Privacy policy

Privacy Policy

We are delighted that you are visiting our website. The protection and security of your personal information whilst using our website is very important to us. We would therefore like to take this opportunity to inform you about which of your personal data we collect when you visit our website and for what purposes this data is used. Personal data refers to specific details relating to the personal or factual circumstances of an identified or identifiable natural person (data subject), e.g. name, address, email addresses, user behaviour. This is therefore data that enables us to identify you. In addition, you will also find some information here regarding data processing activities outside this website (e.g. video conferences or newsletters).

Responsible for data processing

Data controller

For the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)

Cellavent Healthcare GmbH

Am Trippelsberg 43

40589 Düsseldorf

Telephone: 02 11/78 17 69 8-0

Email:info@callavent.com

Data Protection Officer

exkulpa gmbh

Waldfeuchterstr. 266

52525 Heinsberg

Telephone: 02452 / 99 33 11

Email: datenschutz@callavent.com

General information

In addition to the data you actively provide to us on this page (e.g. via our contact form), we collect certain technical data. This so-called metadata is automatically transmitted from your computer to our servers as soon as you access our website (including browser, operating system and timestamp). We use this data to ensure our website is displayed correctly. In addition, we may collect data via integrated third-party providers (e.g. for external media such as map services or analytics tools). We explain the specific purposes and legal bases for this in the course of this privacy policy.

Retention period

Unless a specific retention period is stated within this privacy policy, we will retain your personal data for as long as the purpose of the data processing remains valid. If you submit a valid request for erasure or withdraw your consent, we will erase your data. Statutory retention obligations remain unaffected.

Legal bases for data processing

If you have consented to data processing, the processing of your personal data is carried out on the basis of Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, where special categories of data are processed in accordance with Article 9(1) of the GDPR. Where you have given your explicit consent to the transfer of personal data to third countries, the data is also processed in accordance with Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. through device fingerprinting), data processing also takes place on the basis of Section 25(1) of the TDDDG. You may withdraw your consent at any time. Where your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data in accordance with Article 6(1)(b) of the GDPR. Furthermore, we process your data where this is necessary to comply with a legal obligation, on the basis of Article 6(1)(c) of the GDPR. Data processing may also take place on the basis of our legitimate interest in accordance with Article 6(1)(f) of the GDPR. The following sections of this privacy policy provide information on the respective legal bases in individual cases.

Note on data transfers to third countries and US companies without DPF certification

Please note that we use tools provided by companies based in third countries where data protection standards are not adequate or in the USA, and which are not covered by the EU-US Data Protection Framework (DPF). When using these tools, your personal data may be transferred to and processed in these countries. Please note that in these third countries, a level of data protection comparable to that of the EU cannot be guaranteed.

We would like to clarify that the US generally offers a level of data protection comparable to that of the EU. The transfer of data to the US is permitted if the recipient holds DPF certification or provides appropriate additional safeguards. Information on data transfers to third countries, including data recipients, can be found in our Privacy Policy.

Automated decision-making

Your personal data is not processed for the purposes of automated decision-making.

Your rights

As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access: You have the right to request confirmation from us as to whether your personal data is being processed and, if so, to receive further information about the processing and copies of the data being processed (Art. 15 GDPR).

  • Right to rectification: You have the right to request the immediate rectification of any inaccurate personal data concerning you and, where applicable, the completion of any incomplete personal data (Article 16 of the GDPR).

  • Right to erasure: You have the right to request the erasure without undue delay of personal data concerning you where the legal conditions are met, in particular where the data is no longer necessary for the purposes for which it was collected and the processing is unlawful (Article 17 of the GDPR).

  • Right to restriction of processing: You have the right to request that we restrict the processing of your personal data where the legal conditions are met, in particular where you contest the accuracy of the data, the processing is unlawful and you object to erasure (Article 18 of the GDPR).

  • Right to data portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided this is technically feasible (Article 20 of the GDPR).

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, where the processing is carried out on the basis of Article 6(1)(e) or (f) of the GDPR (Article 21 of the GDPR).

  • Right to withdraw consent: You have the right to withdraw your consent to the processing of personal data at any time with effect for the future. Withdrawal of your consent does not affect the lawfulness of processing carried out on the basis of your consent prior to its withdrawal (Article 7(3) of the GDPR).

  • Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR (Article 77 of the GDPR).

Further data processing operations

General information obligations

This information is intended for customers, prospective customers, suppliers and employees. We process your personal data for the following purposes:

  • To fulfil our contractual obligations towards you (Article 6(1)(b) of the GDPR).

  • To carry out pre-contractual obligations (Article 6(1)(b) of the GDPR).

  • To respond to enquiries (Article 6(1)(b) of the GDPR).

  • Where you have given us your consent to process your personal data for specific purposes (such as to receive our newsletter), data processing takes place on the basis of your consent (Article 6(1)(a) of the GDPR).

  • To comply with legal obligations to which our company is subject (Article 6(1)(c) of the GDPR).

  • Where necessary, we also process your data to safeguard our legitimate interests, in particular to assert legal claims and defend ourselves in legal disputes, or to ensure IT security; to consult credit reference agencies and exchange data with them in order to assess creditworthiness and default risks; for direct marketing and market research, provided you have not objected to the use of your data for this purpose; in connection with measures relating to business management and the further development of services and products; in connection with measures relating to product and sales optimisation; in connection with risk management measures; and for the prevention or investigation of criminal offences (Article 6(1)(f) of the GDPR).

Categories of recipients of personal data

Within our company, only those employees who absolutely need the data to perform their duties have access to it (need-to-know principle). Individual processes and services are carried out by carefully selected service providers, commissioned in accordance with data protection regulations, who are based within the EEA. Where service providers commissioned by us gain access to personal data whilst performing their services, data processing agreements have been concluded with them in accordance with Article 28(3) of the GDPR.

Duration of data retention

The data we process is stored for the duration of the contractual relationship and its fulfilment, whilst complying with statutory retention periods. These include, in particular, retention obligations under commercial and tax law as set out in the German Commercial Code (HGB) and the German Fiscal Code (AO). The standard retention and documentation periods amount to up to ten years. If no contractual relationship is established, we process the data only for as long as required for the specific purpose.

Cookies

Cookies are small text files stored by your browser on your device to retain certain information whilst you are using the website. Cookies enable us to improve various aspects of our website and make your visit more convenient.

There are various types of cookies, each serving different purposes. Temporary cookies, also known as session cookies, are stored only for the duration of your use of the website and are automatically deleted when you close your browser. Persistent cookies, on the other hand, remain stored on your device for a longer period and enable us to recognise you and your preferences when you visit the website again.

Cookies can also be categorised as first-party cookies and third-party cookies. First-party cookies are set by our website, whilst third-party cookies are set by other websites or service providers whose content is integrated into our website, such as plugins or analytics tools.

