Privacy policy
1. Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is all data with which you can be personally identified. Detailed information on the subject of data protection can be found in our data protection declaration listed under this text.
Data collection on this website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find their contact details in the section "Notice on the responsible body" in this data protection declaration.
How do we collect your data?
On the one hand, your data is collected when you communicate it to us. This can be e.g. deal with data that you enter in a contact form.
Other data is collected automatically or with your consent by our IT systems when you visit the website. These are primarily technical data (e.g. Internet browser, operating system or time of the page view). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure that the website is provided without errors. Other data can be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. You also have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time if you have any further questions on the subject of data protection.
Analysis tools and third-party tools
When you visit this website, your surfing behavior can be statistically evaluated. This is mainly done with so-called analysis programs.
Detailed information on these analysis programs can be found in the following data protection declaration.
2. Hosting und Content Delivery Networks (CDN)
We host the content of our website with the following provider:
Shopify
The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter “Shopify”).
Shopify a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address and information about the device and browser you are using. Shopify also analyzes visitor numbers, visitor sources and customer behavior and creates user statistics. When you make a purchase on our website, Shopify also collects your name, email address, shipping and billing addresses, payment information, and other information related to the purchase (eg. telephone number, amount of sales made, etc.). Shopify stores cookies in your browser for the analysis.
For details, please refer to Shopify's privacy policy: https://www.shopify.de/legal/datenschutz .
Shopify is used on the basis of Art. 6 Abs. 1 bed. f DSGVO. We have a legitimate interest in our website being displayed as reliably as possible. If a corresponding consent was requested, the processing takes place exclusively on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent to the storage of cookies or access to information in the user's device (eg. Device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.
order processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed according to our instructions and in compliance with the GDPR.
Google Cloud CDN
We use the content delivery network Google Cloud CDN. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google offers a globally distributed content delivery network. Technically, the transfer of information between your browser and our website is routed via the Google network. This allows us to increase the worldwide accessibility and performance of our website.
The use of Google Cloud CDN is based on our legitimate interest in providing our website as error-free and secure as possible (Art. 6 Abs. 1 bed. f DSGVO).
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://cloud.google.com/terms/eu-model-contract-clause .
For more information about Google Cloud CDN, please visit: https://cloud.google.com/cdn/docs/overview?hl=de .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
3. General information and mandatory information
privacy
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration.
If you use this website, various personal data will be collected. Personal data is data with which you can be personally identified. This data protection declaration explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
We would like to point out that data transmission on the Internet (e.g. when communicating via e-mail) may have security gaps. A complete protection of the data against access by third parties is not possible.
Note on the responsible body
The responsible body for data processing on this website is:
Codeso Living
Franziska Knuckles
Bilker Allee 21
40219 Düsseldorf
Phone: 0211 17838894
Email: info@codeso-living.de
The responsible body is the natural or legal person who, alone or together with others, is responsible for the purposes and means of processing personal data (e.g. names, e-mail addresses, etc.) decides.
storage duration
Unless a specific storage period has been specified in this data protection declaration, your personal data will remain with us until the purpose for data processing no longer applies. If you submit a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. tax or commercial retention periods); in the latter case, the data will be deleted once these reasons have ceased to exist.
General information on the legal basis for data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6 Abs. 1 bed. a GDPR or Art. 9 Abs. 2 lit. a GDPR, if special data categories according to Art. 9 Abs. 1 GDPR are processed. In the event of express consent to the transfer of personal data to third countries, data processing is also based on Art. 49 Abs. 1 bed. and DSGVO. If you consent to the storage of cookies or access to information on your end device (e.g. via device fingerprinting) have consented, the data processing is also carried out on the basis of § 25 para. 1 TTDSG. The consent can be revoked at any time. If your data is required to fulfill the contract or to carry out pre-contractual measures, we process your data on the basis of Art. 6 Abs. 1 bed. b DSGVO. Furthermore, we process your data if they are required to fulfill a legal obligation on the basis of Art. 6 Abs. 1 bed. c DSGVO. The data processing can also be based on our legitimate interest according to Art. 6 Abs. 1 bed. f GDPR. The following paragraphs of this data protection declaration provide information on the relevant legal bases in each individual case.
Note on the transfer of data to third countries that are not secure under data protection law as well as the transfer to US companies that are not DPF-certified
Among other things, we use tools from companies based in third countries that are not secure under data protection law as well as US tools whose providers are not certified according to the EU-US Data Privacy Framework (DPF). If these tools are active, your personal data may be transferred to and processed in these countries. We would like to point out that a level of data protection comparable to that of the EU cannot be guaranteed in third countries that are uncertain under data protection law.
