Política de privacidad
Gracias por su interés en nuestra tienda en línea. La protección de su intimidad es muy importante para nosotros. A continuación le informamos detalladamente sobre cómo tratamos sus datos.
1. datos de acceso y alojamiento
Puede visitar nuestros sitios web sin proporcionar ninguna información personal. Cada vez que usted accede a un sitio web, el servidor web guarda automáticamente el denominado archivo de registro del servidor, que contiene, por ejemplo, el nombre del archivo solicitado, su dirección IP, la fecha y hora del acceso, la cantidad de datos transferidos y el proveedor solicitante (datos de acceso) y documenta el acceso.
Estos datos de acceso se evalúan únicamente con el fin de garantizar un funcionamiento sin problemas del sitio y mejorar nuestros servicios. De conformidad con el art. 6 párr. 1 p. 1 lit. f DSGVO, esto sirve para proteger nuestros intereses legítimos en la presentación correcta de nuestra oferta, que superan nuestros intereses en el contexto de un equilibrio de intereses. Todos los datos de acceso se borrarán a más tardar siete días después de que finalice su visita al sitio.
Servicios de alojamiento por parte de un proveedor externo
Como parte del procesamiento en nuestro nombre, un proveedor externo nos proporciona los servicios para alojar y mostrar el sitio web. Esto sirve para proteger nuestros intereses legítimos en la correcta presentación de nuestra oferta, que prevalecen en el contexto de un equilibrio de intereses. Todos los datos recogidos durante el uso de este sitio web o en los formularios facilitados a tal efecto en la tienda en línea, tal como se describe a continuación, se procesan en sus servidores. El procesamiento en otros servidores sólo tiene lugar dentro del marco aquí explicado.
Este proveedor de servicios se encuentra en EE.UU. y está certificado por el Escudo de Privacidad UE-EE.UU. Aquí puede consultar un certificado actualizado. Basándose en este acuerdo entre EE.UU. y la Comisión Europea, esta última ha determinado un nivel adecuado de protección de datos para las empresas certificadas conforme al Escudo de la privacidad.
2. recopilación y uso de datos para la tramitación de contratos y al abrir una cuenta de cliente
Recopilamos datos personales cuando usted nos los facilita voluntariamente como parte de su pedido, al ponerse en contacto con nosotros (por ejemplo, a través de un formulario de contacto o por correo electrónico) o al abrir una cuenta de cliente. Los campos obligatorios están marcados como tales porque en estos casos necesitamos absolutamente los datos para procesar el contrato, o para procesar su contacto o abrir una cuenta de cliente, y usted no puede completar el pedido y/o abrir una cuenta o enviar el contacto sin proporcionarlos. Los datos que se recogen pueden verse en los respectivos formularios de entrada. Utilizamos los datos que nos facilita de conformidad con el art. 6, apdo. 1, sección 1, letra b del DSGVO para tramitar el contrato y responder a sus consultas. Tras la finalización de la tramitación del contrato o la eliminación de su cuenta de cliente, se restringirá el tratamiento posterior de sus datos y se eliminarán una vez transcurridos los plazos de conservación previstos en la legislación fiscal y mercantil, a menos que haya dado su consentimiento expreso para el uso posterior de sus datos o que nos reservemos el derecho a utilizar los datos más allá de lo permitido por la ley y sobre lo que le informamos en esta declaración. La eliminación de su cuenta de cliente es posible en cualquier momento y puede hacerse enviando un mensaje a la opción de contacto descrita a continuación o a través de una función prevista a tal efecto en la cuenta de cliente.
3. transmisión de datos
Para el cumplimiento del contrato de conformidad con el art. 6 párr. 1 p. 1 lit. b DSGVO, transmitimos sus datos a la empresa de transporte encargada de la entrega, en la medida en que sea necesario para la entrega de la mercancía solicitada. En función del proveedor de servicios de pago que seleccione en el proceso de pedido, transmitimos los datos de pago recogidos a tal efecto a la entidad de crédito encargada del pago y, en su caso, a los proveedores de servicios de pago encargados por nosotros o al servicio de pago seleccionado. En algunos casos, los proveedores de servicios de pago seleccionados también recopilan estos datos ellos mismos si usted crea una cuenta con ellos. En este caso, deberá registrarse en el proveedor de servicios de pago con sus datos de acceso durante el proceso de pedido. A este respecto, se aplica la política de privacidad del proveedor de servicios de pago correspondiente.
Utilizamos proveedores de servicios de pago con sede en un país no perteneciente a la Unión Europea. La transferencia de datos personales a esta empresa sólo tiene lugar en el ámbito de lo necesario para el cumplimiento del contrato.
Transmisión de datos a proveedores de servicios de envío
Si nos ha dado su consentimiento expreso para ello durante o después de su pedido, transmitiremos su dirección de correo electrónico al proveedor de servicios de envío seleccionado sobre la base de este consentimiento de conformidad con el art. 6 párr. 1 p. 1 lit. a DSGVO para que puedan ponerse en contacto con usted antes de la entrega con fines de notificación o coordinación de la entrega.
Puede revocar su consentimiento en cualquier momento enviando un mensaje a la opción de contacto descrita a continuación o directamente al proveedor de servicios de envío a la dirección de contacto indicada más abajo. Después de la revocación, borraremos sus datos proporcionados para este fin, a menos que usted haya consentido expresamente el uso posterior de sus datos o nos reservemos el derecho a utilizar datos más allá de esto, lo cual está permitido por la ley y sobre lo cual le informamos en esta declaración.
DHL
Heinrich-Brüning-Str. 5
53113
Bonn
Ofertas y ventajas de Sovendus GmbH:
Para poder seleccionar una oferta de vales que le interese en ese momento, transmitimos el valor hash de su dirección de correo electrónico y su dirección IP a Sovendus GmbH, Hermann-Veit-Str. 6, 76135 Karlsruhe (Sovendus) de forma seudonimizada y encriptada (Art. 6 Párr. 1 f DSGVO). Sovendus utiliza el valor hash seudonimizado de la dirección de correo electrónico para tener en cuenta una posible objeción a la publicidad (art. 21 apdo. 3, art. 6 apdo. 1 c DSGVO). Sovendus utiliza la dirección IP exclusivamente con fines de seguridad de los datos y, por lo general, se anonimiza al cabo de siete días (art. 6, apdo. 1 f DSGVO). Además, transmitimos el número de pedido, el valor del pedido con la divisa, el identificador de sesión, el código de cupón y la marca de tiempo a Sovendus de forma seudonimizada para fines de facturación (Art. 6 párrafo 1 f DSGVO). Si está interesado en una oferta de vales de Sovendus, no hay objeción publicitaria a su dirección de correo electrónico y hace clic en el banner del vale que sólo se muestra en este caso, transmitimos su título, nombre, código postal, país y dirección de correo electrónico de forma codificada a Sovendus para la preparación del vale (Art. 6 párrafo 1 b, f DSGVO).
Para la selección de una oferta ventajosa que le interese actualmente a nivel regional, transmitimos su título, año de nacimiento, país, código postal, valor hash de la dirección de correo electrónico y su dirección IP a Sovendus GmbH, Hermann-Veit-Str. 6, 76135 Karlsruhe (Sovendus) de forma seudonimizada y encriptada (Art. 6 párrafo 1 f DSGVO). El valor hash seudonimizado de la dirección de correo electrónico también será utilizado por Sovendus para tener en cuenta cualquier objeción a la publicidad (Art. 21 párrafo 3, Art. 6 párrafo 1 c DSGVO). Sovendus utiliza la dirección IP exclusivamente con fines de seguridad de los datos y, por lo general, se anonimiza al cabo de siete días (art. 6, apdo. 1 f DSGVO).
En la medida en que sea necesario para la respectiva oferta de ventajas, su nombre, dirección, dirección de correo electrónico y/o número de teléfono serán transmitidos por nosotros de forma encriptada a Sovendus cuando haga clic en la oferta de ventajas con el fin de preparar la solicitud personalizada para la oferta de ventajas del proveedor del producto (Art. 6 párrafo 1 b, f DSGVO).
Para más información sobre el tratamiento de sus datos por parte de Sovendus, consulte la información en línea sobre protección de datos en www.sovendus.de/datenschutz.
4. Envío de boletines a través de Klaviyo y publicidad postal
El envío de nuestros boletines por correo electrónico se realiza a través del proveedor de servicios técnicos "Klaviyo", 225 Franklin St, Boston, MA 02110, EE.UU. (http://www.klaviyo.com/), a quien transmitimos los datos facilitados durante el registro en el boletín. Esta transferencia tiene lugar de conformidad con el art. 6 (1) lit. f DSGVO y sirve a nuestro interés legítimo de utilizar un sistema de boletín de noticias que sea eficaz en la publicidad, seguro y fácil de usar. Ten en cuenta que tus datos se transfieren normalmente a un servidor de Klaviyo en EE.UU. y se almacenan allí.