Cookies are used for various purposes, such as ensuring the website functions properly, storing user settings, compiling anonymous statistics on user behaviour, or displaying personalised content and advertising. The legal basis for the use of cookies varies depending on the purpose of the cookies. In some cases, the setting of cookies is based on your legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to make our website functional and user-friendly. As the website operator, we have a legitimate interest in storing necessary cookies to ensure the technically flawless and optimised provision of our services. Where we seek your consent to the use of cookies, processing is carried out on the basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You may withdraw your consent at any time.

Cookie consent with Usercentrics

Nature and scope of processing

We use Usercentrics’ consent technology to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document this in accordance with data protection regulations. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich (hereinafter ‘Usercentrics’).

When you visit our website, the following personal data is transmitted to Usercentrics:

  • Your consent(s) or the withdrawal of your consent(s)

  • Your IP address

  • Information about your browser

  • Information about your device

  • The time of your visit to the website

In order to be able to record and document your consent or withdrawal of consent, the provider sets a cookie in your browser. This data is stored until you delete the cookie, request that we delete the data, or the purpose for which the data is processed no longer applies. Statutory retention obligations remain unaffected.

Usercentrics is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Article 6(1)(c) of the GDPR.

Data processing on behalf of a controller

To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.

Data processing in detail

Below, we provide information on the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data and the respective retention period. No automated decision-making, including profiling, takes place in individual cases.

Provision of the website

When you access and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:

  • IP address of the requesting computer

  • Date and time of access

  • Name and URL of the file accessed

  • Website from which the access originated (referrer URL)

  • Browser used and, where applicable, your computer’s operating system, as well as the name of your internet service provider

Our website is not hosted by us directly, but by a service provider who processes the aforementioned data on our behalf in accordance with Article 28 of the GDPR for the purpose of providing the website.

The use of the hosting provider is for the purpose of fulfilling our contractual obligations towards our potential and existing customers (Article 6(1)(b) of the GDPR) and in the interest of ensuring the secure, fast and efficient provision of our online services by a professional provider (Article 6(1)(f) of the GDPR).

Contact form

Nature and scope of processing

If you send us enquiries (e.g. via the contact form, by email or by telephone), we store all data arising from this (e.g. name, email address, subject of the enquiry, etc.). We require this data to process your enquiry and to be able to answer any follow-up questions. We do not pass on this data without your consent.

Purpose and legal basis

The processing of this data is based on Article 6(1)(b) of the GDPR, provided that your enquiry relates to the performance of a contract or is necessary for the implementation of pre-contractual measures. Otherwise, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) of the GDPR) or on your consent (Article 6(1)(a) of the GDPR) if you have previously given it.

Retention period

The data you enter in the contact form will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been fully processed). Mandatory legal provisions – in particular retention periods – remain unaffected.

Live chat and customer service via Gorgias

Provider

We use the Gorgias chat and customer service tool on our website. The provider is Gorgias Inc., 180 Sansome Street, Suite 1800, San Francisco, CA 94104, USA.

Nature and scope of data processing

When you visit our website, the chat widget is loaded from Gorgias’ servers. In doing so, your IP address is transmitted to Gorgias. In addition, information may be stored on your device (e.g. cookies or local storage) in order to associate the chat history and ensure the widget functions correctly.

If you use the chat function or contact us via Gorgias by other means, the data you provide will be processed, in particular your name, email address, the content of your messages, and the date and time of the communication. In order to process your enquiry, Gorgias may also access your order details from our shop system. The data will be used exclusively for the purpose of processing your enquiry.

Legal basis

The legal basis for loading the chat widget, accessing your device and processing the data you transmit via the chat is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time with future effect by accessing the cookie settings via the ‘Cookie Settings’ link in the footer and adjusting your selection. The lawfulness of the data processing carried out up to the point of withdrawal remains unaffected by the withdrawal.

Data processing on behalf of others and data transfers to third countries

We have entered into a data processing agreement with Gorgias in accordance with Article 28 of the GDPR. As data may be transferred to the USA, the transfer is carried out on the basis of the EU Commission’s Standard Contractual Clauses in accordance with Article 46(2)(c) of the GDPR.

Retention period

Your data will be deleted as soon as your enquiry has been fully processed and provided there are no statutory retention obligations to the contrary.

Further information

Further information can be found in Gorgias’ privacy policy: https://www.gorgias.com/legal/privacy

Contact form for applicants

Nature and scope of processing

We collect and process the personal data of job applicants. Such data processing may also take place electronically, for example, when applicants submit their application documents to us by email or via a web form on our website. On our website, we offer you the option of submitting applications for advertised vacancies to us by email.

Purpose and legal basis

We process applicants’ personal data in accordance with legal requirements for the purpose of establishing an employment relationship (Article 6(1)(b) of the GDPR). You are not obliged to provide us with this data. However, without this data, we cannot carry out an application process with you.

If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Article 6(1)(b) of the GDPR and, insofar as you provide us with special categories of personal data, such as health information, on the basis of Article 9(2)(b) for the purpose of carrying out the employment relationship.

We also use the professional networking services LinkedIn and XING to approach potential candidates. In this regard, the operators of these networks act on our behalf as data processors in accordance with our instructions. The legal basis for data processing when approaching potential candidates on our behalf is Article 6(1)(f) of the GDPR (our legitimate interests). If, as a result of such contact, you send us your application, we will process your data for the purpose of establishing an employment relationship as described above, on the basis of Article 6(1)(b) of the GDPR.

Retention period

In the event of a rejection, your data will be stored for a period of 6 months following the conclusion of the application process. This is done to safeguard our legitimate interests, in order to assess whether we require the data to defend against any potential claims arising in connection with the application process. We are then obliged to delete or anonymise your data. In this case, the data will only be available to us as so-called metadata without any direct personal reference for statistical analysis (for example, the proportion of female and male applicants, the number of applications per period, etc.).

Where it is apparent that further storage of the data is necessary after the expiry of the six-month period to safeguard our legitimate interests (e.g. due to an impending or pending legal dispute), the data will only be deleted once the purpose for its continued retention no longer applies. The legal basis for this further data retention is our legitimate interests in the assertion, exercise or defence of civil law claims (Article 6(1)(f) of the GDPR in conjunction with Section 24(1)(2) of the BDSG or, where special categories of personal data are stored, Article 9(2)(f) of the GDPR in conjunction with Section 24(2) of the BDSG).

Inclusion in the candidate pool

As part of the application process, we offer applicants the opportunity to be included in our ‘talent pool’ for a period of 24 months on the basis of consent within the meaning of Article 6(1)(a) and Article 9(2)(a) of the GDPR. If you have provided special categories of personal data in your application, such as health information, your consent also extends to this data. You are not obliged to provide us with your application data for our talent pool. However, without this data, we cannot consider you for future vacancies unless you submit a new application.