We would like to point out that the USA, as a safe third country, generally has a level of data protection comparable to that of the EU. A data transfer to the USA is permitted if the recipient has a certification under the "EU-US Data Privacy Framework" (DPF) or has suitable additional safeguards. Information on transfers to third countries, including the data recipients, can be found in this privacy policy.
Recipients of personal data
As part of our business activities, we work together with various external bodies. In some cases, it is also necessary to transmit personal data to these external bodies. We only pass on personal data to external parties if this is necessary in the context of the performance of a contract, if we are legally obliged to do so (e.g . Disclosure of data to tax authorities) if we have a legitimate interest pursuant to Art. 6 Abs. 1 bed. f GDPR or if another legal basis permits the data transfer. When using processors, we only pass on personal data of our customers on the basis of a valid contract for order processing. In the case of joint processing, a joint processing agreement is concluded.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent that you have already given at any time. The legality of the data processing that took place up until the revocation remains unaffected by the revocation.
Right to object to the collection of data in special cases as well as to direct advertising (Art. 21 GDPR)
IF THE DATA PROCESSING IS BASED ON ART. 6 ABS. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH A PROCESSING IS BASED CAN BE FOUND IN THIS DATA PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR CONCERNED PERSONAL DATA UNLESS WE CAN PROVE COMPREHENSIVE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOM OBJECTION ACCORDING TO ART. 21 ABS. 1 DSGVO).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH ADVERTISING PURPOSES; THIS ALSO APPLIES TO PROFILING TO THE EXTENT RELATED TO SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR THE PURPOSES OF DIRECT ADVERTISING (OBJECTION ACCORDING TO ART. 21 ABS. 2 DSGVO).
Right of appeal to the competent supervisory authority
In the event of violations of the GDPR, those affected have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another person responsible, this will only be done to the extent that it is technically feasible.
Information, correction and deletion
Within the framework of the applicable legal provisions, you have the right to free information about your stored personal data, its origin and recipient and the purpose of the data processing and, if necessary, a right to have this data corrected or deleted. You can contact us at any time if you have any further questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to check this. For the duration of the examination, you have the right to request that the processing of your personal data be restricted.
- If the processing of your personal data happened/is happening unlawfully, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to demand that the processing of your personal data be restricted instead of being deleted.
- If you object pursuant to Art. 21 Abs. 1 GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to demand that the processing of your personal data be restricted.
If you have restricted the processing of your personal data, this data - apart from its storage - may only be used with your consent or to assert, exercise or defend legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State are processed.
SSL-bzw. TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses an SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If the SSL or If TLS encryption is activated, the data that you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after concluding a fee-based contract, there is an obligation to give us your payment details (e.g. account number for direct debit authorization), this data is required for payment processing.
Payment transactions using the usual means of payment (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or SSL connection. TLS connection. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
With encrypted communication, your payment data that you transmit to us cannot be read by third parties.
Objecting to Promotional Emails
We hereby object to the use of contact data published as part of the imprint obligation to send unsolicited advertising and information material. The site operators expressly reserve the right to take legal action in the event of unsolicited advertising being sent, such as spam e-mails.
4. Data collection on this website
Cookies
Our website uses so-called "cookies". Cookies are small data packages and do not damage your end device. They are stored on your end device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your end device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies can come from us (first-party cookies) or from third-party companies (so-called. Third-Party-Cookies). Third-party cookies enable the integration of certain third-party services within websites (e.g . Cookies for processing payment services).
Cookies have different functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g . the shopping cart function or the display of videos). Other cookies may be used to evaluate user behavior or for advertising purposes.
Cookies that are required to carry out the electronic communication process, to provide certain functions you want (e.g. for the shopping cart function) or to optimize the website (e.g. Cookies for measuring the web audience) are required (necessary cookies), based on Art. 6 Abs. 1 bed. f GDPR, unless another legal basis is given. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing takes place exclusively on the basis of this consent (Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG); the consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when the browser is closed. If cookies are deactivated, the functionality of this website may be restricted.
You can find out which cookies and services are used on this website in this data protection declaration.
Consent with Usercentrics
This website uses the consent technology of Usercentrics to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies and to document these in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany, website: https://usercentrics.com/de/ (hereinafter referred to as "Usercentrics").
When you enter our website, the following personal data is transmitted to Usercentrics:
- Your consent(s) or the withdrawal of your consent(s)
- your IP address
- Information about your browser
- Information about your device
- Time of your visit to the website
Furthermore, Usercentrics stores a cookie in your browser in order to remind you of the consents or consents you have given. to assign their revocation. The data collected in this way will be stored until you ask us to delete it, delete the Usercentrics cookie yourself or the purpose for which the data was stored no longer applies. Mandatory statutory retention requirements remain unaffected.