Klaviyo utiliza esta información para enviar el boletín en nuestro nombre. Klaviyo no utiliza los datos de los destinatarios de nuestros boletines para escribirles ella misma ni para cederlos a terceros. Para proteger tus datos en EEUU, tenemos un acuerdo de procesamiento de datos con Klaviyo ("Acuerdo de Procesamiento de Datos"), en el que Klaviyo se compromete a proteger los datos de nuestros usuarios, a procesarlos en nuestro nombre de acuerdo con sus disposiciones de protección de datos y, en particular, a no transmitirlos a terceros.
Puedes consultar la política de protección de datos de Klaviyo aquí: https://www.klaviyo.com/privacy.
Publicidad postal y su derecho de oposición
Además, nos reservamos el derecho a utilizar su nombre y apellidos, así como su dirección postal, para nuestros propios fines publicitarios, por ejemplo, para enviarle ofertas interesantes e información sobre nuestros productos por correo postal. Esto sirve para proteger nuestros intereses legítimos de dirigirnos a nuestros clientes de forma publicitaria de acuerdo con el Art. 6 Párr. 1 S. 1 lit. f DSGVO.
Los envíos publicitarios se realizan en el marco de un tratamiento en nuestro nombre por parte de un proveedor de servicios al que transmitimos sus datos con este fin.
Puede oponerse al almacenamiento y uso de sus datos para estos fines en cualquier momento enviando un mensaje a la opción de contacto descrita a continuación.
5. uso de datos para el procesamiento de pagos
Comprobación de identidad y solvencia al seleccionar los servicios de pago de Klarna.
En colaboración con Klarna Bank AB (publ), Sveavägen 46, 111 34 Estocolmo, Suecia, ofrecemos las siguientes opciones de pago. El pago se realiza a Klarna en cada caso:
Factura: El plazo de pago es de 14 días a partir de la fecha de envío de la mercancía/billete/ o, en el caso de otros servicios, de la prestación del servicio. Encontrará las condiciones de compra de facturas para los envíos a Alemania aquí y para los envíos a Austria aquí.
Compra a plazos (sólo disponible en Alemania): Con el servicio de financiación de Klarna, puedes pagar tu compra de forma flexible en cuotas mensuales de al menos 1/24 del importe total (pero de al menos 6,95 euros) o en las condiciones que se especifiquen en la caja. El pago a plazos vence al final de cada mes, después de que Klarna le envíe una factura mensual. Aquí encontrará más información sobre la compra a plazos, incluidas las Condiciones Generales y la Información normalizada europea sobre el crédito al consumo.
El uso de los métodos de pago factura, compra a plazos requiere una comprobación de crédito positiva. En este sentido, transmitimos sus datos a Klarna con el fin de realizar comprobaciones de dirección y solvencia en el marco del inicio de la compra y la tramitación del contrato de compra. Por favor, comprenda que sólo podemos ofrecerle aquellos métodos de pago que estén permitidos en función de los resultados de la comprobación de crédito. Encontrará más información y las condiciones de uso de Klarna para Alemania aquí y para Austria aquí. Aquí encontrará información general sobre Klarna. Sus datos personales serán tratados por Klarna de acuerdo con la normativa de protección de datos aplicable y según lo especificado en la Política de Protección de Datos de Klarna Alemania/Austria.
6 Cookies y análisis web
Para hacer atractiva la visita a nuestro sitio web y permitir el uso de determinadas funciones, mostrar productos adecuados o realizar estudios de mercado, utilizamos las denominadas cookies en diversas páginas. Esto sirve para proteger nuestros intereses legítimos en una presentación optimizada de nuestra oferta, que prevalecen sobre nuestros intereses en el contexto de un equilibrio de intereses según el Art. 6 párrafo 1 p. 1 lit. f DSGVO. Las cookies son pequeños archivos de texto que se almacenan automáticamente en su dispositivo terminal. Algunas de las cookies que utilizamos se eliminan al final de la sesión del navegador, es decir, después de que usted cierre su navegador (las denominadas cookies de sesión). Otras cookies permanecen en su dispositivo final y nos permiten reconocer su navegador en su próxima visita (cookies persistentes). Puede averiguar durante cuánto tiempo se almacenan en la vista general en la configuración de cookies de su navegador web. Puede configurar su navegador de forma que se le informe sobre la instalación de cookies y decidir individualmente sobre su aceptación o excluir la aceptación de cookies para determinados casos o en general. Cada navegador difiere en la forma en que gestiona la configuración de las cookies. Esto se describe en el menú de ayuda de cada navegador, que explica cómo puede cambiar la configuración de las cookies. Puede encontrarlos para los respectivos navegadores en los siguientes enlaces:
Internet Explorer™: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies
Safari™: https://support.apple.com/kb/ph21411?locale=de_DE
Chrome™: http://support.google.com/chrome/bin/answer.py?hl=de&hlrm=es&answer=95647
Firefox™ https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Opera™ : http://help.opera.com/Windows/10.20/de/cookies.html
No aceptar las cookies puede limitar la funcionalidad de nuestro sitio web.
Uso de Google (Universal) Analytics para el análisis web
Este sitio web utiliza Google (Universal) Analytics, un servicio de análisis web de Google LLC (www.google.de), para el análisis del sitio web. Esto sirve para proteger nuestros intereses legítimos en una presentación optimizada de nuestra oferta, que prevalecen sobre nuestros intereses en el contexto de un equilibrio de intereses de conformidad con el Art. 6 párrafo 1 p. 1 lit. f DSGVO. Google (Universal) Analytics utiliza métodos que permiten analizar el uso que usted hace del sitio web, como las cookies. La información recopilada automáticamente sobre su uso de este sitio web se transfiere generalmente a un servidor de Google en los EE.UU. y se almacena allí. Al activar la anonimización de IP en este sitio web, la dirección IP se acorta antes de su transmisión dentro de los Estados miembros de la Unión Europea o en otros Estados contratantes del Acuerdo sobre el Espacio Económico Europeo. Sólo en casos excepcionales se transmitirá la dirección IP completa a un servidor de Google en EE.UU. y se acortará allí. La dirección IP anonimizada transmitida por su navegador como parte de Google Analytics no se fusionará con otros datos de Google. Una vez finalizada la finalidad y el uso de Google Analytics por nuestra parte, se eliminarán los datos recopilados en este contexto.
Google LLC tiene su sede en EE.UU. y está certificada por el Escudo de Privacidad UE-EE.UU. Aquí puede consultar un certificado actualizado. Basándose en este acuerdo entre EE.UU. y la Comisión Europea, esta última ha determinado un nivel adecuado de protección de datos para las empresas certificadas conforme al Escudo de la privacidad.
Puede evitar la recopilación de los datos generados por la cookie y relacionados con su uso del sitio web (incluida su dirección IP) por parte de Google, así como el tratamiento de estos datos por parte de Google, descargando e instalando el complemento del navegador disponible en el siguiente enlace: http://tools.google.com/dlpage/gaoptout?hl=de.
Como alternativa al plugin del navegador, puede hacer clic en este enlace para evitar que Google Analytics recopile datos en este sitio web en el futuro. Esto colocará una cookie de exclusión en su dispositivo terminal. Si borra sus cookies, deberá volver a hacer clic en el enlace.
7 Publicidad a través de redes de marketing
Google AdWords Remarketing
Utilizamos Google AdWords para anunciar este sitio web en los resultados de búsqueda de Google y en sitios web de terceros. Con este fin, Google instala la denominada cookie de remarketing cuando usted visita nuestro sitio web, lo que permite automáticamente la publicidad basada en intereses mediante una CookieID seudónima y sobre la base de las páginas que usted ha visitado. Esto sirve para proteger nuestros intereses legítimos en la comercialización óptima de nuestro sitio web, que prevalecen sobre nuestros intereses en el contexto de un equilibrio de intereses de conformidad con el Art. 6 párrafo 1 p. 1 lit. f DSGVO. Una vez finalizada la finalidad y el uso de Google AdWords Remarketing por nuestra parte, se eliminarán los datos recopilados en este contexto.
Cualquier otro tratamiento de datos sólo se llevará a cabo si ha dado su consentimiento para que Google vincule su historial de navegación web y de aplicaciones a su cuenta de Google y utilice la información de su cuenta de Google para personalizar los anuncios que ve en la web. En este caso, si inician sesión en Google mientras visitan nuestro sitio web, Google utilizará sus datos junto con los datos de Google Analytics para crear y definir listas de grupos objetivo para el remarketing entre dispositivos. Para ello, sus datos personales serán vinculados temporalmente por Google con los datos de Google Analytics con el fin de formar grupos objetivo.