Consent to the inclusion of application data in the Talent Pool is voluntary and may be withdrawn at any time with future effect. Withdrawal of consent does not affect the lawfulness of any data processing carried out on the basis of that consent prior to its withdrawal.

Your application documents will be deleted from the talent pool at the latest upon expiry of the retention period, or in the event of a withdrawal of consent or the acceptance of a job offer from one of the companies responsible for the talent pool.

If, as part of the application process, you receive and accept an offer of employment with us, we or the relevant company will store the personal data collected during the application process for the purpose of managing the employment relationship. The legal basis for this data processing is Article 6(1)(b) of the GDPR or, insofar as you provide us with special categories of personal data, such as health information, Article 9(2)(b).

Newsletter

We offer our newsletter on this website. If you wish to subscribe to it, we require your email address and further information to verify that the email address belongs to you and that you consent to receiving the newsletter. No other personal data is collected unless you provide it voluntarily (e.g. name, telephone number, place of residence, etc.).

When processing the data you provide when signing up for the newsletter, we rely exclusively on your consent under Article 6(1)(a) of the GDPR as the legal basis. You may withdraw your consent to the processing and storage of your personal data at any time (e.g. via the ‘Unsubscribe’ link in the newsletter) with effect for the future.

We store the personal data you have provided for the purpose of receiving the newsletter until you unsubscribe from the newsletter via us or the mailing service provider. This does not apply to data we have stored about you for other purposes.

If you unsubscribe from the newsletter mailing list, your email address will be stored by us or the mailing service provider on a blacklist for an indefinite period. This is done to prevent future mailings from being sent to you. The data on the blacklist is used exclusively for this purpose and is not combined with any other data. This is not only in your interest, but also in our legitimate interest under Article 6(1)(f) of the GDPR to fulfil our legal obligations regarding the sending of newsletters. You may object to this storage provided that your personal interests override our legitimate interest.

Registration of a customer account

Processing of customer and contract data

We collect, process and use your personal data only to the extent necessary for the establishment, amendment or fulfilment of a legal relationship. This is done for the purpose of fulfilling a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.

The customer data collected will be deleted once the order has been completed or the business relationship has ended. Statutory retention periods remain unaffected.

Data transfer upon conclusion of a contract for online shops, retailers and goods dispatch

We transfer personal data only where this is necessary for the purposes of contract fulfilment, for example to delivery service providers or the bank responsible for processing payments. No further transfer of data takes place, or only if you have expressly consented to such transfer.

The legal basis for data processing is the performance of a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.

Credit checks

In the case of a purchase on account or any other payment method where we make an advance payment, we or our payment service provider may carry out a credit check (scoring). To this end, we will pass on the details you have provided (e.g. name, address, age or bank details) to a credit reference agency. The likelihood of non-payment is determined on the basis of this information. If the risk of non-payment is deemed too high, we may refuse the payment method in question.

The legal basis for data processing is the performance of a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR, as well as the prevention of payment defaults (legitimate interest under Article 6(1)(f) of the GDPR). If you have previously given your consent to data processing at , the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; you may withdraw your consent at any time.

Payment services

We integrate third-party payment services into our website. When you make a purchase from us, your payment details (e.g. name, payment amount, bank account details, credit card number) are processed by the payment service provider for the purpose of processing the payment; the respective contractual and data protection provisions of the relevant providers apply. The legal basis for data processing is the performance of a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR, as well as the legitimate interest in ensuring a payment process that is as smooth, convenient and secure as possible (Article 6(1)(f) of the GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; you may withdraw your consent at any time.

We use the following payment service providers:

PayPal

The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg (hereinafter ‘PayPal’).

Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.

Please refer to PayPal’s privacy policy for further details: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

American Express

This payment service is provided by American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter “American Express”).

American Express may transfer data to its parent company in the USA. The transfer of data to the USA is based on the Binding Corporate Rules. Further details can be found here: https://www.americanexpress.com/en-iec/company/legal/privacy-centre/binding-corporate-rules/

For further information, please refer to the American Express Privacy Policy: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html.

Mastercard

The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter ‘Mastercard’).

Mastercard may transfer data to its parent company in the USA. The transfer of data to the USA is based on Mastercard’s Binding Corporate Rules. Further details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.

VISA

The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).

The United Kingdom is considered a safe third country for data protection purposes. This means that the United Kingdom has a level of data protection equivalent to that in the European Union.

VISA may transfer data to its parent company in the USA. The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.

For further information, please refer to VISA’s privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

Klarna

The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter “Klarna”). Klarna offers various payment options (e.g. payment in instalments). If you choose to pay via Klarna (Klarna Checkout solution), Klarna will collect various items of personal data from you. Klarna uses cookies to optimise the use of the Klarna checkout solution. For details on the use of Klarna cookies, please see the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.

You can find further details in Klarna’s privacy policy at the following link: https://www.klarna.com/de/datenschutz/.

Shop Pay

Nature and scope of processing

We have integrated Shop Pay components into our website. Shop Pay is a service provided by Shopify, Inc. and offers online payment solutions worldwide.

If you select Shop Pay as your payment method, the data required for the payment transaction will be automatically transmitted to Shopify, Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada.

In this context, the following data is generally collected: name, address, company (if applicable), email address, telephone and mobile numbers, and IP address.

Purpose and legal basis

Use of the service is based on the performance of a contract, i.e. for the processing of payment transactions in accordance with Article 6(1)(b) of the GDPR.

Retention period

We have no influence over the specific retention period for the processed data; this is determined by Shopify, Inc. Further information can be found in the Shop Pay privacy policy: https://www.shopify.com/legal/privacy.

Apple Pay

The provider of this payment service is Apple Distribution International Ltd., 40 Fortwilliam Crescent, Belfast, Northern Ireland, BT15 3RD (hereinafter ‘Apple’).

Apple may transfer data to its parent company (Apple Inc.) in the USA. The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses and the EU-US Data Privacy Framework.

For details and further information, please refer to Apple’s privacy policy: https://www.apple.com/legal/privacy/data/de/apple-pay/.

Bancontact

The provider of this payment service is Bancontact Payconiq Company NV/SA, Rue d’Arlon 82, 1040 Brussels, Belgium (hereinafter “Bancontact”).

As Belgium is a Member State of the European Union, the level of data protection complies with the strict requirements of the GDPR. By default, Bancontact does not transfer data to third countries outside the EEA, unless this is strictly necessary for the processing of the payment.

For details and further information, please refer to Bancontact’s privacy policy: https://www.bancontact.com/de/privacy-policy.

eps Bank Transfer

The provider of this payment service is PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria (hereinafter “eps”).

As Austria is a Member State of the European Union, the level of data protection complies with the strict requirements of the GDPR. By default, eps does not transfer data to third countries outside the EEA.