Usercentrics is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Art. 6 Abs. 1 bed. c DSGVO.
Consent with Cookie Notice & Compliance
Our website uses the consent technology of Cookie Notice & Compliance for GDPR to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies and to document them in compliance with data protection regulations.
Anbieter des Tools ist die Hu-manity Rights Inc., 300 Carnegie Center, Suite 150, Princeton, NJ, New Jersey 08540, USA (nachfolgend „Hu-manity Rights Inc.“). When you enter our website, a connection is established to the servers of Hu-manity Rights Inc. in order to obtain your consents and other declarations regarding the use of cookies. Hu-manity Rights Inc. then stores a cookie in your browser in order to provide you with the consents or consents you have given. to assign their revocation. The data collected in this way will be stored until you ask us to delete it, delete the cookie from Hu-manity Rights Inc. yourself or the purpose for which the data was stored no longer applies. Mandatory statutory retention requirements remain unaffected.
The use of Cookie Notice & Compliance for GDPR is done in order to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 Abs. 1 bed. c DSGVO.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- operating system used
- Referrer URL
- Host name of the accessing computer
- Time of server request
- IP address
This data is not merged with other data sources.
The collection of this data takes place on the basis of Art. 6 Abs. 1 bed. f DSGVO. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, the server log files must be recorded.
contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We do not pass on this data without your consent.
The processing of this data takes place on the basis of Art. 6 Abs. 1 bed. b GDPR if your request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 Abs. 1 bed. f GDPR) or on your consent (Art. 6 Abs. 1 bed. a GDPR) if requested; the consent can be revoked at any time.
The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.
Inquiry by e-mail, telephone or fax
If you contact us by e-mail, telephone or fax, your inquiry including all resulting personal data (name, enquiry) will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent.
The processing of this data takes place on the basis of Art. 6 Abs. 1 bed. b GDPR if your request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 Abs. 1 bed. f GDPR) or on your consent (Art. 6 Abs. 1 bed. a GDPR) if requested; the consent can be revoked at any time.
The data you sent to us via contact requests will remain with us until you request deletion, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular statutory retention periods - remain unaffected.
Communication via WhatsApp
For communication with our customers and other third parties, we use, among other things, the instant messaging service WhatsApp. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Communication takes place via end-to-end (peer-to-peer) encryption, which prevents WhatsApp or other third parties from gaining access to the communication content. However, WhatsApp gains access to metadata generated in the course of the communication process (e.g . sender, recipient and time). We would also like to point out that WhatsApp says it shares personal data of its users with its US-based parent company Meta. For more details on data processing, please refer to WhatsApp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy .
The use of WhatsApp is based on our legitimate interest in communicating as quickly and effectively as possible with customers, interested parties and other business and contractual partners (Art. 6 Abs. 1 bed. f DSGVO). If a corresponding consent has been requested, data processing is carried out exclusively on the basis of consent; this can be revoked at any time with effect for the future.
The communication content exchanged between and on WhatsApp will remain with us until you request us to delete it, revoke your consent to storage or the purpose for which the data was stored no longer applies (e.g . after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt00000011sfnAAA&status=Active
We use WhatsApp in the "WhatsApp Business" variant.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.whatsapp.com/legal/business-data-transfer-addendum .
Registration on this site
You can register on this website to use additional functions on the site. We only use the data entered for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise we will refuse the registration.
For important changes, such as the scope of the offer or technically necessary changes, we use the e-mail address provided during registration to inform you in this way.
The data entered during registration is processed for the purpose of implementing the user relationship established by registration and, if applicable, to initiate further contracts (Art. 6 Abs. 1 bed. b GDPR).
The data collected during registration will be stored by us as long as you are registered on this website and will then be deleted. Statutory retention periods remain unaffected.
comment function on this website
For the comment function on this page, in addition to your comment, information about the time the comment was created, your e-mail address and, if you are not posting anonymously, the user name you have chosen will be stored.
Storage duration of the comments
The comments and the associated data will be stored and will remain on this website until the commented content has been completely deleted or the comments must be deleted for legal reasons (e.g . insulting comments).
legal basis
The comments are stored on the basis of your consent (Art. 6 Abs. 1 bed. and DSGVO). You can revoke any consent you have given at any time. An informal message by e-mail to us is sufficient. The legality of the data processing operations that have already taken place remains unaffected by the revocation.
