Privacy policy

Preamble

With the following privacy policy we would like to explain to you what types of your personal data (hereinafter also referred to briefly as "data") we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offering").

The terms used are not gender-specific.

Last updated: 4 August 2026

Table of contents

Controller

Marios Mouratidis
An der Steinlücke 26
57080 Siegen
Germany

E-mail address: office@retroboter.net

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of data processed

  • Inventory data.
  • Payment data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication and procedural data.
  • Contact information (Facebook).
  • Event data (Facebook).

Categories of data subjects

  • Customers.
  • Employees.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Contact requests and communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement.
  • Tracking.
  • Office and organisational procedures.
  • Remarketing.
  • Conversion measurement.
  • Click tracking.
  • Target group formation.
  • A/B testing.
  • Management and response to enquiries.
  • Content delivery network (CDN).
  • Feedback.
  • Marketing.
  • Profiles with user-related information.
  • Cross-device tracking.
  • Provision of our online offering and user-friendliness.
  • Information technology infrastructure.

Relevant legal bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in an individual case, we will inform you of these in this privacy policy.

  • Consent (Art. 6(1)(a) GDPR) - The data subject has given consent to the processing of personal data relating to them for one or more specific purposes.
  • Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection provisions apply in Germany. These include in particular the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transfer, and automated decision-making in individual cases including profiling. Furthermore, the data protection laws of the individual German federal states may apply.

Note on the applicability of the GDPR and the Swiss FADP: These data protection notices serve to provide information both under the Swiss Federal Act on Data Protection (Swiss FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that the terms of the GDPR are used due to their broader geographical application and comprehensibility. In particular, instead of the terms "processing" of "personal data", "predominant interest" and "particularly sensitive personal data" used in the Swiss FADP, the terms "processing" of "personal data", "legitimate interest" and "special categories of data" used in the GDPR are applied. However, the legal meaning of the terms continues to be determined in accordance with the Swiss FADP where the Swiss FADP applies.

Security measures

In accordance with legal requirements and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input of, transfer of, assurance of availability of, and separation of the data. Furthermore, we have established procedures which ensure the exercise of data subject rights, the erasure of data and responses to threats to the data. We also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.

Truncation of the IP address: Where IP addresses are processed by us or by the service providers and technologies used, and the processing of a complete IP address is not necessary, the IP address is truncated (also referred to as "IP masking"). In this process, the last two digits or the last part of the IP address after a full stop are removed or replaced by placeholders. The purpose of truncating the IP address is to prevent or substantially impede the identification of a person by means of their IP address.

TLS/SSL encryption (https): In order to protect the data of users transmitted via our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing internet connections by encrypting the data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) is shown in the URL when a website is secured by an SSL/TLS certificate.

Transfer of personal data

In the course of our processing of personal data, it may happen that the data is transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and in particular conclude corresponding contracts or agreements with the recipients of your data which serve to protect your data.

International data transfers

Data processing in third countries: Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or where processing takes place in the context of using third-party services or the disclosure or transfer of data to other persons, bodies or companies, this is only done in accordance with legal requirements. Where the level of data protection in the third country has been recognised by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is otherwise ensured, in particular by means of standard contractual clauses (Art. 46(2)(c) GDPR), explicit consent, or in the case of contractually or legally required transfer (Art. 49(1) GDPR). In addition, we inform you of the bases for third-country transfers in respect of the individual providers from third countries, whereby adequacy decisions take precedence as a basis. Information on third-country transfers and existing adequacy decisions can be found in the information provided by the European Commission at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.

EU-US Trans-Atlantic Data Privacy Framework: Under the so-called "Data Privacy Framework" (DPF), the European Commission has also recognised the level of data protection as adequate for certain companies from the USA by means of the adequacy decision of 10 July 2023. The list of certified companies as well as further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). Within these data protection notices we inform you which of the service providers we use are certified under the Data Privacy Framework.

Erasure of data

The data processed by us is erased in accordance with legal requirements as soon as the consents permitting its processing are withdrawn or other permissions cease to apply (e.g. where the purpose of processing this data has ceased to apply or the data is not necessary for that purpose). Where the data is not erased because it is required for other and legally permissible purposes, its processing is restricted to those purposes. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or the storage of which is necessary for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person. Within our data protection notices, we may provide users with further information on the erasure and retention of data that applies specifically to the respective processing operations.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw consent given at any time.
  • Right of access: You have the right to obtain confirmation as to whether data concerning you is being processed and to receive information about that data as well as further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: In accordance with legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
  • Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be erased without undue delay, or alternatively, in accordance with legal requirements, to request a restriction of the processing of the data.
  • Right to data portability: You have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format in accordance with legal requirements, or to request its transmission to another controller.
  • Complaint to a supervisory authority: In accordance with legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.

Use of cookies

Cookies are small text files or other storage records which store information on end devices and read information from end devices. For example, to store the login status in a user account, the contents of a shopping cart in an online shop, the content accessed or the functions used within an online offering. Cookies may also be used for various purposes, e.g. for the functionality, security and convenience of online offerings as well as for producing analyses of visitor flows.

Information on consent: We use cookies in accordance with statutory provisions. We therefore obtain prior consent from users, except where this is not required by law. Consent is in particular not necessary where the storage and reading of the information, including cookies, is strictly necessary in order to provide users with a telemedia service (i.e. our online offering) which they have expressly requested. Strictly necessary cookies generally include cookies with functions relating to the display and operability of the online offering, load balancing, security, the storage of users' preferences and choices, or similar purposes connected with the provision of the main and ancillary functions of the online offering requested by users. Revocable consent is clearly communicated to users and contains information on the respective use of cookies.