For details and further information, please refer to eps’s privacy policy: https://eps-ueberweisung.at/de/datenschutzhinweis.

iDEAL

The provider of this payment service is Currence iDEAL B.V., Gustav Mahlerplein 33-35, 1082 MS Amsterdam, Netherlands (hereinafter “iDEAL”).

As the Netherlands is a Member State of the European Union, the level of data protection complies with the strict requirements of the GDPR. By default, iDEAL does not transfer data to third countries outside the EEA.

For details and further information, please refer to iDEAL’s privacy policy: https://www.ideal.nl/en/privacy-cookie-statement/.

wero

The provider of this payment service is EPI Company SE, De Lignestraat 13, 1000 Brussels, Belgium (hereinafter “wero”).

As Belgium is a Member State of the European Union, the level of data protection complies with the strict requirements of the GDPR. By default, wero does not transfer data to third countries outside the EEA.

For details and further information, please refer to wero’s privacy policy: https://epicompany.eu/privacy-policy/.

UnionPay

The provider of this payment service is UnionPay International Co., Ltd., No. 1899 Guozhan Road, China (Shanghai) Pilot Free Trade Zone (hereinafter ‘UnionPay’). The branch in Germany responsible for the European market is UnionPay International Co., Ltd. Germany Branch, An der Welle 4, 60322 Frankfurt am Main.

UnionPay transfers data to its head office in the People’s Republic of China and to other branches worldwide. As the People’s Republic of China is regarded by the EU as a non-adequate third country, the data transfer is based on the EU Commission’s Standard Contractual Clauses to ensure an adequate level of data protection.

For details and further information, please refer to UnionPay’s privacy policy: https://m.unionpayintl.com/en/privacyNotice/.

Social media presence

We maintain public profiles on various social media platforms via our website. You can find more detailed information on the social media platforms we use in the relevant sections of our privacy policy.

Social networks such as Facebook, Twitter and others can analyse your user behaviour in detail when you visit their websites or a website featuring integrated social media content (e.g. ‘Like’ buttons or advertising banners). Visiting our social media pages triggers numerous data processing operations relevant to data protection:

If you are logged into your social media account and visit our social media presence, the operator of the social media portal may link this visit to your user account. However, your personal data may also be collected even if you are not logged in or do not have an account with the relevant social media portal. In this case, data is collected, for example, via cookies stored on your device or by recording your IP address.

Using the data collected in this way, the operators of the social media platforms can create user profiles that record your preferences and interests. This enables interest-based advertising to be displayed to you both on and off the respective social media platform. If you have an account with the relevant social network, interest-based advertising may be displayed on all devices on which you are logged in or have previously been logged in.

Please note that we are not able to track all data processing activities on social media platforms. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media platforms. For further details, please refer to the terms of use and privacy policies of the respective social media platforms.

Legal basis for data processing

Our social media presence serves to ensure the most comprehensive online presence possible. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The analysis processes initiated by the social networks may be based on different legal grounds, which must be specified by the operators of the social networks (e.g. consent within the meaning of Article 6(1)(a) of the GDPR).

Data controller and exercising rights

When you visit our social media pages (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both with us and with the operator of the relevant social media portal (e.g. with Facebook).

Despite our joint responsibility with the social media platform operators, we do not have full control over the data processing operations carried out by the social media platforms. Our options depend largely on the corporate policy of the respective provider.

Duration of data storage

Data collected directly by us via our social media presence will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.

We have no influence over the duration for which your data is stored by the operators of social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. via their privacy policy, see below).

Facebook page

Our company has a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter ‘Meta’). According to Meta, the data collected is also transferred to the USA and other third countries.

We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement sets out which data processing operations we and Meta are responsible for when you visit our Facebook page. You can view the agreement via the following link: https://www.facebook.com/legal/terms/page_controller_addendum.

You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

Data transfers to the US are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

For further information, please refer to Facebook’s privacy policy: https://www.facebook.com/about/privacy/.

Instagram page

Our company has a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381.

For further information on how your personal data is handled, please refer to Instagram’s privacy policy: https://help.instagram.com/519522125107875.

LinkedIn page

Our company has a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.

If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.

For further information on how your personal data is handled, please refer to LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.

YouTube

We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For details on how they handle your personal data, please refer to YouTube’s privacy policy: https://policies.google.com/privacy?hl=de.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the US which aims to ensure compliance with European data protection standards when processing data in the US. Certification under the DPF obliges companies to adhere to these data protection standards.

TikTok

Our company has a profile on TikTok. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. For further information on how your personal data is handled, please refer to TikTok’s privacy policy: https://www.tiktok.com/legal/privacy-policy?lang=de.

Data transfers to non-secure third countries are based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://www.tiktok.com/legal/privacy-policy?lang=de.

Video Conferences

Data processing

We use online conferencing tools to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference, your personal data is collected and processed by us and by the provider of the relevant tool.

The tools collect the data you provide, including your email address and telephone number. They also process the duration of the conference, when you joined the conference, the number of participants and other metadata.

In addition, the tool provider processes all technical data required to facilitate the conference. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.

If you share content via this service, it is stored on the providers’ servers. This includes cloud recordings, chat messages, voice messages, and any photos and videos you have shared whilst using this service.

Please note that we do not have full control over the data processing operations carried out by the tools used. For further details on data processing by the conferencing tools, please refer to the privacy policies of the respective tools used.

Purpose and legal basis

The conferencing tools are used to communicate with prospective or existing contractual partners or to offer specific services to our customers (Article 6(1)(b) of the GDPR). Furthermore, the use of these tools serves to generally simplify and speed up communication with us or our company (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; you may withdraw your consent at any time.

Retention period

Data collected directly by us via the video and conferencing tools will be deleted from our systems as soon as you request us to do so, withdraw your consent to storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected.

We have no influence over the retention period of your data stored by the operators of the conferencing tools for their own purposes. For further details, please contact the operators of the conferencing tools directly.

Contract withdrawal

For distance contracts for services and financial products concluded with consumers via our website, and for which a statutory right of withdrawal applies, we provide an electronic withdrawal button. This obligation is based on the implementation of the amended EU Consumer Rights Directive (EU 2023/2673) through the new Section 356a of the German Civil Code (BGB).

The withdrawal button is clearly marked during the statutory withdrawal period – you will find it in the footer of our website.

The withdrawal process consists of two steps: after clicking on the withdrawal button, you will be shown the details required to identify the contract; you can then confirm your withdrawal, after which you will receive a confirmation of receipt by email.

When you use the cancellation button, we process only those personal data necessary to identify the contract and to process your cancellation (e.g. name, or contract number, email address). The legal basis for this processing is Article 6(1)(c) of the GDPR (fulfilment of our legal obligations under and consumer protection law, in particular Section 356a of the German Civil Code (BGB)) and Article 6(1)(b) of the GDPR (performance of the contractual relationship).