Google AdWords Remarketing es una oferta de Google LLC (www.google.de). Google LLC tiene su sede en EE.UU. y está certificada por el Escudo de Privacidad UE-EE.UU. Aquí puede consultar un certificado actualizado. Basándose en este acuerdo entre EE.UU. y la Comisión Europea, esta última ha determinado un nivel adecuado de protección de datos para las empresas certificadas conforme al Escudo de la privacidad.
Puede desactivar la cookie de remarketing a través de este enlace. Además, puede obtener más información sobre la instalación de cookies y realizar ajustes al respecto en la Digital Advertising Alliance.
AdRoll Retargeting
A través de nuestro socio publicitario AdRoll Advertising Limited, Level 6, 1, Burlington Plaza, Burlington Road, Dublín 4, Irlanda, anunciamos este sitio web en los resultados de búsqueda y en sitios web de terceros. Para ello, cuando visita nuestro sitio web, estos proveedores o sus socios instalan automáticamente una cookie que permite la publicidad basada en intereses mediante un CookieID seudónimo y en función de las páginas que ha visitado. Esto sirve para proteger nuestros intereses legítimos en la comercialización óptima de nuestro sitio web, que prevalecen en el contexto de un equilibrio de intereses, de conformidad con el Art. 6 párrafo 1 p. 1 lit. f DSGVO. Una vez finalizada la finalidad y el uso de AdRoll Retargeting por nuestra parte, se eliminarán los datos recopilados en este contexto.
Puede desactivar la cookie de reorientación haciendo clic en uno de los siguientes enlaces: https://app.adroll.com/optout/safari
Alternativamente, puede desactivar el uso de cookies por parte de terceros visitando la página de desactivación de la Network Advertising Initiative.
Píxel de Facebook
Píxel de Facebook para la creación de Públicos Personalizados con concordancia avanzada de datos (con herramienta de consentimiento de cookies) Dentro de nuestra oferta online, se utiliza el denominado "píxel de Facebook" de la red social Facebook en modo de concordancia avanzada de datos, que es operado por Facebook Ireland Limited, 4 Grand Canal Quare, Dublín 2, Irlanda ("Facebook").
Sobre la base del consentimiento expreso del usuario, cuando un usuario hace clic en un anuncio reproducido en Facebook y colocado por nosotros, se añade un añadido a la URL de nuestra página enlazada mediante el píxel de Facebook. Tras el reenvío, este parámetro de URL se inscribe en el navegador del usuario mediante una cookie, que es instalada por nuestra propia página enlazada. Además, esta cookie recoge datos específicos del cliente, como la dirección de correo electrónico, que recopilamos en nuestro sitio web vinculado al anuncio de Facebook durante transacciones como operaciones de compra, inicios de sesión en cuentas o registros (cotejo de datos ampliado). A continuación, el píxel de Facebook lee la cookie y permite que los datos, incluidos los datos específicos del cliente, se envíen a Facebook.
Con la ayuda del píxel de Facebook con correspondencia de datos ampliada, es posible para Facebook, por un lado, determinar con precisión los visitantes de nuestra oferta en línea como grupo objetivo para la visualización de anuncios (los denominados "Facebook Ads"). En consecuencia, utilizamos el píxel de Facebook con concordancia de datos avanzada para mostrar los anuncios de Facebook colocados por nosotros sólo a aquellos usuarios de Facebook que también han mostrado interés en nuestra oferta en línea o que tienen ciertas características (por ejemplo, intereses en ciertos temas o productos determinados sobre la base de los sitios web visitados), que transmitimos a Facebook (los llamados "Públicos personalizados"). Con la ayuda del píxel de Facebook con concordancia de datos avanzada, también queremos asegurarnos de que nuestros anuncios de Facebook corresponden al interés potencial de los usuarios y no tienen un efecto de acoso. Esto nos permite seguir evaluando la eficacia de los anuncios de Facebook con fines estadísticos y de investigación de mercado mediante el seguimiento de si los usuarios fueron redirigidos a nuestro sitio web después de hacer clic en un anuncio de Facebook (la llamada "conversión"). En comparación con la variante estándar del píxel de Facebook, la función avanzada de correspondencia de datos nos ayuda a medir mejor la eficacia de nuestras campañas publicitarias al captar más conversiones atribuidas.
Todos los datos enviados son almacenados y procesados por Facebook, lo que permite vincularlos al perfil de usuario correspondiente y que Facebook los utilice para sus propios fines publicitarios, de acuerdo con la Política de uso de datos de Facebook (https://www.facebook.com/about/privacy/). Los datos pueden permitir a Facebook y a sus socios publicar anuncios dentro y fuera de Facebook. Estas operaciones de tratamiento sólo se llevarán a cabo si se da el consentimiento explícito de conformidad con el art. 6 (1) lit. a DSGVO. El consentimiento para el uso del píxel de Facebook sólo puede ser otorgado por usuarios mayores de 16 años. Si eres más joven, te rogamos que pidas permiso a tus tutores legales. La información generada por Facebook se transmite normalmente a un servidor de Facebook y se almacena allí; esto también puede implicar la transmisión a los servidores de Facebook Inc. en los EE.UU.. Puede revocar su consentimiento en cualquier momento con efectos para el futuro. Para ejercer su revocación, elimine la marca de verificación junto a la configuración del "píxel de Facebook" en la "Herramienta de consentimiento de cookies" integrada en el sitio web.
Google Ads (antes Adwords)
Nuestro sitio web utiliza las funciones de Google AdWords para anunciar este sitio web en los resultados de búsqueda de Google y en sitios web de terceros. El proveedor es Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, EE.UU. ("Google"). Para ello, Google instala una cookie en el navegador de su dispositivo que activa automáticamente la publicidad basada en intereses utilizando una ID de cookie seudónima y basándose en las páginas que visita. El tratamiento se basa en nuestro interés legítimo en la comercialización óptima de nuestro sitio web de conformidad con el art. 6 (1) lit. f DSGVO. El tratamiento posterior sólo tendrá lugar si ha acordado con Google que su historial de navegación en Internet y en aplicaciones sea vinculado por Google a su cuenta de Google y que la información de su cuenta de Google se utilice para personalizar sus anuncios en la web. Si inicia sesión en Google mientras navega por nuestro sitio web, Google utilizará sus datos con los datos de Google Analytics para crear y definir listas de objetivos para el remarketing entre dispositivos. Para ello, Google vincula temporalmente su información personal con los datos de Google Analytics para crear un grupo objetivo. Puede desactivar permanentemente la configuración de cookies descargando e instalando el complemento del navegador disponible en el siguiente enlace: https://www.google.com/settings/ads/onweb/
Alternativamente, puede ponerse en contacto con Digital Advertising Alliance en la dirección de Internet www.aboutads.info para obtener información sobre la configuración de cookies y realizar ajustes. Por último, puede configurar su navegador para que le informe sobre la instalación de cookies y decidir individualmente sobre su aceptación o excluir la aceptación de cookies para determinados casos o en general. No aceptar las cookies puede limitar la funcionalidad de nuestro sitio web. Google LLC, con sede en EE.UU., está certificada por el Escudo de Privacidad de EE.UU., que garantiza el cumplimiento del nivel de protección de datos en la UE.
En la medida en que la ley lo exige, hemos obtenido su consentimiento para el tratamiento de sus datos descrito anteriormente de conformidad con el art. 6, apdo. 1 lit. a DSGVO. Puede revocar su consentimiento en cualquier momento con efectos para el futuro. Para ejercer su revocación, desactive este servicio en la "Herramienta de consentimiento de cookies" proporcionada en el sitio web o, alternativamente, siga la opción descrita anteriormente para realizar una objeción.