Information on legal bases under data protection law: The legal basis under data protection law on which we process users' personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the consent given. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g. in the commercial operation of our online offering and the improvement of its usability), or, where this takes place in the context of fulfilling our contractual obligations, where the use of cookies is necessary in order to fulfil our contractual obligations. We provide information on the purposes for which we process cookies in the course of this privacy policy or as part of our consent and processing procedures.

Storage period: With regard to the storage period, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their end device (e.g. browser or mobile application).
  • Persistent cookies: Persistent cookies remain stored even after the end device has been closed. For example, the login status can be saved or preferred content displayed directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information on the type and storage period of cookies (e.g. when obtaining consent), users should assume that cookies are persistent and that the storage period may be up to two years.

General information on withdrawal and objection (so-called "opt-out"): Users may withdraw the consent they have given at any time and object to processing in accordance with legal requirements. To do so, users may, among other things, restrict the use of cookies in their browser settings (which may also limit the functionality of our online offering). An objection to the use of cookies for online marketing purposes may also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.

  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Consent (Art. 6(1)(a) GDPR).

Further information on processing operations, procedures and services:

  • Processing of cookie data on the basis of consent: We use a consent management procedure for obtaining, logging, managing and withdrawing consent, in particular for the use of cookies and similar technologies for storing, reading and processing information on users' end devices and for processing that information. Within this procedure, users' consent to the use of cookies and to the processing operations and providers named in the consent management procedure is obtained and can be managed and withdrawn by users. The declaration of consent is stored so that it does not have to be requested again and so that consent can be evidenced in accordance with the legal obligation. Storage may take place on the server side and/or in a cookie (so-called opt-in cookie, or by means of comparable technologies) in order to be able to attribute the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following applies: the storage period of the consent may be up to two years. In this process, a pseudonymous user identifier is created and stored together with the time of consent, information on the scope of the consent (e.g. which categories of cookies and/or service providers) as well as the browser, system and end device used; Legal bases: Consent (Art. 6(1)(a) GDPR).

Business services

We process the data of our contractual and business partners, e.g. customers and prospective customers (collectively referred to as "contractual partners"), in the context of contractual and comparable legal relationships as well as associated measures and in the context of communication with contractual partners (or pre-contractually), e.g. in order to answer enquiries.

We process this data in order to fulfil our contractual obligations. These include in particular the obligations to provide the agreed services, any update obligations and remedies in the event of warranty claims and other performance disruptions. In addition, we process the data in order to safeguard our rights and for the purposes of the administrative tasks associated with these obligations as well as the organisation of the business. Furthermore, we process the data on the basis of our legitimate interests in the proper and commercial management of our business as well as in security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information and rights (e.g. involving telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the framework of applicable law, we only pass on the data of contractual partners to third parties insofar as this is necessary for the aforementioned purposes or in order to fulfil legal obligations. Contractual partners are informed about further forms of processing, e.g. for marketing purposes, within this privacy policy.

We inform contractual partners which data is required for the aforementioned purposes before or in the course of data collection, e.g. in online forms, by means of special marking (e.g. colours) or symbols (e.g. asterisks or similar), or personally.

We erase the data after expiry of statutory warranty and comparable obligations, i.e. generally after four years, unless the data is stored in a customer account, e.g. for as long as it must be retained for legal archiving reasons. The statutory retention period is ten years for documents relevant under tax law as well as for commercial books, inventories, opening balance sheets, annual financial statements, the working instructions and other organisational documents necessary for understanding these documents, and accounting vouchers, and six years for commercial and business letters received and reproductions of commercial and business letters sent. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, opening balance sheet, annual financial statement or management report was prepared, the commercial or business letter was received or sent, or the accounting voucher was created, the record was made, or the other documents were created.

Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and data protection notices of the respective third-party providers or platforms apply in the relationship between users and the providers.

  • Types of data processed: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. e-mail, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status); content data (e.g. entries in online forms).
  • Data subjects: Customers; prospective customers; business and contractual partners. Communication partners.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; security measures; contact requests and communication; office and organisational procedures. Management and response to enquiries.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Online shop, order forms, e-commerce and delivery: We process the data of our customers in order to enable them to select, purchase or order the chosen products, goods and associated services, as well as their payment and delivery or performance. Where necessary for the execution of an order, we use service providers, in particular postal, freight forwarding and shipping companies, in order to carry out the delivery or performance for our customers. For the processing of payment transactions we use the services of banks and payment service providers. The required information is marked as such in the context of the order or comparable purchase process and comprises the information required for delivery or provision and invoicing as well as contact information in order to be able to make any enquiries; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
  • DHL: Logistics company, shipping and delivery services. We share certain personal data with DHL in order to enable the shipment and delivery of parcels as well as shipment tracking and notifications to recipients. This information may include the names, addresses and contact details of the recipients; Service provider: Deutsche Post AG, Charles-de-Gaulle-Strasse 20, 53113 Bonn, Germany; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: http://www.dhl.com/. Privacy policy: https://www.dhl.com/de-de/home/fusszeile/datenschutzhinweis.html.

Use of online platforms for offering and sales purposes

We offer our services on online platforms operated by other service providers. In this context, the data protection notices of the respective platforms apply in addition to our data protection notices. This applies in particular with regard to the execution of the payment process and the procedures used on the platforms for reach measurement and interest-based marketing.