We store the data you submit via the cancellation button for the duration of the statutory retention periods and subsequently delete or anonymise it in accordance with our data deletion policies. Irrespective of the cancellation button, existing cancellation options (e.g. by email or post) remain available.

Services and tools used

Roeye, San Francisco, USA

Roeye CDN

Nature and scope of processing

We use the Content Delivery Network (“Roeye CDN”) provided by Roeye, operated by Roeye, San Francisco, CA, USA, to deliver certain content on our website (e.g. scripts or other technical resources) more quickly and reliably via a distributed network of servers. When this content is accessed, your IP address and technical information about your browser and device are processed and logged in server log files. Roeye may use cookies or similar technologies for this purpose to technically route requests and to ensure the delivery and security of the services.

Purpose, legal basis and transfers to third countries

The purpose of the processing is to improve the performance, stability and security of our website. Insofar as only technically necessary data is processed, this is carried out on the basis of Article 6(1)(f) of the GDPR (legitimate interest in the secure and efficient provision of our online services). Where Roeye CDN uses cookies or comparable technologies that go beyond purely technical operation, this is based on your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG, which you may withdraw at any time via our consent/cookie tool.

The use of Roeye CDN involves the transfer of data to the USA; where necessary, we rely on appropriate safeguards in accordance with Article 44 et seq. of the GDPR (e.g. EU Standard Contractual Clauses).

Further information on data processing can be found in Roeye’s privacy policy.

Shopify CDN

Nature and scope of processing

We use Shopify CDN to ensure the proper delivery of our website’s content. Shopify CDN is a service provided by Shopify International Limited, which acts as a Content Delivery Network (CDN) on our website to ensure the functionality of other services provided by Shopify, Inc. A separate section of this privacy policy covers these services. This section deals solely with the use of the CDN.

A CDN helps to deliver content from our online offering – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes stated above and to maintain the security and functionality of the Shopify CDN.

Purpose and legal basis

The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online services in accordance with Article 6(1)(f) of the GDPR.

Klaviyo

Nature and scope of processing

We have integrated Klaviyo components into our website. Klaviyo is a service provided by Klaviyo, Inc. and offers marketing automation software for marketing services and products, including SEO and content creation, lead management, newsletters, email and SMS marketing, and web analytics.

Klaviyo uses cookies and other browser technologies to analyse user behaviour and recognise users. This information is used, amongst other things, to compile reports on website activity. Furthermore, Klaviyo is used to store and transmit data entered into forms via cookies, including your IP address. In this case, your data is transferred to the operator of Klaviyo, Klaviyo, Inc., 125 Summer Street, Boston, Massachusetts 02111, United States.

Purpose and legal basis

We process your data using Klaviyo for the purpose of optimising our website and for marketing purposes on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.klaviyo.com/legal/dpaWeitere Further information can be found in Klaviyo’s privacy policy: https://www.klaviyo.com/privacy/policy.

ReCharge

Provider

We use the ReCharge service to process and manage subscriptions in our shop. The provider is ReCharge Inc., 1507 20th Street, Santa Monica, CA 90404, USA.

Nature and scope of data processing

When you take out a subscription in our shop, the data required for this is transmitted to ReCharge and processed there. This includes, in particular, your name, email address, delivery and billing addresses, products ordered, order history and details of the subscription (e.g. start date, delivery frequency, pausing, changes or cancellation). Recharge receives only limited information regarding your payment details, such as the last four digits of your credit card; the full payment details are processed by the relevant payment service provider.

The data is used exclusively for the processing and administration of your subscription.

Legal basis

The legal basis for the processing is Article 6(1)(b) of the GDPR, as the processing is necessary for the performance of the subscription contract concluded with you. Where we are legally obliged to retain data, the processing is carried out on the basis of Article 6(1)(c) of the GDPR.

Data processing on behalf of others and data transfers to third countries

We have entered into a data processing agreement with Recharge in accordance with Article 28 of the GDPR. As data is transferred to the USA, the transfer takes place on the basis of the EU Commission’s Standard Contractual Clauses in accordance with Article 46(2)(c) of the GDPR.

Retention period

Your data will be stored for the duration of your subscription. Upon termination, it will be deleted, provided there are no statutory retention obligations to the contrary.

Further information

Further information can be found in Recharge’s privacy policy: https://getrecharge.com/privacy-policy/

JSDelivr CDN

Nature and scope of processing

We use JSDelivr CDN to ensure the proper delivery of our website’s content. JSDelivr CDN is a service provided by Prospect One, which acts as a Content Delivery Network (CDN) on our website.

A CDN helps to deliver content from our online offering – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Prospect One, Krolewska 65a, Krakow, Malopolskie 30-081, Poland, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes stated above and to maintain the security and functionality of JSDelivr CDN.

Purpose and legal basis

The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online services in accordance with Article 6(1)(f) of the GDPR.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF).

In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other appropriate safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE.

Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).

Retention period

We have no influence over the specific retention period of the processed data; this is determined by Prospect One. Further information can be found in the privacy policy for JSDelivr CDN: https://www.jsdelivr.com/privacy-policy-jsdelivr-net.

sentry.io

On this website, we use features provided by sentry.io, a service operated by Functional Software, Inc., 132 Hawthorne St, San Francisco, CA 94107, USA.

Nature and scope of data processing

sentry.io is an error tracking and performance monitoring tool that helps us identify technical error messages and improve the stability of our website. In particular, collects information about the browser used, the operating system, the time of the error, and technical details regarding the error situation. This information is generally processed anonymously and is used solely for the purpose of analysing and resolving malfunctions. Functional Software, Inc. does not use the data collected for advertising or analytical purposes. Further information on this can be found in the sentry.io privacy policy: https://sentry.io/privacy/.

Legal basis for processing

Front-end integration: The integration of sentry.io into the front-end is based solely on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You give this consent via our cookie banner. Without your consent, no data is transferred to sentry.io via the front-end.

Back-end integration: The use of sentry.io in the back-end is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to detect technical errors, maintain the stability of our systems and ensure the secure operation of our website.

Data processing on behalf of a controller

To ensure that data processing complies with data protection regulations, we have entered into a data processing agreement (DPA) with Functional Software, Inc. in accordance with Article 28 of the GDPR.

PayPal

Nature and scope of processing

We have integrated PayPal components into our website. PayPal is a service provided by PayPal Pte. Ltd. and offers online payment solutions worldwide.

If you select PayPal as your payment method, the data required for the payment transaction will be automatically transmitted to PayPal Pte. Ltd., San Jose, California, US.

In this context, the following data is generally collected: name, address, company (if applicable), email address, telephone and mobile numbers, and IP address.

Purpose and legal basis

Use of the service is based on the performance of a contract, i.e. for the processing of payment transactions in accordance with Article 6(1)(b) of the GDPR.