Puede encontrar más información y disposiciones de protección de datos sobre publicidad y Google en: http://www.google.com/policies/technologies/ads/
Pinterest tag conversion tracking
Este sitio web utiliza la tecnología de seguimiento de conversiones "Pinterest Tag" de Pinterest Europe Ltd, Palmerston House, 2nd Floor, Fenian Street, Dublín 2, Irlanda ("Pinterest"). Si ha llegado a nuestro sitio web desde un pin en Pinterest, instalaremos una cookie en su ordenador, que interactúa con una "etiqueta" también implementada en forma de código JavaScript de Pinterest. Las cookies son pequeños archivos de texto que se almacenan en su dispositivo final. Estas cookies pierden su validez a los 180 días y no se utilizan para la identificación personal. Si el usuario es redirigido desde un pin en Pinterest a páginas de este sitio web y la cookie aún no ha caducado, la etiqueta registra ciertos datos predefinidos por nosotros;
acciones de los usuarios y puede realizar un seguimiento de las mismas (por ejemplo, transacciones completadas, clientes potenciales, búsquedas en el sitio web, vistas de páginas de productos). Cuando se realiza una acción de este tipo, su navegador envía una solicitud HTTP al servidor de Pinterest a través de la etiqueta Pinterest de la cookie, con la que se transmite determinada información sobre la acción (incluido el tipo de acción, la hora, el tipo de navegador del dispositivo final). A través de esta transmisión, Pinterest puede crear estadísticas sobre el comportamiento de uso en nuestro sitio web después de reenviar un Pin de Pinterest, que nos sirven para optimizar nuestra oferta. Si se procesan datos personales del usuario en el proceso, esto se hace de acuerdo con el Art. 6 (1) lit. f DSGVO sobre la base de nuestro interés legítimo en la evaluación estadística del éxito de los anuncios de productos en Pinterest y el comportamiento de compra de los usuarios y, por lo tanto, sirve para optimizar nuestra oferta en línea. Sin embargo, no recibimos ninguna información con la que se pueda identificar personalmente a los usuarios. Si no desea participar en el seguimiento, puede oponerse desactivando la cookie de seguimiento de conversión de etiquetas de Pinterest a través de su navegador de Internet en la configuración de usuario. En ese caso, no se le incluirá en las estadísticas de seguimiento de conversiones. Alternativamente, puede comprobar si las cookies publicitarias de Microsoft están instaladas en su navegador y desactivarlas utilizando la página de desactivación para consumidores de la UE http://www.youronlinechoices.com/de/praferenzmanagement/. También puede desactivar las cookies publicitarias haciendo clic en el siguiente enlace. Puede obtener más información sobre las disposiciones de protección de datos de Pinterest en la siguiente dirección de Internet: https://policy.pinterest.com/de/privacy-policy En la medida en que sea legalmente necesario, hemos obtenido su consentimiento de conformidad con el art. 6, apdo. 1 lit. a DSGVO para el tratamiento de sus datos tal y como se ha descrito anteriormente. Puede revocar su consentimiento en cualquier momento con efectos para el futuro. Para ejercer su revocación, siga la opción descrita anteriormente para presentar una objeción.
Píxel de Snapchat
Este sitio web utiliza el "Snapchat Pixel" de Snap Inc, 63 Market Street, Venice, CA 90291, USA. Snapchat está certificada por el Escudo de Privacidad UE-EE.UU. y ofrece así una garantía de cumplimiento de la legislación europea sobre protección de datos.
El tratamiento de datos por parte de Snap Inc. se lleva a cabo en el marco de la Política de Uso de Datos de Snapchat. Encontrará más información y orientación en la Política de uso de datos de Snapchat: https://www.snap.com/de-DE/privacy/privacy-by-product/.
En el informe de ayuda de Snapchat, encontrará más información sobre el píxel de Snapchat y su: https://businesshelp.snapchat.com/en-US/a/snap-pixel-about.
Para el análisis, la optimización y el funcionamiento económico de nuestro sitio web, utilizamos el píxel de Snapchat. Mediante el uso del píxel de Snapchat, Snap Inc. puede determinar los visitantes de nuestro sitio web como grupo objetivo para la visualización de anuncios (los denominados "anuncios de Snapchat"). En consecuencia, utilizamos el píxel de Snapchat para mostrar los anuncios de Snapchat publicados por nosotros únicamente a aquellos usuarios de Snapchat que también hayan mostrado interés en nuestra oferta en línea o que tengan determinadas características (por ejemplo, intereses en determinados temas o productos determinados en función de los sitios web visitados) que transmitamos a Snapchat (los denominados "Públicos personalizados").
Con la ayuda del píxel de Snapchat, también queremos garantizar que nuestros anuncios de Snapchat se correspondan con el interés potencial de los usuarios y no tengan un efecto acosador. El píxel de Snapchat también nos permite realizar un seguimiento de la eficacia de los anuncios de Snapchat con fines estadísticos y de investigación de mercado, viendo si los usuarios fueron redirigidos a nuestro sitio web después de hacer clic en un anuncio de Snapchat (lo que se denomina "conversión").
La base jurídica para el tratamiento de datos personales mediante píxeles de Snapchat es el art. 6 (1) (f) DSGVO, es decir, un interés legítimo por nuestra parte. Nuestro interés legítimo reside concretamente en el análisis, la optimización y el funcionamiento económico de nuestro sitio web y nuestras ofertas en línea.
Puedes oponerte a la recopilación por parte del píxel de Snapchat y al uso de tus datos para la visualización de anuncios de Snapchat. Para ajustar qué tipos de anuncios se te muestran dentro de Snapchat, puedes acceder a la función disponible en la aplicación Snapchat. Además, puede darse de baja del uso de cookies utilizadas para medir el alcance y con fines publicitarios a través de la página de exclusión de la Network Advertising Initiative (http://optout.networkadvertising.org/) y, además, del sitio web estadounidense (http://www.aboutads.info/choices) o del sitio web europeo (http://www.youronlinechoices.com/uk/your-ad-choices/).
8. Tratamiento de datos en las redes sociales
Estamos representados en las redes sociales para presentar allí nuestra empresa y nuestros servicios.
Los operadores de estas redes tratan regularmente los datos de sus usuarios con fines publicitarios. Entre otras cosas, crean perfiles de usuarios a partir de su comportamiento en línea, que se utilizan, por ejemplo, para mostrar en las páginas de las redes y en otros lugares de Internet publicidad que corresponde a los intereses de los usuarios. Para ello, los operadores de las redes almacenan información sobre el comportamiento de los usuarios en cookies en los ordenadores de los usuarios. Además, no puede descartarse que los operadores fusionen esta información con otros datos.
Los usuarios pueden obtener más información e instrucciones sobre cómo oponerse al tratamiento por parte de los operadores del sitio en las declaraciones de protección de datos de los respectivos operadores que se enumeran a continuación. También puede ocurrir que los operadores o sus servidores estén situados en países no pertenecientes a la UE, de modo que traten los datos allí. Esto puede acarrear riesgos para los usuarios, por ejemplo, porque es más difícil hacer valer sus derechos o porque los organismos gubernamentales tienen acceso a los datos. Si los usuarios de las redes se ponen en contacto con nosotros a través de nuestros perfiles de empresa, tratamos los datos que nos facilitan para responder a las consultas. Se trata de nuestro interés legítimo, por lo que la base jurídica es el art. 6 párr. 1 p. 1 lit. f DSGVO.
Facebook
Mantenemos un perfil de empresa en Facebook. El operador es Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublín 2, Irlanda. La política de privacidad está disponible aquí: https://www.facebook.com/policy.php. Una forma de oponerse al tratamiento de datos es a través de la configuración de los anuncios: https://www.facebook.com/settings?tab=ads. Somos corresponsables del tratamiento de los datos de los visitantes de nuestro perfil sobre la base de un acuerdo en el sentido del art. 26 DSGVO con Facebook. Facebook explica exactamente qué datos se procesan en https://www.facebook.com/legal/terms/information_about_page_insights_data. Los interesados pueden ejercer sus derechos tanto contra nosotros como contra Facebook. Sin embargo, según nuestro acuerdo con Facebook, estamos obligados a reenviar las solicitudes a Facebook. Por lo tanto, los interesados recibirán una respuesta más rápida si se ponen en contacto directamente con Facebook.
Instagram
Mantenemos un perfil de empresa en Instagram. El operador es Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublín 2, Irlanda. La política de privacidad está disponible aquí: https://help.instagram.com/519522125107875.
Tiktok
Mantenemos un perfil de empresa en Tiktok. El operador es musical.ly Inc, 10351 Santa Monica Blvd #310, Los Angeles, CA 90025 USA. La política de privacidad está disponible aquí: https://www.tiktok.com/de/privacy-policy.
Pinterest
Mantenemos un perfil de empresa en Pinterest. El operador es Pinterest Inc, 635 High Street, Palo Alto, CA, 94301, USA. La política de privacidad está disponible aquí: https://about.pinterest.com/de/privacy-policy. Una forma de oponerse al tratamiento de datos es a través de la configuración de los anuncios: https://about.pinterest.com/de/privacy-policy.
YouTube
Mantenemos un perfil de empresa en YouTube. El operador es Google Ireland Limited Gordon House, Barrow Street Dublín 4. Irlanda. La política de privacidad está disponible aquí: https://policies.google.com/privacy?hl=de.