5. Social media
Elements of the social network Facebook are integrated on this website. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the data collected is also transmitted to the USA and other third countries.
An overview of the Facebook social media elements can be found here: https://developers.facebook.com/docs/plugins/?locale=de_DE .
If the social media element is active, a direct connection is established between your end device and the Facebook server. Facebook receives the information that you have visited this website with your IP address. If you click the Facebook "Like" button while you are logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to associate your visit to this website with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the data transmitted or how it is used by Facebook. Further information can be found in Facebook's privacy policy at: https://de-de.facebook.com/privacy/explanation .
If consent has been obtained, the above mentioned service on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, the use of the service is based on our legitimate interest in the widest possible visibility on social media.
Insofar as personal data is collected on our website and forwarded to Facebook using the tool described here, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited to collecting the data and passing it on to Facebook. The processing by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum . According to this agreement, we are responsible for issuing data protection information when using the Facebook tool and for implementing the tool on our website in a secure manner in accordance with data protection law. Facebook is responsible for the data security of Facebook products. Rights of data subjects (e.g. Request for information) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert the rights of data subjects with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt0000000GnywAAC&status=Active
Functions of the Instagram service are integrated on this website. These functions are offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
If the social media element is active, a direct connection will be established between your end device and the Instagram server. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking on the Instagram button. This allows Instagram to associate your visit to this website with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or how it is used by Instagram.
If consent has been obtained, the above mentioned service on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, the use of the service is based on our legitimate interest in the widest possible visibility on social media.
Insofar as personal data is collected on our website with the help of the tool described here and sent to Facebook or Facebook. are forwarded to Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited to collecting the data and passing it on to Facebook or Facebook. Instagram. The processing that takes place after the forwarding by Facebook or Instagram is not part of the shared responsibility. Our joint obligations have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum . According to this agreement, we are responsible for providing data protection information when using the Facebook or Instagram tools and responsible for the data protection-compliant implementation of the tool on our website. For the data security of the Facebook resp. Instagram products is Facebook responsible. Rights of data subjects (e.g. Request for information) with regard to Facebook or You can assert the data processed by Instagram directly on Facebook. If you assert the rights of data subjects with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381 .
For more information, please refer to Instagram's privacy policy: https://privacycenter.instagram.com/policy /.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt0000000GnywAAC&status=Active
On this website, we use elements of the social network Pinterest, which is operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
When you visit a page that contains such an element, your browser establishes a direct connection to Pinterest's servers. This social media element transmits log data to the Pinterest server in the USA. This log data may contain your IP address, the address of the websites visited, which also contain Pinterest functions, the type and settings of the browser, the date and time of the request, your use of Pinterest and cookies.
If consent has been obtained, the above mentioned service on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, the use of the service is based on our legitimate interest in the widest possible visibility on social media.
Further information on the purpose, scope and further processing and use of data by Pinterest, as well as your rights in this regard and options for protecting your privacy, can be found in Pinterest's privacy policy: https://policy.pinterest.com/de/privacy-policy .
6. Analytics Tools and Advertising
Google Tag Manager
We use the Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is a tool that we can use to integrate tracking or statistical tools and other technologies on our website. The Google Tag Manager itself does not create any user profiles, does not save any cookies and does not carry out any independent analyses. It is only used for the administration and display of the tools integrated via it. However, the Google Tag Manager records your IP address, which can also be transmitted to Google's parent company in the United States.
The Google Tag Manager is used on the basis of Art. 6 Abs. 1 bed. f DSGVO. The website operator has a legitimate interest in the quick and easy integration and management of various tools on its website. If a corresponding consent was requested, the processing takes place exclusively on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent to the storage of cookies or access to information in the user's device (eg. Device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as e.g. Page views, length of stay, operating systems used and origin of the user. This data is summarized in a user ID and assigned to the respective end device of the website visitor.
Google Analytics uses technologies that enable the user to be recognized for the purpose of analyzing user behavior (e.g. Cookies oder Device-Fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the USA and stored there.
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs /.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
IP anonymization
We have activated the IP anonymization function on this website. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de .
You can find more information about the handling of user data by Google Analytics in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de .
Demographic characteristics in Google Analytics
This website uses the "demographic characteristics" function of Google Analytics in order to be able to show website visitors relevant advertisements within the Google advertising network. This allows reports to be created that contain statements about the age, gender and interests of the site visitors. This data comes from interest-based advertising from Google and visitor data from third-party providers. This data cannot be assigned to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the point "Objection to data collection".
order processing
We have concluded an order processing contract with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Google Analytics Ecommerce Measurement
This website uses the "e-commerce measurement" function of Google Analytics. With the help of e-commerce measurement, the website operator can analyze the purchasing behavior of website visitors to improve their online marketing campaigns. Information such as the orders placed, average order values, shipping costs and the time from viewing a product to purchasing it is recorded. This data can be summarized by Google under a transaction ID, which is assigned to the respective user or whose device is assigned.