Retention period

We have no influence over the specific retention period for the processed data; this is determined by PayPal Pte. Ltd. Further information can be found in PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

Shopify CDN

Nature and scope of processing

We use Shopify CDN to ensure the proper delivery of our website’s content. Shopify CDN is a service provided by Shopify International Limited, which acts as a Content Delivery Network (CDN) on our website to ensure the functionality of other services provided by Shopify, Inc. A separate section in this privacy policy covers these services. This section deals solely with the use of the CDN.

A CDN helps to deliver content from our online offering – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes stated above and to maintain the security and functionality of the Shopify CDN.

Purpose and legal basis

The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online services in accordance with Article 6(1)(f) of the GDPR.

Cloudflare

We use a so-called ‘Content Delivery Network’ (CDN) provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.

A CDN enables us to deliver certain content quickly, in particular large media files. This is achieved via a network of regionally distributed servers connected via the internet. In this way, the provider can analyse the data transmission between your browser and our servers and filter out potentially malicious traffic. The processing of users’ data is carried out solely for the aforementioned purposes and serves to maintain the security and functionality of the CDN.

The use of Cloudflare is based on our legitimate interest in providing our website as error-free and secure as possible (Article 6(1)(f) of the GDPR).

Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.cloudflare.com/privacypolicy/.

Further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.

The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the US which aims to ensure compliance with European data protection standards when processing data in the US. Certification under the DPF obliges companies to adhere to these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnZKAA0&status=Active

Data processing

To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.

Klaviyo

Nature and scope of processing

We have integrated Klaviyo components into our website. Klaviyo is a service provided by Klaviyo, Inc. and offers marketing automation software for marketing services and products, including SEO and content creation, lead management, newsletters, email and SMS marketing, and web analytics.

Klaviyo uses cookies and other browser technologies to analyse user behaviour and recognise users. This information is used, amongst other things, to compile reports on website activity. Furthermore, Klaviyo is used to store and transmit data entered into forms via cookies, including your IP address. In this case, your data is transferred to the operator of Klaviyo, Klaviyo, Inc., 125 Summer Street, Boston, Massachusetts 02111, United States.

Purpose and legal basis

We process your data using Klaviyo for the purpose of optimising our website and for marketing purposes on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.klaviyo.com/legal/dpaWeitere Further information can be found in Klaviyo’s privacy policy: https://www.klaviyo.com/privacy/policy.

Google Fonts

Nature and scope of data processing

This website uses web fonts to ensure consistent display of fonts provided by Google. When you visit the page, your browser loads the required web fonts into your browser cache so that text and fonts are displayed correctly. To do this, the browser you are using establishes a connection to Google’s servers. As a result, Google becomes aware of your IP address.

Legal basis

The use of Google Web Fonts is based on our legitimate interest in ensuring a consistent font display on our website (Article 6(1)(f) of the GDPR). If consent has been requested (e.g. consent to the storage of cookies), the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. If your browser does not support web fonts, a standard font from your computer will be used. Further information on Google Web Fonts can be found here: https://developers.google.com/fonts/faq. Google’s privacy policy can be found here: https://policies.google.com/privacy?hl=de.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google APIs (Google Hosted Libraries)

On our website, we use what are known as ‘Google Hosted Libraries’. This involves loading JavaScript libraries (e.g. jQuery), which are required for the functionality of our website, via Google’s servers rather than hosting them directly on our own server. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (‘Google’).When these external libraries are accessed, a connection to Google’s servers is established automatically. In the process, information is transmitted to Google regarding which of our web pages you have visited. Your IP address is also processed. This occurs regardless of whether you have a Google user account and are logged in, or do not have a user account. If you are logged in to Google, your data may be directly associated with your account. If you do not wish this to happen, you must log out of Google before accessing our website.

The use of Google Hosted Libraries is in the interests of providing and updating our website quickly, securely and efficiently (Article 6(1)(f) of the GDPR). Where consent has been sought, processing takes place exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time.

It cannot be ruled out that Google may transfer the data to the USA. Further information on the handling of user data can be found in Google’s privacy policy: https://policies.google.com/privacy?hl=de

Google Tag Manager

On this website, we use services and functions provided by Google Tag Manager, which is offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that enables us to implement other tools on our website. It does not create user profiles, does not store cookies and does not carry out any analyses independent of . However, your IP address is recorded and may be transferred to the USA. Google Tag Manager itself is used solely for the administration of these tools, which are integrated via it.

Purpose & Legal Basis

When using Google Tag Manager on this website, we rely on Article 6(1)(f) of the GDPR as the legal basis, as we have a legitimate interest in implementing and managing tracking tools on this website quickly and easily. If you have previously given your consent to data processing on this website via Google Tag Manager, the processing of your data takes place solely on the legal basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. You may withdraw your consent at any time.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Smile.io

Provider

We use the Smile.io service for our loyalty and rewards programme. The provider is Smile Inc., PO Box 33042 Ira Needles, Waterloo, ON N2T 2M9, Canada.

Nature and scope of data processing

When you visit our website, the rewards widget is loaded from Smile.io’s servers. In doing so, your IP address is transmitted to Smile.io. In addition, information may be stored on your device (e.g. cookies or local storage) to ensure the widget functions correctly.

If you take part in our rewards programme, the data required for this purpose is transmitted to Smile.io and processed there. This includes, in particular, your name, email address, your orders, your points balance and any rewards you have redeemed. The data is used exclusively for the purposes of running the rewards programme, i.e. to credit points, display your points balance and redeem rewards.

Legal basis

The legal basis for loading the widget and accessing your device is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time with future effect via our cookie settings. The lawfulness of the data processing carried out up to the point of withdrawal remains unaffected by the withdrawal.

The processing of your data in connection with your participation in the rewards programme is based on Article 6(1)(b) of the GDPR, as it is necessary for the performance of the programme.

Data processing on behalf of others and data transfers to third countries

We have entered into a data processing agreement with Smile.io in accordance with Article 28 of the GDPR. Your data may be processed in Canada and the USA. An adequacy decision by the European Commission pursuant to Article 45 of the GDPR is in place for Canada. Transfers to the USA are carried out on the basis of the European Commission’s standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

Retention period

Your data will be stored for the duration of your participation in the rewards programme. Upon termination, it will be deleted, provided there are no statutory retention obligations to the contrary.

Further information

Further information can be found in Smile.io’s privacy policy: https://smile.io/privacy-policy

AdRoll

Nature and scope of processing

We use the AdRoll service provided by NextRoll, Inc., San Francisco, California, US, to display specific and relevant advertisements to user groups using targeting technologies.

Web tracking technologies are used to create pseudonymised user profiles. These profiles cannot generally be linked to you as a natural person, but are used, for example, for segmentation when displaying advertisements.

Purpose and legal basis

The use of AdRoll is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Retention period

We have no influence over the specific retention period of the processed data; this is determined by NextRoll, Inc. Further information can be found in the AdRoll privacy policy: https://www.nextroll.com/privacy.