9. opciones de contacto y sus derechos
Como interesado, tiene los siguientes derechos:
según el art. 15 de la DSGVO el derecho a solicitar información sobre sus datos personales procesados por nosotros en la medida especificada en el mismo;
según el art. 16 de la DSGVO el derecho a solicitar la corrección de datos personales inexactos o incompletos almacenados por nosotros sin demora;
según el art. 17 DSGVO el derecho a exigir la supresión de sus datos personales almacenados por nosotros, a menos que el tratamiento posterior
- sea necesario para el ejercicio del derecho a la libertad de expresión e información;
- para el cumplimiento de una obligación legal;
- por razones de interés público o
- para la formulación, el ejercicio o la defensa de reclamaciones judiciales
;
de conformidad con el art. 18 DSGVO el derecho a exigir la limitación del tratamiento de sus datos personales, en la medida en que
- usted impugne la exactitud de los datos;
- el tratamiento sea ilícito, pero usted se oponga a su supresión;
- ya no necesitemos los datos, pero usted los necesite para la formulación, el ejercicio o la defensa de reclamaciones judiciales o
- usted se oponga al tratamiento de sus datos personales de conformidad con el art. 21 DSGVO;
de conformidad con el art. 20 DSGVO, el derecho a recibir sus datos personales que nos haya facilitado en un formato estructurado, común y legible por máquina o a solicitar la transferencia a otro responsable del tratamiento;
de conformidad con el art. 77 DSGVO, el derecho a presentar una reclamación ante una autoridad de control. Por regla general, puede dirigirse a tal efecto a la autoridad de control de su lugar de residencia o de trabajo habitual o a la sede de nuestra empresa.
Si tiene alguna pregunta sobre la recogida, el tratamiento o el uso de sus datos personales, para obtener información, rectificación, bloqueo o supresión de datos, así como para revocar el consentimiento dado u oponerse a un determinado uso de los datos, póngase directamente en contacto con nosotros utilizando los datos de contacto que figuran en nuestro pie de imprenta.
********************************************************************
Derecho de oposición
En la medida en que tratemos datos personales como se ha explicado anteriormente para salvaguardar nuestros intereses legítimos que prevalecen en el contexto de una ponderación de intereses, puede oponerse a este tratamiento con efectos para el futuro. Si el tratamiento se lleva a cabo con fines de venta directa, puede ejercer este derecho en cualquier momento tal como se ha descrito anteriormente. Si el tratamiento se lleva a cabo con otros fines, sólo tendrá derecho a oponerse por motivos relacionados con su situación particular.
Una vez que haya ejercido su derecho de oposición, dejaremos de tratar sus datos personales para estos fines, a menos que podamos demostrar motivos legítimos imperiosos para el tratamiento que prevalezcan sobre sus intereses, derechos y libertades, o si el tratamiento es para el establecimiento, ejercicio o defensa de reclamaciones legales.
Esto no se aplica si el tratamiento tiene fines de marketing directo. En ese caso, no volveremos a tratar sus datos personales con este fin. ********************************************************************
Privacy policy
Information on the handling of personal data
We are very pleased about your interest in our website - and thus in our company. The protection of your private rights and freedoms is very important to us; we only use your data for the purposes intended. Since it is important to us that you are aware at all times of the extent to which we collect, use and, if necessary, transfer your data to third parties, we will provide you with the following comprehensive information on the processing of your personal data collected by us or stored by us.
In principle, you can use our pages without providing any data
Name and address of the responsible entity
Salelab GmbH
Patrick Block
Haydnstraße 28
88284 Wolpertswende
Germany
E-mail: support@salelab.de
Website: https://pamo-design.de
Name and address of the person responsible for data protection
Actuality of the privacy policy
To ensure that we always have up-to-date data protection information in connection with the services of our website, we use the CLOUD Privacy Policy service of Cookiebox GmbH from Münster.
Right
The EU General Data Protection Regulation (GDPR) provides for extensive rights for data subjects in Chapter III, which we explain to you accordingly below with regard to the processing of your personal data:
Right to information
This requirement concerns in particular information on the following details of data processing:
- Processing purposes
- Data categories
- If applicable, recipients or categories of recipients
- If applicable, the planned storage duration or the criteria for determining this duration.
- Note on the respective right of correction, deletion, restriction or objection
- Existence of the right to complain to a supervisory authority
- If applicable, origin of the data (if not collected from you)
- If applicable, existence of automated decision-making including profiling, including meaningful information about the logic involved, the scope and the effects to be expected
- If applicable, (planned) transfer to a third country or international organization
Right to rectification
We will correct any erroneous data immediately, provided that you inform us of the circumstance accordingly.
Right to erasure (right to be forgotten)
Provided that the processing is no longer necessary and one of the following conditions is met:
- Discontinuation of the purpose of processing
- Withdrawal of their consent and absence of any other legal basis for processing
- Objection to processing without an important reason to the contrary
- Unlawful processing
- Required to fulfill a legal obligation
- Data collection was carried out in accordance with Art. 8 (1) GDPR
Right to restriction of processing
Provided that one of the following conditions is met:
- You dispute the accuracy of your data (restriction can be made for the duration of the review on our side)
- In the event of unlawful processing and if the data is not to be deleted, restriction of processing shall take the place of deletion
- If the processing purposes cease to apply, at the same time you need your data for the assertion, exercise or defense of legal claims
- After you have lodged an objection pursuant to Art. 21 (1) GDPR and for the duration of the examination as to whether our legitimate reasons outweigh yours.
Right to data portability
If it is technically possible and does not affect the rights and freedoms of other persons, we will - at your request - transfer your data to another recipient (responsible party).
Right to object
If we collect or have collected and process personal data from you (on the basis of Art. 6 (1) e or f or Art. 9 (2) a GDPR), you have the right to object to the data processing (including profiling) at any time (with effect for the future). In exceptional cases, the objection may be ineffective, e.g. if we can demonstrate compelling interests worthy of protection for the processing that outweigh your interests or processing serves the assertion, exercise or defense of legal claims. If we process your personal data for the purpose of direct marketing, you have the right to object to such processing at any time. This also applies to profiling, insofar as it is related to such direct advertising. You also have the right to object to processing of your data concerning you which is carried out by us for scientific or historical research purposes or for statistical purposes pursuant to Article 89 (1) GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.
Automated decisions in individual cases including profiling
If we collect or have collected and process personal data from you, you have the right not to be subject to any decision based solely on automated processing - including profiling - which produces legal effects concerning you or similarly significantly affects you. Exceptions to this requirement apply if the decision is necessary for the conclusion or performance of a contract between you and us or you have expressly consented to the processing. In any case, we will take reasonable steps to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain the intervention of a person on our part, to express our own point of view and to contest the decision.
Right to revoke consent under data protection law
You have the right to revoke consent to the processing of personal data at any time.
General information on data processing on the website
The following information applies to the data processing on our website in general. If there are exceptions or additions to this information, these are described in detail in the relevant sections.
Data security information
We secure our website and other systems through technical and organizational measures against loss, destruction, access, modification or distribution of your data by unauthorized persons. In addition, we have implemented SSL encryption (SHA256) on our website to protect your data. However, despite regular checks, complete protection against all dangers is not possible.
Legal basis of processing
We process personal data in accordance with the requirements of the GDPR, depending on the type and purpose of the processing as follows:
Permitted use | Specification of the GDPR |
Informed consent | Art. 6 para. 1 a |
Performance of a contract | Art. 6 para. 1 b |
Implementation of pre-contractual measures | Art. 6 para. 1 b |
Fulfillment of legal obligations | Art. 6 para. 1 c |
Protection of vital interests | Art. 6 para. 1 d |
Safeguarding our legitimate interest | Art. 6 para. 1 f |
Our legitimate interest
Our legitimate interest, as defined in Article 6 (1) f DS-GVO, is based on the performance of our business activities in order to maintain our operational capability and secure the employment of our employees.
General deadlines for data deletion
After the purpose of storage has ceased, the retention periods are generally at least six or ten years. As a rule, data is deleted immediately in accordance with our deletion concept, provided that this does not conflict with any retention obligation, necessity for contract fulfillment or a legitimate interest.
Deletion or blocking of personal data
We store your personal data only for the period required to fulfill the specified purpose. After the purpose no longer applies and after expiration of any existing retention periods, your data will be deleted immediately. If deletion is not possible, the data will be blocked instead.