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program from Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when the user enters certain search terms on Google (keyword targeting). Furthermore, targeted advertisements can be generated using the user data available on Google (e.g. Location data and interests) are played out (target group targeting). As the website operator, we can evaluate this data quantitatively, for example by analyzing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs /.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
Google AdSense
This website uses Google AdSense, a service for integrating advertisements. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google Adsense, we can display targeted advertisements from third-party companies on our site. The content of the advertisements is based on your interests, which Google determines based on your previous user behavior. Furthermore, when selecting the appropriate advertisement, context information such as your location, the content of the website visited or the Google search terms you entered are also taken into account.
Google AdSense uses cookies, web beacons (invisible graphics) and similar recognition technologies. This allows information such as visitor traffic on these pages to be evaluated.
The information collected by Google Adsense about the use of this website (including your IP address) and the delivery of advertising formats is transmitted to a Google server in the USA and stored there. This information may be passed on by Google to Google's contractual partners. However, Google will not merge your IP address with other data stored by you.
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs /.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
Google Ads Remarketing
This website uses the features of Google Ads Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With Google Ads Remarketing, we can assign people who interact with our online offer to specific target groups in order to then display interest-based advertising to them in the Google advertising network (remarketing or remarketing). Retargeting).
In addition, the advertising audiences created with Google Ads Remarketing can be linked to Google's cross-device features. In this way, interest-based, personalized advertising messages, which are based on your previous usage and surfing behavior on a device (e.g . mobile phone) have also been adapted to you on another of your devices (e.g . tablet or PC).
If you have a Google account, you can object to personalized advertising at the following link: https://www.google.com/settings/ads/onweb /.
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Further information and data protection regulations can be found in Google's privacy policy at: https://policies.google.com/technologies/ads?hl=de .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
Google Conversion-Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, we and Google can recognize whether the user has carried out certain actions. For example, we can evaluate which buttons on our website were clicked how often and which products were viewed or purchased particularly frequently. This information is used to generate conversion statistics. We learn the total number of users who have clicked on our ads and what actions they have taken. We do not receive any information with which we can personally identify the user. Google itself uses cookies or comparable recognition technologies for identification.
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
You can find more information about Google Conversion Tracking in Google's privacy policy: https://policies.google.com/privacy?hl=de .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
claviyo
We have included Klaviyo on this website. The provider is Klaviyo Inc., 125 Summer Street, Floor 6, Boston, MA, 02110, USA (hereinafter referred to as Klaviyo).
Klaviyo is a marketing automation tool for sending emails, SMS, push notifications, and collecting customer reviews for eCommerce merchants.
For this purpose, Klaviyo stores the consent to email marketing. In particular, the following data may be processed: name, telephone number, e-mail address, address data, IP address, device identifications, usage data (e.g . Interactions between a user and Klaviyo's online system, website or e-mail, browser used, operating system used, referrer URL).
The use of Klaviyo is based on Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Further details can be found in the provider's privacy policy at https://www.klaviyo.com/legal/privacy .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt00000012uf9AAA&status=Active
The provider applies standard contractual clauses for the transfer of personal data to third countries. Details can be found here: https://www.klaviyo.com/legal/data-processing-agreement .
order processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed according to our instructions and in compliance with the GDPR.
Meta Pixel (formerly Facebook Pixel)
This website uses Facebook/Meta visitor action pixels to measure conversions. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the data collected is also transmitted to the USA and other third countries.
In this way, the behavior of site visitors can be tracked after they have been redirected to the provider's website by clicking on a Facebook ad. This allows the effectiveness of the Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.
The data collected is anonymous for us as the operator of this website, we cannot draw any conclusions about the identity of the user. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes, in accordance with the Facebook Data Use Policy (https://de-de.facebook.com/about/privacy/). This enables Facebook to place advertisements on Facebook pages and outside of Facebook. This use of the data cannot be influenced by us as the site operator.
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Insofar as personal data is collected on our website and forwarded to Facebook using the tool described here, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited to collecting the data and passing it on to Facebook. The processing by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum . According to this agreement, we are responsible for issuing data protection information when using the Facebook tool and for implementing the tool on our website in a secure manner in accordance with data protection law. Facebook is responsible for the data security of Facebook products. Rights of data subjects (e.g. Request for information) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert the rights of data subjects with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381 .