Meta Pixel

On this website, we use the Meta Pixel, which is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

With the help of the Meta Pixel, we can analyse the behaviour of our website visitors when they are redirected to our website by clicking on a Facebook advert. We use the user data to measure the success of our Facebook adverts and to optimise them. As the website operator, we only receive anonymised data for this purpose, meaning we cannot identify you as a user.

Meta, on the other hand, processes the data in such a way that it is linked to a specific user and used for its own advertising purposes. This enables Meta to display personalised adverts on Meta and other websites. As the website operator, we have no influence over this. Further information on data processing can be found in Meta’s privacy policy at https://www.facebook.com/about/privacy/.

Legal basis

When using Meta Pixel, we rely on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time.

The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.

The transfer of your personal data to the USA is based on the European Commission’s Standard Contractual Clauses. Further information on this can be found at https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

If personal data is collected on this website via this service and passed on to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, share joint responsibility for the processing of your personal data (Article 26 of the GDPR). However, we are only responsible for the collection of your data and its transfer to Meta, whilst Meta is responsible for what happens to the data thereafter. The obligations we impose on each other within the framework of joint controllership are set out in a joint data processing agreement. You can find the full text of the agreement at the following link: https://www.facebook.com/legal/controller_addendum. Accordingly, when using the Meta tool, we must provide you with information on data protection and ensure that the tool is implemented on our website in compliance with data protection regulations.

Meta itself is responsible for the security of its own products. If you wish to exercise your rights as a data subject and, for example, request information about the data processed by Meta relating to you, you can contact Meta directly. If you exercise your rights as a data subject with us, we are obliged to forward your request to Meta .

Taboola

On this website, we use the service provided by the international advertising technology company Taboola, which is offered by Taboola, Inc., 1115 Broadway, 7th Floor, New York, New York 10010, USA.

We use Taboola to display personalised content recommendations on our website. When you visit one of our pages featuring Taboola, a connection is established with the provider’s servers. In the process, information about your usage behaviour, such as pages visited and content clicked on, is collected.

Purpose and legal basis

When using Taboola, we rely on Article 6(1)(f) of the GDPR as the legal basis for the collection and storage of your personal data, as we have a legitimate interest in presenting you with relevant content on our website. If you have previously given your consent to data processing by Taboola on this website, the processing of your data takes place solely on the legal basis of Article 6(1)(a) of the GDPR. You may withdraw your consent at any time.

Retention period

Taboola stores the personal data collected for the purpose of displaying adverts for a maximum of 13 months from your last interaction with the service. The data is then deleted or anonymised. Cookies with an identification function may remain active for up to 2 years.

Data processing on behalf of a third party

Taboola uses the European Commission’s Standard Contractual Clauses as a safeguard for the transfer of personal data to third countries. This ensures that your data is adequately protected even when processed outside the EU.

Further information on data processing can be found in Taboola’s privacy policy at https://www.taboola.com/privacy-policy.

Rubicon Project Ads

Nature and scope of processing

We have integrated Rubicon Project Ads into our website. Rubicon Project Ads is a service provided by Rubicon Project, Inc., which displays targeted advertising to users. Rubicon Project Ads uses cookies and other browser technologies to analyse user behaviour and recognise users. Rubicon Project Ads collects information about visitor behaviour on various websites. This information is used to optimise the relevance of the advertising. Furthermore, Rubicon Project Ads delivers targeted advertising based on behavioural profiles and geographical location. Your IP address and other identifying characteristics, such as your user agent, are transmitted to the provider. In this case, your data is transferred to the operator of Rubicon Project Ads, Rubicon Project, Inc.

Web tracking technologies are used to create pseudonymised user profiles. These profiles cannot be linked to you as a natural person, but are used, for example, for segmentation when displaying advertisements.

Purpose and legal basis

The use of Rubicon Project Ads is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Retention period

We have no influence over the specific retention period of the processed data; this is determined by Rubicon Project, Inc. Further information can be found in the privacy policy for Rubicon Project Ads: https://rubiconproject.com/privacy/.

Casale Media

Nature and scope of processing

We have integrated Casale Media into our website. Casale Media is a service provided by Casale Media, Inc., which displays targeted advertising to users. Casale Media uses cookies and other browser technologies to analyse user behaviour and recognise users. Casale Media collects information about visitor behaviour on various websites. This information is used to optimise the relevance of the advertising. Furthermore, Casale Media delivers targeted advertising based on behavioural profiles and geographical location. Your IP address and other identifying characteristics, such as your user agent, are transmitted to the provider. In this case, your data is passed on to the operator of Casale Media, Casale Media, Inc., 74 Wingold Avenue, Toronto, Ontario M6B 1P5, Canada.

Web tracking technologies are used to create pseudonymised user profiles. These profiles cannot be linked to you as a natural person, but are used, for example, for segmentation when displaying advertisements.

Purpose and legal basis

The use of Casale Media is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Retention period

We have no influence over the specific retention period of the processed data; this is determined by Casale Media, Inc. Further information can be found in the Casale Media privacy policy: https://casalemedia.com/legal/.

Outbrain

Nature and scope of processing

We have integrated Outbrain into our website. Outbrain is a service provided by Outbrain Inc. designed to display targeted advertising to users. Outbrain uses cookies and other browser technologies to analyse user behaviour and recognise users.

Outbrain collects information about visitor behaviour on various websites. This information is used to optimise the relevance of adverts. Furthermore, Outbrain delivers targeted adverts based on behavioural profiles and geographical location. Your IP address and other identifying characteristics, such as your user agent, are transmitted to the provider.

In this case, your data is passed on to the operator of Outbrain, Outbrain Inc., New York, New York, US.

Purpose and legal basis

The use of Outbrain is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Retention period

We have no influence over the specific retention period of the processed data; this is determined by Outbrain Inc. Further information can be found in Outbrain’s privacy policy: https://www.outbrain.com/legal/privacy#privacy-policy.

Google DoubleClick

On this website, we use services and functions provided by Google DoubleClick, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Nature and scope of data processing

Google DoubleClick enables us to display targeted adverts in Google applications that match users’ interests. In order to provide relevant adverts, Google DoubleClick must identify users and link their website visits, clicks and other information to their user behaviour. To do this, Google DoubleClick uses cookies and technologies to recognise users and creates pseudonymised user profiles based on the data collected.

You can opt out of this personalised advertising in your personal Google account at https://policies.google.com/technologies/ads and https://adssettings.google.com/authenticated.

Legal basis

When using Google DoubleClick, we rely on Article 6(1)(f) of the GDPR as the legal basis, as we have a legitimate interest in analysing the use of our website. This enables us to optimise our online presence and services for you. If you have previously given your consent to data processing by Google DoubleClick on this website, the processing of your data takes place on the legal basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG. You may withdraw your consent at any time.