Collection of general data and information
As soon as you visit our website, our web server collects some general data and technical information - as shown in the table below:
browser types and versions used | correct display of the page content |
Operating system used, origin of the visitor (referrer, e.g. Google), subpages clicked on | Optimization of our website content as well as our advertising |
Date and time of access to the website as well as IP address and internet service provider of the visitor | Ensuring the permanent functionality of our IT systems (for the operation of the website) and prevention of misuse |
Other data and information for security in the event of attacks | Providing relevant information to law enforcement agencies in the event of a cyberattack |
Obligation to provide personal data
Under certain circumstances (e.g. due to legal or contractual regulations), an obligation arises for you to provide us with your personal data. Examples of such processing as follows:
Nature or purpose of the processing | Need |
---|---|
Conclusion of a sales contract (e.g. your address) | Fulfillment of the contractual obligation (e.g. delivery of the goods to your address) |
In the employee context (e.g. transmission of data to the tax office) | Compliance with legal requirements (e.g. tax regulations) |
Data security information
We secure our website and other systems through technical and organizational measures against loss, destruction, access, modification or distribution of your data by unauthorized persons. In addition, we have implemented SSL encryption (SHA256) on our website to protect your data. However, despite regular checks, complete protection against all dangers is not possible.
Information about specific data processing on the website
If applicable, in deviation from or in addition to the above-mentioned general information, you will find details of the individual data processing on our website below.
Blog
Purpose of processing | Possibility of (pseudonymized) expression of opinion on published blog posts |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | none |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | A data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | There is no obligation to provide personal data. The comment function can be used by entering a pseudonym. |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject. |
Where applicable, categories of personal data (if not collected directly from the data subject). | none |
Change of purpose if necessary | none |
Newsletter
Purpose of processing | Provision of information in the form of electronic circulars |
Legal basis | Consent (Art. 6 para. 1 lit. a GDPR) |
Recipient (if applicable) | none |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | A data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | There is no obligation to provide personal data. Newsletters are sent exclusively after registration via a double opt-in procedure (voluntarily given and revocable informed consent pursuant to Article 6 (1) a DSGVO) or after a purchase contract has been successfully concluded and the e-mail address has been collected in this process (pursuant to Section 7 (3) UWG). |
Consequences of non-compliance (in case of failure to provide the required data) | Non-compliance (i.e. not providing the required data) would result in the newsletter not being delivered to you. |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data comes from the data subject himself. |
Change of purpose, if applicable | none |
Contact form
Purpose of processing | Processing and, if necessary, answering the request of the form sender |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | The data will not be passed on to third parties and/or to a third country. |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | There is no obligation. |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data originates from the person concerned. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Data and categories requested in the respective form. |
Change of purpose if necessary | none |
User login
Purpose of processing |
| ||||
Legal basis (according to Art. 6 / 9 GDPR) | |||||
Recipient (if applicable) | none | ||||
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | A data transfer to a third country does not take place and is not planned. | ||||
If known: Duration of data storage | See General deadlines for data deletion | ||||
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the user account cannot be created. | ||||
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the user account cannot be created. | ||||
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. | ||||
If applicable, origin of the data (if not collected directly from the data subject) | The data comes from the data subject himself. | ||||
Change of purpose if necessary | none |
Customer account and product order
Purpose of the processing of general data |
| ||||||||
Legal basis | Fulfillment of a contract (Art. 6 para. 1 lit. b GDPR) | ||||||||
Recipient (if applicable) | Parcel service provider, logistics service provider, payment service provider | ||||||||
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | A data transfer to a third country does not take place and is not planned. | ||||||||
If known: Duration of data storage | See General deadlines for data deletion | ||||||||
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | The data (in the mandatory fields) must be provided as part of the underlying contract. | ||||||||
Consequences of non-compliance (in case of failure to provide the required data) | The creation of a customer account is not possible in this case. | ||||||||
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. | ||||||||
If applicable, origin of the data (if not collected directly from the data subject) | The data comes from the data subject himself. | ||||||||
Where applicable, categories of personal data (if not collected directly from the data subject). | The data comes from the data subject himself. | ||||||||
Change of purpose if necessary | none |
Cookies
We use cookies on this website; these are small text files that are stored on your computer via your internet browser (e.g. Google Chrome, Safari, Firefox, Edge). These cookies are used for various purposes: Many cookies are technically necessary to provide you with certain website functions (e.g. shopping cart functions, saving your login information), other cookies are used for the security of your data or the website and some cookies can be used to analyze your user behavior. The latter cookies may contain a so-called cookie ID - a unique identifier consisting of a character string that enables websites and servers to be assigned to the storing browser.
Cookies that are necessary to carry out the transmission of a message via a public telecommunications network and cookies that are absolutely necessary to provide you with an expressly requested function are referred to as "technically necessary cookies" and may be set without your explicit consent (Section 25 (2) TDDDG). All other cookies are subject to consent (Section 25 (1) TDDDG); where applicable, this is regulated by our consent management platform.
We use cookies in part only for the duration of your visit to the website, in part for a predefined period and in part permanently. You can delete all these cookies manually or automatically at any time via your web browser.
It is possible to use our website (although possibly not to its full extent) without cookies. Most browsers are set to accept cookies automatically. However, you can deactivate the storage of cookies or set your browser so that it notifies you as soon as cookies are sent.
Cookiebot
Purpose of processing | Compliance with legal obligations, storage of consent |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Usercentrics A/S, Havnegade 39, 1058 Kopenhagen, Denmark |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Opt-in and opt-out data, referrer URL, user agent, user settings, consent ID, time of consent, consent type |
Change of purpose if necessary | no |
Data protection officer of the provider | privacy@cookiebot.com |
Privacy policy of the provider | https://www.cookiebot.com/de/privacy-policy/ |
Amazon Pay
Purpose of processing | pay |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Amazon Payments Europe S.C.A. 38 avenue J.F. Kennedy, L-1855 Luxemburg |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America, Amazon.com, Inc. The data transfer is based on the EU-US Data Privacy Framework, with which Amazon.com, Inc. is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be processed. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be processed. |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Address, browser information, date of birth, device information, email address, first name, last name, geographic location, IP address, phone number, time zone, usage data, bank details, clickstream data, purchase details |
Change of purpose if necessary | no |
Apple Pay
Purpose of processing | Payment |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Apple Payments Inc.One Apple Park Way Cupertino, CA 95014, United States |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be carried out. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be carried out. |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Payment card information, first name, last name, address |
Change of purpose if necessary | none |
Facebook Connect
Purpose of processing | Facebook Connect simplifies the registration process for new web services for Facebook users. Instead of creating a new user account as before, Facebook users log in to the new service with their Facebook profile. |
Legal basis | Consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG). If personal data is collected on our website with this tool and forwarded to Facebook, we are jointly responsible with Meta Platforms Ireland Ltd. for this data processing (Art. 26 GDPR). We expressly point out that this joint responsibility is limited exclusively to the collection of data and the transfer to Facebook. The further processing of personal data by Facebook is the responsibility of Facebook. You can find the wording of the agreement on joint processing here: https://www.facebook.com/legal/controller_addendum. |
Recipient (if applicable) | Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin, D02, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing of personal data in the USA. The data transfer is based on the standard contractual clauses of the EU Commission. Meta Platforms is certified in accordance with the EU-US Data Privacy Framework (DPF). |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Profile information, browser information, user agent, usage data, profile picture, age, IP address, gender, geographic location, referrer URL, HTTP header, email address |
Change of purpose if necessary | none |
Facebook Connect
Purpose of processing | Facebook Connect simplifies the registration process for new web services for Facebook users. Instead of creating a new user account as before, Facebook users log in to the new service with their Facebook profile. |
Legal basis | Consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG). If personal data is collected on our website with this tool and forwarded to Facebook, we are jointly responsible with Meta Platforms Ireland Ltd. for this data processing (Art. 26 GDPR). We expressly point out that this joint responsibility is limited exclusively to the collection of data and the transfer to Facebook. The further processing of personal data by Facebook is the responsibility of Facebook. You can find the wording of the agreement on joint processing here: https://www.facebook.com/legal/controller_addendum. |
Recipient (if applicable) | Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin, D02, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing of personal data in the USA. The data transfer is based on the standard contractual clauses of the EU Commission. Meta Platforms is certified in accordance with the EU-US Data Privacy Framework (DPF). |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Profile information, browser information, user agent, usage data, profile picture, age, IP address, gender, geographic location, referrer URL, HTTP header, email address. |
Change of purpose if necessary | none |