  • Types of data processed: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. e-mail, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
  • Data subjects: Customers.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations. Marketing.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • eBay: Online marketplace for e-commerce; Service provider: eBay Marketplaces GmbH, Helvetiastrasse 15/17, 3005 Bern, Switzerland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.ebay.de/; Privacy policy: https://www.ebay.de/help/policies/member-behavior-policies/datenschutzerklrung?id=4260. Basis for third-country transfers: Adequacy decision (Switzerland).
  • Etsy: Online marketplace for e-commerce; Service provider: Etsy, Inc., 55 Washington Street, Suite 712, Brooklyn, NY 11201, USA; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.etsy.com/de. Privacy policy: https://www.etsy.com/de/legal/privacy/?ref=ftr.
  • Shopify: Platform through which e-commerce services are offered and provided. The services and the processes carried out in connection with them include in particular online shops, websites, their offerings and content, community elements, purchase and payment transactions, customer communication as well as analysis and marketing; Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.shopify.com/. Privacy policy: https://www.shopify.com/legal/privacy.

Providers and services used in the course of business activities

In the course of our business activities we use additional services, platforms, interfaces or plug-ins from third-party providers (in short "services"), in compliance with legal requirements. Their use is based on our interests in the proper, lawful and economical management of our business operations and our internal organisation.

  • Types of data processed: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); contract data (e.g. subject matter of the contract, term, customer category).
  • Data subjects: Customers; prospective customers; users (e.g. website visitors, users of online services); business and contractual partners; employees (e.g. staff, applicants, former employees).
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations. Office and organisational procedures.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

Payment procedures

Within the framework of contractual and other legal relationships, on the basis of legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and use, in addition to banks and credit institutions, further service providers for this purpose (collectively "payment service providers").

The data processed by the payment service providers includes inventory data such as name and address, bank data such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, sum and recipient-related information. This information is necessary in order to carry out the transactions. However, the data entered is only processed by the payment service providers and stored with them. This means that we do not receive any account or credit card related information, but only information confirming or denying the payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit agencies. The purpose of this transmission is to verify identity and creditworthiness. In this regard we refer to the terms and conditions and the data protection notices of the payment service providers.

The terms and conditions and the data protection notices of the respective payment service providers apply to payment transactions and are available on the respective websites or transaction applications. We also refer to these for further information and for the exercise of rights of withdrawal, access and other data subject rights.

  • Types of data processed: Inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status); contact data (e.g. e-mail, telephone numbers).
  • Data subjects: Customers. Prospective customers.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

Provision of the online offering and web hosting

We process users' data in order to be able to provide them with our online services. For this purpose we process the user's IP address, which is necessary in order to transmit the content and functions of our online services to the user's browser or end device.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status); content data (e.g. entries in online forms); inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. e-mail, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category).
  • Data subjects: Users (e.g. website visitors, users of online services). Customers.
  • Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.); security measures. Provision of contractual services and fulfilment of contractual obligations.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Provision of the online offering on rented storage space: For the provision of our online offering we use storage space, computing capacity and software which we rent or otherwise obtain from a corresponding server provider (also referred to as a "web host"); Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
  • Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes, e.g. to avoid server overload (in particular in the case of abusive attacks, so-called DDoS attacks) and, on the other hand, to ensure server utilisation and stability; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Erasure of data: Log file information is stored for a maximum period of 30 days and then deleted or anonymised. Data whose further retention is necessary for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.
  • E-mail dispatch and hosting: The web hosting services we use also include the sending, receipt and storage of e-mails. For these purposes, the addresses of the recipients and senders as well as further information relating to the dispatch of e-mails (e.g. the providers involved) and the content of the respective e-mails are processed. The aforementioned data may also be processed for the purposes of detecting spam. Please note that e-mails on the internet are generally not sent in encrypted form. As a rule, e-mails are encrypted in transit, but (unless a so-called end-to-end encryption procedure is used) not on the servers from which they are sent and received. We can therefore accept no responsibility for the transmission path of e-mails between the sender and receipt on our server; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
  • Content delivery network: We use a "content delivery network" (CDN). A CDN is a service which enables the content of an online offering, in particular large media files such as graphics or program scripts, to be delivered more quickly and securely with the help of regionally distributed servers connected via the internet; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
  • STRATO: Services in the field of the provision of information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: STRATO AG, Pascalstrasse 10, 10587 Berlin, Germany; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.strato.de; Privacy policy: https://www.strato.de/datenschutz/. Data processing agreement: Provided by the service provider.
  • Shopify: Platform through which e-commerce services are offered and provided. The services and the processes carried out in connection with them include in particular online shops, websites, their offerings and content, community elements, purchase and payment transactions, customer communication as well as analysis and marketing; Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.shopify.com/. Privacy policy: https://www.shopify.com/legal/privacy.

Registration, login and user account

Users can create a user account. During registration, users are informed of the required mandatory information, which is processed for the purposes of providing the user account on the basis of the performance of contractual obligations. The data processed includes in particular the login information (user name, password and an e-mail address).

In the course of using our registration and login functions as well as the use of the user account, we store the IP address and the time of the respective user action. This storage takes place on the basis of our legitimate interests as well as those of the users in protection against misuse and other unauthorised use. As a rule, this data is not passed on to third parties unless it is necessary in order to pursue our claims or there is a legal obligation to do so.

Users may be informed by e-mail about processes relevant to their user account, such as technical changes.