You can find further information on how to protect your privacy in Facebook's privacy policy: https://de-de.facebook.com/about/privacy /.
You can also disable the "Custom Audiences" remarketing feature in the Ad Settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen . To do this, you must be logged in to Facebook.
If you do not have a Facebook account, you can opt out of usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement /.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt0000000GnywAAC&status=Active
Facebook Conversion API
We have integrated Facebook Conversion API on this website. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the data collected is also transmitted to the USA and other third countries.
Facebook Conversion API allows us to track the website visitor's interactions with our website and pass them on to Facebook in order to improve advertising performance on Facebook.
For this purpose, in particular, the time of access, the website accessed, your IP address and your user agent and, if applicable, the time of the call, the time of the access, the time of access, the time of the access, the time of the call, the time of the call other specific data (e.g . products purchased, basket value and currency). A complete overview of the data that can be collected can be found here: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters .
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Insofar as personal data is collected on our website and forwarded to Facebook using the tool described here, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited to collecting the data and passing it on to Facebook. The processing by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum . According to this agreement, we are responsible for issuing data protection information when using the Facebook tool and for implementing the tool on our website in a secure manner in accordance with data protection law. Facebook is responsible for the data security of Facebook products. Rights of data subjects (e.g. Request for information) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert the rights of data subjects with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381 .
You can find further information on how to protect your privacy in Facebook's privacy policy: https://de-de.facebook.com/about/privacy /.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt0000000GnywAAC&status=Active
Facebook Custom Audiences
We use Facebook Custom Audiences. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
When you visit our websites and apps, or When you use our free or paid services, transmit data to us or interact with our company's Facebook content, we collect your personal data in the process. If you give us your consent to the use of Facebook Custom Audiences, we will transmit this data to Facebook, which Facebook can use to display suitable advertising to you. Furthermore, your data can be used to define target groups (lookalike audiences).
Facebook processes this data as our processor. Details can be found in Facebook's user agreement: https://www.facebook.com/legal/terms/customaudience .
This service is used on the basis of your consent in accordance with Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG. The consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:, https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt0000000GnywAAC&status=Active
Pinterest Tag
We have embedded Pinterest tag on this website. The provider is Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
Pinterest tag is used to track certain actions you take on our website. The data may then be used to show you interest-based advertising on our website or on another page of the Pinterest Tag advertising network.
To this end, the Pinterest tag collects, among other things: a tag ID, your location and the referrer URL. In addition, promotion-specific data such as order value, order quantity, order number, category of purchased items and video views can be recorded.
Pinterest-Tag uses technologies that enable cross-site recognition of the user in order to analyze user behavior (e.g . Cookies oder Device-Fingerprinting).
If consent has been obtained, the above mentioned service exclusively on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, the use of this service is based on Art. 6 Abs. 1 bed. f GDPR; the website operator has a legitimate interest in marketing measures that are as effective as possible.
Pinterest is a globally active company, so data can also be transferred to the USA. According to Pinterest, this data transfer is based on the EU Commission's standard contractual clauses. Details can be found here: https://policy.pinterest.com/de/privacy-policy .
You can find more information about Pinterest tags here: https://help.pinterest.com/de/business/article/track-conversions-with-pinterest-tag .
7. Newsletter
Newsletterdaten
If you would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter . Further data will not be collected only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The processing of the data entered in the newsletter registration form takes place exclusively on the basis of your consent (Art. 6 Abs. 1 bed. and DSGVO). You can revoke your consent to the storage of the data, the e-mail address and their use for sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.
The data you have stored with us for the purpose of subscribing to the newsletter will be retained by us until you unsubscribe from the newsletter. saved by the newsletter service provider and deleted from the newsletter distribution list after you unsubscribe from the newsletter or after it no longer serves any purpose. We reserve the right to remove e-mail addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest in accordance with Art. 6 Abs. 1 bed. f GDPR to delete or block.
Data stored by us for other purposes remain unaffected.
After you have removed yourself from the newsletter distribution list, your e-mail address will be stored with us or the newsletter service provider, if applicable stored in a blacklist if this is necessary to prevent future mailings. The data from the blacklist is only used for this purpose and is not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Abs. 1 bed. f DSGVO). The storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.
8. plugins and tools
YouTube with enhanced privacy
This website includes videos from the YouTube website. The website operator is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in the extended data protection mode. According to YouTube, this mode means that YouTube does not store any information about visitors to this website before they watch the video. However, the extended data protection mode does not necessarily exclude the transfer of data to YouTube partners. This is how YouTube connects to the Google Marketing Network, regardless of whether you're watching a video.