Font Awesome
Purpose of processing | Uniform representation of fonts |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Fonticons, Inc.6 Porter Road, Apartment 3R, Cambridge, MA 02140, United States of Americahttps://fontawesome.com/privacy |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America |
If known: Duration of data storage | Unknown duration See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | IP address, access time, access date |
Change of purpose if necessary | no |
Sweepstakes, contests and raffles
Purpose of processing | The implementation of sweepstakes |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | If applicable, sweepstake partner, cf. general information on transmission |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | A data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | We store your personal data only as long as it is necessary for the fulfillment of mutual obligations in connection with the competition, contest or prize draw. In addition, we store your personal data only for the assertion of or defense against legal claims or until the respective statutory retention obligations have expired. |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Unless otherwise specified, the data (in the mandatory fields) must be provided as part of the underlying contract. |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Data required for participation in the competition (e.g. name, title, postal address, e-mail address, landline or cell phone number, age, date of birth, gender, user-generated content or other personal data). |
Change of purpose if necessary | none |
Google Ads
Purpose of processing | Placement of advertisements for relevant search queries in the results of the Google search engine and in the network of Google Ads participants.Evaluation of success rates of placed advertisements (conversion tracking) |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Irland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | if applicable, transfer, storage and processing in the USA; Google LLC The data transfer is based on the EU-US Data Privacy Framework, through which Google LCC is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Which pages and functions are accessed or clicked during the website visit (click behavior), IP address assigned by the Internet service provider (ISP) in anonymized form, previously visited website (referrer), subpages visited, time spent on the website, frequency of visits, date, access location, Time of visit, user agent |
Change of purpose, if applicable | no |
Opt-Out | Prevent cookies from being set, object to interest-based advertising by Google at https://adssettings.google.de/ , See also under Cookies |
Data protection officer of the provider | https://support.google.com/policies/contact/general_privacy_form |
Privacy policy of the provider | https://business.safety.google/privacy/ |
Google Ads Conversion Tracking
Purpose of processing | This service records what happens after a click on an ad placed by us via Google Ads when users subsequently visit the website. Conversions measure whether users perform a specific, predefined action on the website after clicking on an ad placed via Google Ads (e.g. whether services are ordered). This makes it possible to track which keywords, ads, ad groups, or campaigns lead to the desired user interaction. |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing in the USA, Google LLC The data transfer is based on the EU-U.S. Data Privacy Framework via which Google LCC is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Browser language, browser type, ads clicked, cookie ID, date and time of visit, IP address, referrer URL, web request, user behavior, user agent |
Change of purpose, if applicable | none |
Opt-Out | Prevent cookies from being set, object to interest-based advertising by Google at https://adssettings.google.de/, See also under Cookies. |
Data protection officer of the provider | https://support.google.com/policies/contact/general_privacy_form |
Privacy policy of the provider | https://business.safety.google/privacy/ |
Google Analytics
Purpose of processing | Creation of usage profiles to optimize the cost-benefit factor on the website |
Legal basis | Consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG) |
Recipient (if applicable) | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transmission, storage and processing in the USA, Google LLCThe data transfer is based on the EU-U.S. Data Privacy Framework through which Google LCC is certified |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | As a rule, the data originates from the data subject themselves. |
If applicable, categories of pb data (if not collected directly from the data subject) | which pages and functions are accessed or clicked on during the website visit (click behavior), IP address assigned by the Internet service provider (ISP) in anonymized form, previously visited website (referrer), subpages visited, time spent on the website, frequency of visit, date, access location, time of visit, user agent |
Change of purpose if necessary | none |
Opt-Out | Installation of the browser plugin: https://tools.google.com/dlpage/gaoptout, see also under Cookies |
Data protection officer of the provider | https://support.google.com/policies/contact/general_privacy_form |
Privacy policy of the provider | https://policies.google.com/privacy?hl=en |
Google Enhanced Conversions
Purpose of processing | Conversion tracking, conversion optimization, measurement partners - ensure security |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing in United States, Taiwan, Chile, Singapore; Google LCC The data transfer is based on the EU-U.S. Data Privacy Framework via which Google LCC is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | E-mail address, first name, last name, address, telephone number, subscription service registration data, purchase information. |
Change of purpose if necessary | none |
Privacy policy of the provider | https://business.safety.google/privacy/ |
Google Fonts
Purpose of processing | Uniform representation of the fonts |
Legal basis | Consent (Art. 6 para. 1 lit. a GDPR) |
Recipient (if applicable) | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transmission, storage and processing in the USA, Google LLCThe data transfer is based on the EU-U.S. Data Privacy Framework through which Google LCC is certified |
If known: Duration of data storage | Unknown duration See General time limits for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | IP address, access time, access date |
Change of purpose if necessary | none |
Opt-Out | Use a browser that does not support Google Fonts |
Privacy info of the addin | https://www.google.com/policies/privacy/ |
Google Pay
Purpose of processing | pay |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Google Ireland LimitedGordon House, Barrow StreetDublin 4Irland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be processed. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be processed. |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Browser information, credit and debit card number, first name, geographical location, Internet service provider, IP address, last name, payment information, purchase activity, transaction information, bank details, master and contract data, password, TAN and checksum, device type, type of network connection, account information, email address |
Change of purpose if necessary | no |
Privacy policy of the provider | https://business.safety.google/privacy/ |
Google Signals
Processing description | Google Signals is session data from websites and apps that Google associates with users who are logged into their Google Account and have enabled personalized advertising. Through Google Signals, you are identified through your Google profile and the data collected is linked to your profile. This allows us to track you across different sessions and devices and to combine the collected data into a user profile. As a site operator, we only receive anonymized reports from Google. |
Purpose of processing | Analysis, optimization, remarketing |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing in United States, Singapore, Taiwan, Chile; Google LCC The data transfer is based on the EU-U.S. Data Privacy Framework via which Google LCC is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Search Terms, Usage Data, Device Information, Browser Information, Content Viewed, Geographic Location, IP Address, Demographic Data. |
Change of purpose if necessary | none |
Privacy policy of the provider | https://business.safety.google/privacy/ |
Google Tag Manager
Purpose of processing | Simplified management of analysis tools through central control and management of the collected analysis mechanisms |
Legal basis | Consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG) |
Recipient (if applicable) | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Irland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing of personal data in the USA. The data transfer is based on the standard contractual clauses of the EU Commission. Google LLC is certified in accordance with the EU-US Data Privacy Framework (DPF). |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | As a rule, the data comes from the person concerned. |
Where applicable, categories of personal data (if not collected directly from the data subject). | which pages and functions are accessed or clicked during the website visit (click behavior), IP address assigned by the Internet service provider (ISP) in anonymized form, previously visited website (referrer), subpages visited, time spent on the website, frequency of visits, date, access location, time of visit |
Opt-Out | no |
Data protection officer of the provider | https://support.google.com/policies/contact/general_privacy_form |
Privacy policy of the provider | https://business.safety.google/privacy/ |
Hotjar
Purpose of processing | Creation of usage profiles to optimize the website in terms of the cost-benefit factor |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | As a rule, the data comes from the person concerned. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Date and time of visit, device type, geographical location, IP address, mouse movements, pages visited, referrer URL, screen resolution, own device identifier, language information, device operating system, browser type, clicks, domain name, own user ID, user agent |
Change of purpose, if applicable | no |
Opt-Out | See Cookies and https://www.hotjar.com/legal/compliance/opt-out |
Data protection officer of the provider | dpo@hotjar.com |
Privacy policy of the provider | https://www.hotjar.com/legal/policies/privacy |
Purpose of processing | Displaying Instagram content, retargeting or marketing |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Meta Platforms Ireland Limited, Meta Platforms Inc., 4 Grand Canal Square, Grand Canal Harbour, Dublin, D02, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Meta Platforms Ireland Limited, Meta Platforms Inc., Weltweit Die Datenübertragung stützt sich auf das EU-U.S. Data Privacy Framework über das Meta Platforms, Inc. zertifiziert ist. |
If known: Duration of data storage | Siehe Allgemeine Fristen für die Datenlöschung |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Device information, interactions with the embed, IP address, referrer URL, user agent |
Change of purpose, if applicable | no |
Data protection officer of the provider | https://www.facebook.com/help/contact/540977946302970 |
Privacy policy of the provider | https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect |
Judge.me
Purpose of processing | Display and submit product reviews |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Judge.me Ltd., c/o Buckworths, 1-3 Worship Street, London EC2A 2AB, United Kingdom; We have concluded a data processing agreement with the provider |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United Kingdom (adequacy decision) |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Display ratings: IP address, user agent, time of access Submitting ratings: Submitted rating and comment, display name, email address (for subsequent editing/deletion of the rating by the user), IP address, time of rating, user agent |
Change of purpose if necessary | no |
Klarna