  • Types of data processed: Inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; security measures; management and response to enquiries. Provision of our online offering and user-friendliness.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Registration with pseudonyms: Users may use pseudonyms instead of their real names as user names; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).
  • User profiles are not public: Users' profiles are not publicly visible or accessible.
  • Erasure of data after cancellation: If users have cancelled their user account, their data relating to the user account is erased, subject to any legal permission, obligation or consent of the users; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).

Blogs and publication media

We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data is processed for the purposes of the publication medium only insofar as this is necessary for its presentation and for communication between authors and readers, or for security reasons. In all other respects, we refer to the information on the processing of visitors to our publication medium within these data protection notices.

  • Types of data processed: Inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; feedback (e.g. collecting feedback via an online form). Provision of our online offering and user-friendliness.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Contact and enquiry management

When contacting us (e.g. by post, contact form, e-mail, telephone or via social media) as well as in the context of existing user and business relationships, the information provided by the enquiring persons is processed insofar as this is necessary in order to answer the contact enquiries and any requested measures.

  • Types of data processed: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status); inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category).
  • Data subjects: Communication partners. Customers.
  • Purposes of processing: Contact requests and communication; management and response to enquiries; feedback (e.g. collecting feedback via an online form); provision of our online offering and user-friendliness. Provision of contractual services and fulfilment of contractual obligations.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR).

Further information on processing operations, procedures and services:

  • Contact form: When users contact us via our contact form, by e-mail or via other communication channels, we process the data communicated to us in this context in order to deal with the matter raised; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
  • Shopify: Platform through which e-commerce services are offered and provided. The services and the processes carried out in connection with them include in particular online shops, websites, their offerings and content, community elements, purchase and payment transactions, customer communication as well as analysis and marketing; Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.shopify.com/. Privacy policy: https://www.shopify.com/legal/privacy.

Electronic withdrawal function

We provide an electronic withdrawal function in our online shop through which consumers can exercise their statutory right of withdrawal. We are required by law to provide this function (Section 356a of the German Civil Code (BGB), implementing Directive (EU) 2023/2673).

When you use the withdrawal function, we process the information you enter, in particular your name, the information identifying the contract and the e-mail address you provide for the acknowledgement of receipt. We also process any further information provided voluntarily, such as a reason for withdrawal or a free-text message, insofar as you choose to provide it.

In order to protect the form against misuse and to evidence receipt of your declaration, we additionally process technical data such as the IP address, the time stamp of use and the browser identifier. This technical data may also arise if you merely access the withdrawal function without completing the process.

We use the information exclusively for receiving and processing your withdrawal, for sending the acknowledgement of receipt required by law and for documenting the process. The information is not used for advertising purposes.

  • Types of data processed: Inventory data (e.g. names); contact data (e.g. e-mail addresses); contract data (e.g. order number, order date, items withdrawn from); content data (e.g. entries in online forms); usage data (e.g. access times); meta, communication and procedural data (e.g. IP addresses, time stamps, browser identifiers).
  • Data subjects: Customers; prospective customers. Users (e.g. website visitors, users of online services).
  • Purposes of processing: Compliance with a legal obligation; provision of contractual services and fulfilment of contractual obligations; management and response to enquiries. Security measures.
  • Legal bases: Legal obligation (Art. 6(1)(c) GDPR); performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
  • Erasure of data: Withdrawal records are erased after expiry of the statutory retention and limitation periods.

Further information on processing operations, procedures and services:

  • EU Widerrufs-Button Pro: Software for providing the electronic withdrawal function required by law. The services include displaying the withdrawal button, receiving declarations of withdrawal via a form, sending acknowledgements of receipt and documenting the processes; Service provider: Martini & Radl OG, Garnisongasse 4/11, 1090 Vienna, Austria; Legal bases: Legal obligation (Art. 6(1)(c) GDPR); Website: https://euwiderruf.com; Data processing agreement: https://euwiderruf.com/avv; Basis for third-country transfers: Data Privacy Framework (DPF), supplemented by standard contractual clauses. Further information: The provider in turn uses sub-processors, in particular Railway Corp. for application hosting and database (processing in the EU region) and Resend, Inc. for sending the acknowledgements of receipt (processing in the USA). The current list of sub-processors is available in the provider's data processing agreement.

Newsletters and electronic notifications

We send newsletters, e-mails and other electronic notifications (hereinafter "newsletters") only with the consent of the recipients or on the basis of a legal permission. Where the contents of a newsletter are specifically described when signing up, they are decisive for the users' consent. In all other respects, our newsletters contain information about our services and about us.

In order to subscribe to our newsletters, it is generally sufficient to provide your e-mail address. We may, however, ask you to provide a name for the purpose of addressing you personally in the newsletter, or other information insofar as this is necessary for the purposes of the newsletter.

Double opt-in procedure: Subscription to our newsletter generally takes place by means of a so-called double opt-in procedure. This means that after signing up you will receive an e-mail asking you to confirm your subscription. This confirmation is necessary so that no one can subscribe using someone else's e-mail address. Newsletter subscriptions are logged in order to be able to demonstrate the subscription process in accordance with legal requirements. This includes storing the time of subscription and confirmation as well as the IP address. Changes to your data stored with the dispatch service provider are also logged.

Erasure and restriction of processing: We may store unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to demonstrate consent previously given. The processing of this data is restricted to the purpose of a possible defence against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time. In the event of obligations to observe objections permanently, we reserve the right to store the e-mail address solely for this purpose in a blocklist.

The logging of the subscription procedure takes place on the basis of our legitimate interests for the purpose of demonstrating its proper conduct. Insofar as we commission a service provider to send e-mails, this takes place on the basis of our legitimate interests in an efficient and secure dispatch system.