BidSwitch

Nature and scope of processing

We have integrated BidSwitch into our website. BidSwitch is a service provided by IPONWEB Holding Limited that displays targeted advertising to users. BidSwitch uses cookies and other browser technologies to analyse user behaviour and recognise users. BidSwitch collects information about visitor behaviour on various websites. This information is used to optimise the relevance of the advertising. Furthermore, BidSwitch delivers targeted advertising based on behavioural profiles and geographical location. Your IP address and other identifying characteristics, such as your user agent, are transmitted to the provider. In this case, your data is passed on to the operator of BidSwitch, IPONWEB Holding Limited, 4th Floor, 16 Garrick Street, Covent Garden, London, WC2E 9BA, UK.

Web tracking technologies are used to create pseudonymised user profiles. These profiles cannot be linked to you as a natural person, but are used, for example, for segmentation when displaying advertisements.

Purpose and legal basis

The use of BidSwitch is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Retention period

We have no influence over the specific retention period of the processed data; this is determined by IPONWEB Holding Limited. Further information can be found in the BidSwitch privacy policy: https://www.iponweb.com/privacy-policy.

TikTok Analytics

Nature and scope of processing

We use TikTok Analytics from Beijing Bytedance Technology Ltd., Beijing, China, to analyse the use of our online service and to obtain statistical insights into the reach, interactions and performance of our content. To this end, TikTok Analytics processes, in particular, information about the content you access, how you interact with our content (e.g. views, clicks, time spent on the site), as well as technical data relating to your device and browser. TikTok uses cookies and similar technologies for this purpose, which enable the use of our online service to be recorded and attributed to pseudonymous users or user groups.

Purpose and legal basis

The purpose of the processing is to analyse and improve our online offering, as well as to optimise our content and marketing activities on TikTok and, where applicable, linked services. The use of TikTok Analytics is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the use of cookies or similar technologies falls within the scope of these provisions. You may withdraw your consent at any time with future effect via our consent/cookie management tool.

Retention period

The specific retention period for the processed data is determined by TikTok Technology Limited and is beyond our direct control. Further information on the processing of personal data in connection with TikTok services and on your rights can be found in TikTok’s privacy policy at: https://www.tiktok.com/legal/privacy-policy.

Replo Analytics

Replo Inc. (Replo Analytics)

We use the ‘Replo Analytics’ service on our website. The provider is Replo Inc., based in San Francisco, USA. The domains data.replo.app and replocdn.com are used to provide the service.

Scope of data processing

Replo Analytics is used on our website to improve user-friendliness and to analyse and optimise our online offering. When using our website with Replo Analytics enabled, the following data may be processed:

  • IP address

  • Date and time of access

  • Browser type and browser version

  • Operating system

  • Pages visited on our website

  • Time spent on individual pages

  • Click behaviour and interactions on the website

  • Referrer URL (the page visited previously)

  • Approximate location (based on the IP address)

  • Device information (screen resolution, device type)

Replo Analytics may use cookies or similar technologies to analyse your usage behaviour and improve the website’s performance.

Legal basis

Replo Analytics will only process your personal data with your explicit consent in accordance with Article 6(1)(a) of the GDPR. We obtain this consent via our cookie banner before Replo Analytics is activated.

Data transfer and recipients

Replo Inc. is based in the USA, a third country outside the EU for which there is no general adequacy decision by the European Commission. To ensure the protection of your personal data during this transfer, we have entered into Standard Contractual Clauses (SCCs) with Replo Inc. in accordance with Article 46 of the GDPR and have implemented additional technical and organisational measures.

Provided that Replo Inc. participates in the EU-US Data Privacy Framework (DPF), this may also serve as a basis for the data transfer.

Retention period

The data collected via Replo Analytics is retained for as long as is necessary for the purposes of analysing and optimising our website, usually for a maximum period of 26 months. Anonymised or aggregated data may be retained for longer periods.

Right to withdraw consent and right to object

You may withdraw your consent to the use of Replo Analytics at any time. To do so, you have the following options:

  • Adjust your cookie settings via our cookie banner (open cookie settings)

  • Disable cookies in your browser

  • Using browser add-ons that block tracking

  • Contacting us directly

Withdrawal does not affect the lawfulness of any processing carried out prior to the withdrawal.

Replo Inc.’s Privacy Policy

Further information on data processing by Replo Inc. can be found in their privacy policy at: https://www.replo.app/privacy

Judgeme

Judge.me product reviews

We use the ‘Judge.me’ service on our website. The provider is Judge.me, based in London, United Kingdom. The domains cdn.judge.me, cdn1.judge.me, judgeme-public-images.imgix.net and tracking.aws.judge.me are used to provide the service.

Scope of data processing

Judge.me is used on our website as a rating and review system. When using our website with Judge.me components or when submitting a review, the following data may be processed:

  • IP address (usually anonymised)

  • Date and time of access

  • Browser type and version

  • Operating system

  • When submitting a rating: name/username, email address, rating text, star rating, any photos uploaded

  • Information about purchased products (for product reviews)

  • Information regarding interaction with reviews (marking as ‘helpful’, views)

  • Referrer URL (the page visited previously)

Judge.me may use cookies or similar technologies to ensure reviews are displayed correctly and to enable features such as marking reviews as helpful.

Legal basis

The legal basis for the processing of your personal data depends on the specific function:

  • For the display of reviews: Our legitimate interest pursuant to Article 6(1)(f) of the GDPR to improve our service and increase transparency

  • When submitting a review: your consent in accordance with Article 6(1)(a) of the GDPR

  • For tracking and analytics functions: your consent in accordance with Article 6(1)(a) of the GDPR

Data transfer and recipients

Judge.me is based in the United Kingdom, which is no longer a member of the EU. However, the European Commission has issued an adequacy decision for the United Kingdom, confirming that an adequate level of data protection exists. This means that data transfers are generally possible without further safeguards.

Due to the use of servers in the AWS cloud (“tracking.aws.judge.me”), data may technically also be processed in other countries. Where data is transferred to countries outside the EU, Judge.me ensures, through appropriate safeguards, that an adequate level of data protection is maintained.

Retention period

The data collected via Judge.me is stored for as long as is necessary to provide the service. Reviews are generally stored permanently for as long as the reviewed product remains in our range. Personal data such as IP addresses is anonymised or deleted after a reasonable period of time in accordance with Judge.me’s privacy policy.

Right to withdraw consent and right to object

You may object to the processing of your personal data at any time or withdraw your consent. To do so, you have the following options:

  • Adjusting your cookie settings in your browser

  • Using our cookie banner with the relevant opt-out options

  • Contacting us directly to have a review you have submitted deleted

  • Contacting Judge.me via their website

Judge.me’s privacy policy

Further information on data processing by Judge.me can be found in their privacy policy at: https://judge.me/privacy