As soon as you start a YouTube video on this website, a connection to the YouTube servers is established. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, after starting a video, YouTube may store various cookies on your device or use comparable recognition technologies (e.g . Device-Fingerprinting) einsetzen. In this way, YouTube can receive information about visitors to this website. This information is used, among other things: used to collect video statistics, improve usability and prevent fraud attempts.
If necessary, after the start of a YouTube video, further data processing operations can be triggered over which we have no influence.
YouTube is used in the interest of an attractive presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 Abs. 1 bed. f DSGVO dar. If a corresponding consent was requested, the processing takes place exclusively on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent to the storage of cookies or access to information in the user's device (eg. Device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.
For more information about data protection at YouTube, please refer to their privacy policy at: https://policies.google.com/privacy?hl=de .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
Google Fonts (local hosting)
This site uses so-called Google Fonts, which are provided by Google, for the uniform display of fonts. The Google Fonts are installed locally. There is no connection to Google servers.
For more information about Google Fonts, please visit https://developers.google.com/fonts/faq and Google's privacy policy: https://policies.google.com/privacy?hl=de .
Adobe Fonts
This website uses web fonts from Adobe for the uniform display of certain fonts. Anbieter ist die Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe).
When you visit this website, your browser loads the required fonts directly from Adobe in order to be able to display them correctly on your device. Your browser establishes a connection to the Adobe servers in the USA. This gives Adobe knowledge that this website was accessed via your IP address. According to Adobe, no cookies are stored when the fonts are provided.
The data is stored and analyzed on the basis of Art. 6 Abs. 1 bed. f DSGVO. The website operator has a legitimate interest in the uniform presentation of the typeface on his website. If a corresponding consent was requested, the processing takes place exclusively on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent to the storage of cookies or access to information in the user's device (eg. Device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.adobe.com/de/privacy/eudatatransfers.html .
For more information about Adobe Fonts, please visit: https://www.adobe.com/de/privacy/policies/adobe-fonts.html .
Adobe's privacy policy can be found at: https://www.adobe.com/de/privacy/policy.html
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt0000000TNo9AAG&status=Active
Google Maps
This site uses the map service Google Maps. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
In order to use the functions of Google Maps, it is necessary to store your IP address. This information is usually transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer. If Google Maps is enabled, Google can use Google Fonts for the purpose of uniformly representing the fonts. When you call Google Maps, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.
The use of Google Maps is in the interest of an appealing presentation of our online offers and an easy findability of the places indicated by us on the website. This constitutes a legitimate interest within the meaning of Art. 6 Abs. 1 bed. f DSGVO dar. If a corresponding consent was requested, the processing takes place exclusively on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent to the storage of cookies or access to information in the user's device (eg. Device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms /sccs/.
You can find more information on the handling of user data in Google's privacy policy: https://policies.google.com/privacy?hl=de .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
The purpose of reCAPTCHA is to check whether the data entry on this website (e.g . in a contact form) by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For analysis, reCAPTCHA evaluates various pieces of information (e.g . IP address, how long the website visitor spent on the website or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyzes run completely in the background. Website visitors are not informed that an analysis is taking place.
The data is stored and analyzed on the basis of Art. 6 Abs. 1 bed. f DSGVO. The website operator has a legitimate interest in protecting its web offerings from abusive automated spying and from SPAM. If a corresponding consent was requested, the processing takes place exclusively on the basis of Art. 6 Abs. 1 bed. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent to the storage of cookies or access to information in the user's device (eg. Device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.
For more information about Google reCAPTCHA, please refer to the Google Privacy Policy and the Google Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de .
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the United States that aims to ensure compliance with European data protection standards for data processing in the United States. Every DPF-certified company is committed to complying with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true& ; id=a2zt000000001L5AAI&status=Active
9. eCommerce and Payment Providers
Processing of customer and contract data
We collect, process and use personal customer and contract data to establish, structure and change our contractual relationships. We collect, process and use personal data about the use of this website (usage data) only to the extent necessary to enable the user to use the service or to bill the user. The legal basis for this is Art. 6 Abs. 1 bed. b DSGVO.
The collected customer data will be deleted after completion of the order or termination of the business relationship and expiry of any existing legal retention periods are deleted. Statutory retention periods remain unaffected.
Data transmission upon conclusion of contract for online shops, dealers and goods dispatch
If you order goods from us, we pass on your personal data to the transport company responsible for the delivery and to the payment service provider responsible for processing the payment. Only data that the respective service provider needs to fulfill its task will be released. The legal basis for this is Art. 6 Abs. 1 bed. b GDPR, which allows the processing of data to fulfill a contract or pre-contractual measures. If you have given your consent in accordance with Art. 6 Abs. 1 bed. a GDPR, we will pass on your e-mail address to the transport company responsible for the delivery so that they can inform you about the shipping status of your order by e-mail; You can revoke your consent at any time.