Contents:

Information about us, our services, campaigns and offers.

  • Types of data processed: Inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g. by e-mail or post).
  • Legal bases: Consent (Art. 6(1)(a) GDPR).
  • Right to object (opt-out): You may cancel receipt of our newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find a link to unsubscribe from the newsletter either at the end of each newsletter, or you may use one of the contact options given above, preferably e-mail, for this purpose.

Further information on processing operations, procedures and services:

  • Reminder e-mails regarding the order process: If users do not complete an order process, we may remind users of the order process by e-mail and send them a link to continue it. This function may be useful, for example, where the purchase process could not be continued due to a browser crash, oversight or forgetfulness. Dispatch takes place on the basis of consent which users may withdraw at any time; Legal bases: Consent (Art. 6(1)(a) GDPR).

Web analytics, monitoring and optimisation

Web analytics (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offering and may comprise behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis we can, for example, identify at what times our online offering or its functions or content are used most frequently or invite repeat use. We can likewise determine which areas require optimisation.

In addition to web analytics, we may also use testing procedures, e.g. in order to test and optimise different versions of our online offering or its components.

Unless stated otherwise below, profiles, i.e. data aggregated into a usage process, may be created for these purposes and information may be stored in a browser or end device and read from it. The information collected includes in particular the web pages visited and the elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. Where users have consented to the collection of their location data vis-à-vis us or the providers of the services we use, location data may also be processed.

Users' IP addresses are also stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. In general, no plain data of users (such as e-mail addresses or names) is stored in the context of web analytics, A/B testing and optimisation, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
  • Data subjects: Customers; users (e.g. website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest- and behaviour-based profiling, use of cookies); target group formation; A/B testing; marketing; profiles with user-related information (creation of user profiles); remarketing. Provision of our online offering and user-friendliness.
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6(1)(a) GDPR).

Further information on processing operations, procedures and services:

  • Google Analytics: We use Google Analytics to measure and analyse the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data such as names or e-mail addresses. It serves to attribute analytics information to an end device in order to identify which content users have accessed within one or several usage processes, which search terms they have used, whether they have accessed content again or interacted with our online offering. Likewise, the time of use and its duration are stored, as well as the sources of users referring to our online offering and technical aspects of their end devices and browsers. In this process, pseudonymous profiles of users are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides coarse geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based equivalents). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. It is not logged, is not accessible and is not used for any further purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF); Right to object (opt-out): Opt-out plug-in: https://tools.google.com/dlpage/gaoptout, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and data processed).
  • Google Signals (Google Analytics function): Google Signals are session data from websites and apps which Google associates with users who are signed in to their Google accounts and have activated ad personalisation. This attribution of data to signed-in users is used to enable cross-device reporting, cross-device remarketing and cross-device conversion measurement. This includes: cross-platform reporting - linking data across devices and activities from different sessions using your user ID or Google Signals data, enabling an understanding of user behaviour at every step of the conversion process, from first contact to conversion and beyond; remarketing with Google Analytics - creating remarketing audiences from Google Analytics data and sharing these audiences with linked advertising accounts; demographics and interests - Google Analytics collects additional information on the demographics and interests of users who are signed in to their Google accounts and have activated ad personalisation; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://support.google.com/analytics/answer/7532985; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms; Basis for third-country transfers: Data Privacy Framework (DPF). Further information: https://business.safety.google/adsservices/ (types of processing and data processed).
  • Target group formation with Google Analytics: We use Google Analytics in order to display the advertisements placed within Google's advertising services and those of its partners only to users who have also shown an interest in our online offering or who exhibit certain characteristics (e.g. interests in particular topics or products, determined on the basis of the websites visited) which we transmit to Google (so-called "remarketing" or "Google Analytics audiences"). With the help of remarketing audiences we also wish to ensure that our advertisements correspond to the potential interests of users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms for Google advertising products and standard contractual clauses for third-country transfers of data: https://business.safety.google/adsprocessorterms.
  • Google Tag Manager: Google Tag Manager is a solution which allows us to manage so-called website tags via an interface and thus integrate other services into our online offering (please refer to the further information in this privacy policy). The Tag Manager itself (which implements the tags) therefore does not yet create user profiles or store cookies. Google merely learns the user's IP address, which is necessary in order to run Google Tag Manager; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms. Basis for third-country transfers: Data Privacy Framework (DPF).

Online marketing

We process personal data for the purposes of online marketing, which may in particular include the marketing of advertising space or the display of advertising and other content on the basis of the potential interests of users, as well as the measurement of their effectiveness.

For these purposes, so-called user profiles are created and stored in a file (so-called "cookie"), or similar procedures are used by means of which the information relevant for the display of the aforementioned content about the user is stored. This information may include, for example, content viewed, websites visited, online networks used, but also communication partners and technical information such as the browser used, the computer system used as well as information on usage times and functions used. Where users have consented to the collection of their location data, this may also be processed.

Users' IP addresses are also stored. However, we use the available IP masking procedures (i.e. pseudonymisation by truncating the IP address) to protect users. In general, no plain data of users (such as e-mail addresses or names) is stored within the online marketing procedures, but rather pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.

The information in the profiles is generally stored in cookies or by means of similar procedures. These cookies may subsequently, as a rule, also be read on other websites which use the same online marketing procedure and analysed for the purposes of displaying content, as well as supplemented with further data and stored on the server of the provider of the online marketing procedure.

Exceptionally, plain data may be assigned to the profiles. This is the case where users are, for example, members of a social network whose online marketing procedure we use and the network links the users' profiles with the aforementioned information. Please note that users may make additional arrangements with the providers, e.g. by giving consent during registration.