Purpose of processing | pay |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Klarna Bank AB (publ)Sveavägen 46, 111 34 Stockholm, Swedenhttps://www.klarna.com/de/datenschutz-und-sicherheit/? |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be processed. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be processed. |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data comes from the person concerned. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Address, browser language, device operating system, email address, first name, last name, IP address, billing information |
Change of purpose if necessary | no |
Klaviyo
Meta Pixel (formerly Facebook Pixel)
Purpose of processing | Our website uses the visitor action pixel from Meta (formerly Facebook) to measure conversions. The behavior of website visitors can be tracked after they have been redirected to the provider's website by clicking on a Facebook ad. In this way, the effectiveness of Facebook ads can be evaluated for statistical and market research purposes and optimized for future advertising measures. |
Legal basis (according to Art. 6 / 9 GDPR) | Consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG). If personal data is collected on our website with this tool and forwarded to Facebook, we are jointly responsible with Meta Platforms Ireland Ltd. for this data processing (Art. 26 GDPR). We expressly point out that this joint responsibility is limited exclusively to the collection of data and the transfer to Facebook. The further processing of personal data by Facebook is the responsibility of Facebook. You can find the wording of the agreement on joint processing here: https://www.facebook.com/legal/controller_addendum. |
Recipient (if applicable) | Meta Ireland Ltd, 4 Grand Canal Square Grand Canal Harbour Dublin 2 Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing of personal data in the USA. The data transfer is based on the standard contractual clauses of the EU Commission. Meta Platforms is certified in accordance with the EU-US Data Privacy Framework (DPF). |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Ads viewed, Browser information, Content viewed, Device information, Geographic location, Interactions with ads, services, and products, IP address, Marketing information, Pixel ID, Referrer URL, Usage data, User behavior, Facebook user ID, Device operating system, Device ID, HTTP header, Items clicked, Pages viewed, Facebook cookie information, Page/click behavior, User agent, Browser type. |
Change of purpose if necessary | none |
Data protection officer of the provider | https://www.facebook.com/help/contact/540977946302970 |
Privacy policy of the provider | https://www.facebook.com/privacy/explanation |
Microsoft Ads (formerly Bing Ads)
Purpose of processing | Placement of advertisements in search engines and networks |
Legal basis | Consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG) |
Recipient (if applicable) | Microsoft Ireland Operations Limited, Attn: Data Protection Officer, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Phone: 353 (0) 1 295 3826 |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transfer, storage and processing of personal data in the USA. The data transfer is based on the standard contractual clauses of the EU Commission. Microsoft Corporation is certified in accordance with the EU-US Data Privacy Framework (DPF). |
If known: Duration of data storage | A conversion cookie is placed on the visitor's PC and remains valid for 30 days.See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | As a rule, the data originates from the data subject himself. |
Where applicable, categories of personal data (if not collected directly from the data subject). | |
Opt-Out | |
Privacy info of the addin | https://privacy.microsoft.com/de-de/privacystatement |
Microsoft Advertising
Purpose of processing | Advertising, Conversion Tracking |
Legal basis (according to Art. 6 / 9 GDPR) | Consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG) |
Recipient (if applicable) | Microsoft Corporation, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Browser language, Ads clicked, Digital signature, GUID generated by the UET tag, IP address, Microsoft click ID, Microsoft cookie, Page title, Referrer URL, Browser and device data, UET ID tag |
Change of purpose if necessary | no |
Opt-Out | https://account.microsoft.com/privacy/ad-settings/signedout?ru=https:%2F%2Faccount.microsoft.com%2Fprivacy%2Fad-settings. |
Data protection officer of the provider | https://aka.ms/privacyresponse |
https://privacy.microsoft.com/en-gb/privacystatement |
Mollie
Purpose of processing | Implementation and processing of payment |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Mollie B.V., Keizergracht 313, 1016 EE Amsterdam, Netherlands |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | A data transfer to a third country does not take place and is not planned. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be carried out. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be carried out. |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | First name, last name, address, transaction information, IP address, browser information, device information, contact information, geographic location, Internet service provider. |
Change of purpose if necessary | none |
Privacy policy of the add-in | https://www.mollie.com/en/privacy |
Data protection officer of the add-in | dpo@mollie.com |
PayPal
Purpose of processing | pay |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be processed. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be processed. |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data comes from the person concerned. |
Where applicable, categories of personal data (if not collected directly from the data subject). | no |
Change of purpose if necessary | no |
Pinterest tag
Purpose of processing | Analysis, conversion tracking, targeting, performance measurement of marketing projects. |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Pinterest Inc.651 Brannan Street, San Francisco, CA 94107, United States of America https://policy.pinterest.com/en-gb/privacy-policy |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automatic decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | IP address, click behavior, device information, date and time of visit, browser settings, geo data. |
Change of purpose if necessary | none |
Store Pay
Purpose of processing | Payment |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Transfer, storage and processing in the USA and Canada, if applicable |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be carried out. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be carried out. |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Credit and debit card number, user name, geographic location, IP address, e-mail address, payment information, transaction information, bank details, e-mail address, billing information |
Change of purpose if necessary | none |
Data protection officer of the provider | https://www.shopify.com/legal/privacy |
Shopify
Purpose of processing | Hosting and building the website. |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Shopify International Limited Victoria Buildings, 2. Etage, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Canada (adequacy decision) |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Necessity through CMS |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | IP address, information about website visits |
Change of purpose if necessary | no |
Instant bank transfer
Purpose of processing | Create secure and convenient payment options |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Sofort GmbH, Theresienhöhe 12, 80339 Munich (a company of the Klarna Group) |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | Forwarding to certain business information units |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Name, address, e-mail address, IP address, telephone number, other data if applicable |
Change of purpose if necessary | none |
Opt-Out | Refuse payment option, See also under Cookies |
Data protection information of the provider | https://www.sofort.com/payment/wizard/getCmsContent/data_protection/DE/0/de |
Stripe
Purpose of processing | pay |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Stripe, Inc. 3180 18th Street, San Francisco, CA 94110, United States of Americahttps://stripe.com/de/privacy |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America, Stripe, Inc. The data transfer is based on the EU-US Data Privacy Framework, with which Stripe, Inc. is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | Without the data, the product order or payment cannot be processed. |
Consequences of non-compliance (in case of failure to provide the required data) | Without the data, the product order or payment cannot be processed. |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Purchase date, payment information, purchase activity, payment card information |
Change of purpose if necessary | no |
TikTok Pixel
Purpose of processing | Analysis, marketing, functionality. |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | TikTok Inc.TikTok Information Technologies UK Limited, TikTok Pte. Ltd.Aviation House, 125 Kingsway Holborn, London, WC2B 6NH. |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | SingaporeChinaUnited States of AmericaUnited Kingdom (adequacy decision) |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Device information, information about the operating system, time zone, usage data, IP address |
Change of purpose if necessary | no |
YouTube
Purpose of processing | This is a video player service. It can be used by users to view, rate, share, comment on and upload videos. |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Google Ireland Limited; Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | If applicable, transmission, storage and processing in the USA, Google LLCThe data transfer is based on the EU-U.S. Data Privacy Framework through which Google LCC is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (in case of failure to provide the required data) | none |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually originates from the data subject, but may also originate from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Device informationIP addressReferrer URLViewed videos |
Change of purpose if necessary | none |
Change of purpose if necessary | https://safety.google/privacy/privacy-controls/ |
Data protection officer of the provider | https://support.google.com/policies/contact/general_privacy_form |
Privacy policy of the provider | https://policies.google.com/privacy?hl=en |
Zendesk
Purpose of processing | Responding to user requests, analyzing |
Legal basis (according to Art. 6 / 9 GDPR) | |
Recipient (if applicable) | Zendesk Inc. 989 Market Street #300, San Francisco, CA 94102, United States of America https://www.zendesk.de/company/agreements-and-terms/privacy-notice/ |
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees) | United States of America, Zendesk, Inc. The data transfer is based on the EU-US Data Privacy Framework, with which Zendesk, Inc. is certified. |
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | no |
Consequences of non-compliance (in case of failure to provide the required data) | no |
If applicable, existence of an automated decision-making process | In this context, we do not use automated decision-making. |
If applicable, origin of the data (if not collected directly from the data subject) | The data usually comes from the data subject, but can also come from third parties. |
Where applicable, categories of personal data (if not collected directly from the data subject). | Address, email address, first name, last name, IP address. |
Change of purpose if necessary | no |
Website hosting
For the operation of this website, a so-called hosting service provider is used, on whose European servers the contents of the Internet presence are stored. The hosting partner collects certain meta data (including IP addresses of website visitors) in log files to ensure the security of the systems and for verification purposes; see also under "Collection of general data and information".
The hosting service provider was carefully selected; all necessary measures were also taken to ensure data processing that is permissible under data protection law (for example, the conclusion of an agreement on commissioned processing, AVV).