “retargeting” refers to noting, for example for advertising purposes, which products a user has shown interest in on a website in order to remind the user of these products on other websites, e.g. in advertisements.
  • Location data: Location data is generated when a mobile device (or another device with the technical requirements for determining a location) connects to a mobile cell, a WLAN or similar technical means and functions for determining location. Location data indicates the geographically determinable position on Earth at which the respective device is located. Location data can be used, for example, to display map functions or other information dependent on a location.
  • Tracking: “Tracking” refers to following users’ behavior across several online offerings. As a rule, behavioral and interest information relating to the online offerings used is stored in cookies or on the servers of the providers of tracking technologies (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
  • Controller: “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: “Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether collecting, evaluating, storing, transmitting or deleting it.
  • Audience creation: “Audience creation” (in English “Custom Audiences”) refers to determining audiences for advertising purposes, e.g. displaying advertisements. For example, based on a user’s interest in certain products or topics on the Internet, it may be inferred that this user is interested in advertisements for similar products or the online shop in which they viewed the products. “Lookalike Audiences” (or similar audiences), in turn, refers to displaying content assessed as suitable to users whose profiles or interests presumably correspond to those of the users for whom the profiles were created. Cookies and web beacons are generally used for the creation of Custom Audiences and Lookalike Audiences.