As a rule, we only receive access to aggregated information about the success of our advertisements. However, in the context of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e. for example to the conclusion of a contract with us. Conversion measurement is used solely to analyse the success of our marketing measures.

Unless stated otherwise, please assume that the cookies used are stored for a period of two years.

  • Types of data processed: Content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status); event data (Facebook) ("event data" is data which may be transmitted by us to Facebook, e.g. via the Facebook pixel (via apps or by other means), and which relates to persons or their actions; this data includes, for example, information about visits to websites, interactions with content, functions, installations of apps, purchases of products, etc.; the event data is processed for the purpose of forming target groups for content and advertising information (custom audiences); event data does not include the actual content (such as comments written), any login information or any contact information (i.e. no names, e-mail addresses or telephone numbers). Event data is deleted by Facebook after a maximum of two years, and the target groups formed from it are deleted when our Facebook account is deleted); contact information (Facebook) ("contact information" is data which clearly identifies data subjects, such as names, e-mail addresses and telephone numbers, which may be transmitted to Facebook, e.g. via the Facebook pixel or by upload for matching purposes in order to form custom audiences. After matching for the purpose of forming target groups, the contact information is deleted).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest- and behaviour-based profiling, use of cookies); conversion measurement (measuring the effectiveness of marketing measures); target group formation; marketing; profiles with user-related information (creation of user profiles); provision of our online offering and user-friendliness; remarketing; click tracking. Cross-device tracking (cross-device processing of user data for marketing purposes).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
  • Right to object (opt-out): We refer to the data protection notices of the respective providers and to the objection options stated for those providers (so-called "opt-out"). Where no explicit opt-out option has been provided, you have the option of disabling cookies in your browser settings. This may, however, limit functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered on a regional basis:

    a) Europe: https://www.youronlinechoices.eu.
    b) Canada: https://www.youradchoices.ca/choices.
    c) USA: https://www.aboutads.info/choices.
    d) Cross-regional: https://optout.aboutads.info.

Further information on processing operations, procedures and services:

  • Meta pixel and target group formation (custom audiences): With the help of the Meta pixel (or comparable functions for transmitting event data or contact information by means of interfaces in apps), Meta is able to determine the visitors of our online offering as a target group for the display of advertisements (so-called "Meta ads"). Accordingly, we use the Meta pixel in order to display the Meta ads placed by us only to those users on Meta platforms and within the services of partners cooperating with Meta (so-called "Audience Network" https://www.facebook.com/audiencenetwork/) who have also shown an interest in our online offering or who exhibit certain characteristics (e.g. interest in particular topics or products which is apparent from the websites visited) which we transmit to Meta (so-called "custom audiences"). With the help of the Meta pixel we also wish to ensure that our Meta ads correspond to the potential interests of users and are not perceived as intrusive. With the help of the Meta pixel we can furthermore track the effectiveness of Meta ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta ad (so-called "conversion measurement"); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Users' event data, i.e. behavioural and interest information, is processed for the purposes of targeted advertising and target group formation on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). Joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Advanced matching for the Meta pixel: In addition to the processing of event data in the context of using the Meta pixel (or comparable functions, e.g. in apps), contact information (data identifying individual persons, such as names, e-mail addresses and telephone numbers) is also collected by Meta within our online offering or transmitted to Meta. The processing of the contact information serves to form target groups (so-called "custom audiences") for displaying content and advertising information oriented towards the presumed interests of users. The collection or transmission and matching with data held by Meta does not take place in plain text but as so-called "hash values", i.e. mathematical representations of the data (this method is used, for example, when storing passwords). After matching for the purpose of forming target groups, the contact information is deleted; Legal bases: Consent (Art. 6(1)(a) GDPR); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for third-country transfers: Data Privacy Framework (DPF). Further information: https://www.facebook.com/legal/terms/data_security_terms.
  • Meta - target group formation via data upload: Formation of target groups for marketing purposes - We transmit contact information (names, e-mail addresses and telephone numbers) in list form to Meta for the purpose of forming target groups (so-called "custom audiences") for displaying content and advertising information oriented towards the presumed interests of users. The transmission and matching with data held by Meta does not take place in plain text but as so-called "hash values", i.e. mathematical representations of the data (this method is used, for example, when storing passwords). After matching for the purpose of forming target groups, the contact information is deleted; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Facebook advertisements: Placement of advertisements within the Facebook platform and evaluation of the advertising results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Right to object (opt-out): We refer to the privacy and advertising settings in users' profiles on the Facebook platforms as well as to Facebook's consent procedures and contact options for exercising rights of access and other data subject rights, as described in Facebook's privacy policy; Further information: Users' event data, i.e. behavioural and interest information, is processed for the purposes of targeted advertising and target group formation on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). Joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Google Ad Manager: We use the "Google Ad Manager" service in order to place advertisements within the Google advertising network (e.g. in search results, in videos, on websites, etc.). Google Ad Manager is characterised by the fact that advertisements are displayed in real time on the basis of the presumed interests of users. This allows us to display advertisements for our online offering to users who may have a potential interest in our offering or who have previously shown an interest in it, and to measure the success of the advertisements; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/; data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms; where Google acts as a processor, data processing terms for Google advertising products and standard contractual clauses for third-country transfers of data: https://business.safety.google/adsprocessorterms.
  • Google Ads and conversion measurement: Online marketing procedure for the purpose of placing content and advertisements within the advertising network of the service provider (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether users took them as an occasion to interact with the advertisements and to make use of the offers advertised (so-called conversion). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR), legitimate interests (Art. 6(1)(f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
  • Google Ads remarketing: Google remarketing, also referred to as retargeting, is a technology by means of which users who use an online service are added to a pseudonymous remarketing list, so that advertisements can be displayed to those users on other online offerings on the basis of their visit to the online service; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
  • Enhanced conversions for Google Ads: When customers click on our Google advertisements and subsequently make use of the advertised service (so-called "conversion"), the data entered by the user, such as the e-mail address, name, home address or telephone number, may be transmitted to Google. The hash values are then matched with users' existing Google accounts in order to better evaluate and improve users' interaction with the advertisements (e.g. clicks or views) and thus their performance; Legal bases: Consent (Art. 6(1)(a) GDPR). Website: https://support.google.com/google-ads/answer/9888656.
  • Instagram advertisements: Placement of advertisements within the Instagram platform and evaluation of the advertising results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Right to object (opt-out): We refer to the privacy and advertising settings in users' profiles on the Instagram platform as well as to Instagram's consent procedures and contact options for exercising rights of access and other data subject rights in Instagram's privacy policy; Further information: Users' event data, i.e. behavioural and interest information, is processed for the purposes of targeted advertising and target group formation on the basis of the agreement on joint controllership ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). Joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Pinterest tag: Interest- and behaviour-based measurement and analysis of users' interaction with our online services (in particular page visits, search entries, transactions, video and page views as well as time and duration) for the purpose of forming target groups for the display of content and advertising content within the Pinterest platform and of the partners participating in its advertising network; Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://help.pinterest.com/en/business/article/track-conversions-with-pinterest-tag; Privacy policy: https://policy.pinterest.com/en/privacy-policy; Right to object (opt-out): https://help.pinterest.com/en/article/personalized-ads-on-pinterest. Further information: Agreement on joint controllership in the "Pinterest Advertising Services Agreement, Exhibit B: Pinterest Joint Controller Addendum" https://business.pinterest.com/pinterest-advertising-services-agreement/.

Presence on social networks (social media)

We maintain online presences within social networks and process users' data in this context in order to communicate with the users active there or to offer information about us.

We point out that users' data may be processed outside the European Union in this context. This may give rise to risks for users, because it could, for example, make the enforcement of users' rights more difficult.

Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created on the basis of users' usage behaviour and the resulting interests. The usage profiles may in turn be used, for example, to place advertisements within and outside the networks which presumably correspond to the interests of users. For these purposes, cookies are generally stored on users' computers, in which the usage behaviour and interests of users are stored. Furthermore, data may also be stored in the usage profiles independently of the devices used by users (in particular where users are members of the respective platforms and are logged in to them).

For a detailed description of the respective forms of processing and the objection options (opt-out), we refer to the privacy policies and information of the operators of the respective networks.

In the case of requests for information and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the providers have access to users' data in each case and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you may contact us.

  • Types of data processed: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Contact requests and communication; feedback (e.g. collecting feedback via an online form). Marketing.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Instagram: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Facebook pages: Profiles within the social network Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not the further processing) of data of visitors to our Facebook page (so-called "fan page"). This data includes information on the types of content that users view or interact with, or the actions they take (see under "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see under "Device information" in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under "How do we use this information?", Facebook also collects and uses information in order to provide analytics services, so-called "page insights", to page operators so that they gain insights into how people interact with their pages and the content connected with them. We have concluded a special agreement with Facebook ("Page Insights Information", https://www.facebook.com/legal/terms/page_controller_addendum), which in particular governs the security measures Facebook must observe and in which Facebook has agreed to fulfil data subject rights (i.e. users may, for example, address requests for information or erasure directly to Facebook). Users' rights (in particular to access, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the "Page Insights Information" (https://www.facebook.com/legal/terms/information_about_page_insights_data). Joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which in particular concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA.
  • Pinterest: Social network; Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.pinterest.com. Privacy policy: https://policy.pinterest.com/en/privacy-policy.

Plug-ins and embedded functions and content

We integrate functional and content elements into our online offering which are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may be, for example, graphics, videos or city maps (hereinafter uniformly referred to as "content").

Such integration always requires that the third-party providers of this content process the IP address of users, as without the IP address they would not be able to send the content to their browser. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may furthermore use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. "Pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may furthermore be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and further information on the use of our online offering, and may also be combined with such information from other sources.

  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, consent status); content data (e.g. entries in online forms).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and user-friendliness; provision of contractual services and fulfilment of contractual obligations; marketing; profiles with user-related information (creation of user profiles). Content delivery network (CDN).
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Instagram plug-ins and content: Instagram plug-ins and content - These may include, for example, content such as images, videos or text and buttons with which users can share content of this online offering within Instagram. - We are jointly responsible with Meta Platforms Ireland Limited for the collection or receipt in the context of a transmission (but not the further processing) of "event data" which Facebook collects by means of Instagram functions (e.g. embedding functions for content) executed on our online offering, or receives in the context of a transmission for the following purposes: a) display of content and advertising information corresponding to the presumed interests of users; b) delivery of commercial and transaction-related messages (e.g. addressing users via Facebook Messenger); c) improvement of ad delivery and personalisation of functions and content (e.g. improving the recognition of which content or advertising information presumably corresponds to the interests of users). We have concluded a special agreement with Facebook ("Controller Addendum", https://www.facebook.com/legal/controller_addendum), which in particular governs the security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfil data subject rights (i.e. users may, for example, address requests for information or erasure directly to Facebook). Note: where Facebook provides us with measurements, analyses and reports (which are aggregated, i.e. contain no information on individual users and are anonymous for us), this processing does not take place within the framework of joint controllership but on the basis of a data processing agreement ("Data Processing Terms", https://www.facebook.com/legal/terms/dataprocessing), the "Data Security Terms" (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the USA, on the basis of standard contractual clauses ("Facebook EU Data Transfer Addendum", https://www.facebook.com/legal/EU_data_transfer_addendum). Users' rights (in particular to access, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.instagram.com. Privacy policy: https://instagram.com/about/legal/privacy/.
  • Pinterest plug-ins and content: Pinterest plug-ins and content - These may include, for example, content such as images, videos or text and buttons with which users can share content of this online offering within Pinterest; Service provider: Pinterest Inc., 635 High Street, Palo Alto, CA 94301, USA; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.pinterest.com. Privacy policy: https://policy.pinterest.com/en/privacy-policy.
  • reCAPTCHA: We integrate the "reCAPTCHA" function in order to be able to recognise whether entries (e.g. in online forms) are made by humans and not by automatically acting machines (so-called "bots"). The data processed may include IP addresses, information on operating systems, devices or browsers used, language settings, location, mouse movements, keystrokes, time spent on websites, previously visited websites, interactions with reCAPTCHA on other websites, possibly cookies, and results of manual recognition processes (e.g. answering questions posed or selecting objects in images). Data processing takes place on the basis of our legitimate interest in protecting our online offering from abusive automated crawling and spam; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.google.com/recaptcha/; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plug-in: https://tools.google.com/dlpage/gaoptout, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff.
  • Cloudflare: Content delivery network (CDN) - service which enables the content of an online offering, in particular large media files such as graphics or program scripts, to be delivered more quickly and securely with the help of regionally distributed servers connected via the internet; Service provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.cloudflare.com; Privacy policy: https://www.cloudflare.com/privacypolicy/; Data processing agreement: https://www.cloudflare.com/cloudflare-customer-dpa/. Basis for third-country transfers: Data Privacy Framework (DPF).

Amendment and updating of the privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We amend the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.

Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and we ask you to verify the information before making contact.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Where the terms are defined by law, their statutory definitions apply. The following explanations, on the other hand, are intended primarily to aid understanding.

  • A/B testing: A/B tests serve to improve the user-friendliness and performance of online offerings. In this process, users are presented, for example, with different versions of a web page or its elements, such as input forms, which may differ in the placement of content or the labelling of navigation elements. It is then possible to determine, on the basis of user behaviour, e.g. longer time spent on the website or more frequent interaction with the elements, which of these web pages or elements better correspond to users' needs.
  • Content delivery network (CDN): A "content delivery network" (CDN) is a service which enables the content of an online offering, in particular large media files such as graphics or program scripts, to be delivered more quickly and securely with the help of regionally distributed servers connected via the internet.
  • Cross-device tracking: Cross-device tracking is a form of tracking in which users' behavioural and interest information is recorded across devices in so-called profiles by assigning an online identifier to users. This allows user information to be analysed independently of the browsers or devices used (e.g. mobile phones or desktop computers), generally for marketing purposes. With most providers, the online identifier is not linked to plain data such as names, postal addresses or e-mail addresses.
  • Click tracking: Click tracking makes it possible to monitor users' movements within an entire online offering. Since the results of these tests are more accurate if the interaction of users can be tracked over a certain period of time (e.g. so that we can find out whether a user likes to return), cookies are generally stored on users' computers for these testing purposes.
  • Conversion measurement: Conversion measurement (also referred to as "visit action evaluation") is a procedure by means of which the effectiveness of marketing measures can be determined. For this purpose, a cookie is generally stored on users' devices within the websites on which the marketing measures take place and is then retrieved again on the target website. For example, this allows us to determine whether the advertisements we have placed on other websites were successful.
  • Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles with user-related information: The processing of "profiles with user-related information", or "profiles" for short, comprises any form of automated processing of personal data consisting of the use of such personal data to evaluate, analyse or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
  • Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and may comprise the behaviour or interests of visitors in certain information, such as the content of web pages. With the help of reach analysis, operators of online offerings can, for example, identify at what times users visit their web pages and what content they are interested in. This enables them, for example, to better adapt the content of the web pages to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used in order to recognise returning visitors and thus obtain more accurate analyses of the use of an online offering.
  • Remarketing: "Remarketing" or "retargeting" refers to the practice of noting, e.g. for advertising purposes, which products a user has shown an interest in on a website, in order to remind the user of those products on other websites, e.g. in advertisements.
  • Tracking: "Tracking" refers to the practice of tracing users' behaviour across several online offerings. As a rule, behavioural and interest information relating to the online offerings used is stored in cookies or on the servers of the providers of the tracking technologies (so-called profiling). This information can then be used, for example, to display advertisements to users which are likely to correspond to their interests.
  • Controller: "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: "Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, evaluation, storage, transmission or erasure.
  • Target group formation: Target group formation (in English "custom audiences") refers to the determination of target groups for advertising purposes, e.g. the display of advertisements. For example, on the basis of a user's interest in certain products or topics on the internet it may be concluded that this user is interested in advertisements for similar products or in the online shop in which they viewed the products. "Lookalike audiences" (or similar target groups), on the other hand, refers to the practice of displaying content deemed suitable to users whose profiles or interests presumably correspond to those of the users for whom the profiles were created. Cookies and web beacons are generally used for the purposes of forming custom audiences and lookalike audiences.