Data transmission upon conclusion of contract for services and digital content
We only transmit personal data to third parties if this is necessary within the framework of contract processing, for example to the bank responsible for processing payments.
A further transmission of the data does not take place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for data processing is Art. 6 Abs. 1 bed. b GDPR, which allows the processing of data to fulfill a contract or pre-contractual measures.
Order processing via dropshipping
If you order goods from us, it is possible that your order will be sent to you directly from our dealers (dropshipping). For this purpose, we pass on your name, the delivery address and - insofar as this is necessary for the delivery - your telephone number to the shipping company. The transfer takes place exclusively for the purpose of delivering the goods.
The legal basis for data processing is Art. 6 Abs. 1 bed. b GDPR (performance of contract) and our legitimate interest in the quickest and most effective purchase process possible within the meaning of Art. 6 Abs. 1 bed. f DSGVO.
We use the following dealers for dropshipping:
Richmond Interiors
Butter 17
1713 GM Obdam
Netherlands
credit checks
In the case of a purchase on account or another payment method for which we pay in advance, we can carry out a credit check (scoring). For this purpose, we transmit the data you have entered (e.g . Name, address, age or bank details) to a credit agency. The probability of a payment default is determined on the basis of this data. If there is an excessive risk of non-payment, we can refuse the relevant payment method.
The credit check is carried out on the basis of the fulfilment of the contract (Art. 6 Abs. 1 bed. b GDPR) as well as to avoid payment defaults (legitimate interest according to Art. 6 Abs. 1 bed. f DSGVO). If consent has been obtained, the credit check is carried out on the basis of this consent (Art. 6 Abs. 1 bed. GDPR); the consent can be revoked at any time.
payment services
We integrate payment services from third party companies on our website. If you make a purchase from us, your payment details (e.g. Name, payment amount, account details, credit card number) processed by the payment service provider for the purpose of payment processing. The respective contract and data protection provisions of the respective provider apply to these transactions. The payment service providers are used on the basis of Art. 6 Abs. 1 bed. b GDPR (contract execution) and in the interest of a payment process that is as smooth, convenient and secure as possible (Art. 6 Abs. 1 bed. f DSGVO). If your consent is requested for certain actions, Art. 6 Abs. 1 bed. a GDPR legal basis for data processing; Consent can be revoked at any time for the future.
We use the following payment services / payment service providers on this website:
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full .
Details can be found in the privacy policy of PayPal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full .
Apple Pay
The payment service provider is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple's privacy policy can be found at: https://www.apple.com/legal/privacy/de-ww /.
Google Pay
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy policy can be found here: https://policies.google.com/privacy .
Stripe
The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter referred to as "Stripe").
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://stripe.com/de/privacy and https://stripe.com/de/guides/general-data-protection-regulation .
Details can be found in Stripe's privacy policy at the following link: https://stripe.com/de/privacy .
Klarna
The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers various payment options (e.g. hire purchase). If you decide to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the Klarna checkout solution. Details on the use of Klarna cookies can be found at the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf .
Details can be found in Klarna's privacy policy at the following link: https://www.klarna.com/de/datenschutz /.
Sofortüberweisung
The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter “Sofort GmbH”). With the help of the "Sofortüberweisung" procedure, we receive a payment confirmation from Sofort GmbH in real time and can immediately start fulfilling our obligations. If you have decided on the payment method “Sofortüberweisung”, send the PIN and a valid TAN to Sofort GmbH, with which they can log into your online banking account. Sofort GmbH automatically checks your account balance after logging in and carries out the transfer to us using the TAN you sent. It then immediately sends us a transaction confirmation. After logging in, your sales, the credit limit of the overdraft facility and the existence of other accounts and their balances are automatically checked. In addition to the PIN and the TAN, the payment data you enter as well as personal data are transmitted to Sofort GmbH. Your personal data is your first and last name, address, telephone number(s), e-mail address, IP address and, if applicable, other data required for payment processing. The transmission of this data is necessary to establish your identity beyond doubt and to prevent attempts at fraud. Details on how to pay with instant bank transfer can be found at the following links: https://www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/.
Amazon Pay
The provider of this payment service is Amazon Payments Europe S.C.A., 38 avenue J.F. Kennedy, L-1855 Luxembourg.
Details on how your data will be handled can be found in Amazon Pay's privacy policy at the following link: https://pay.amazon.de/help/201212490?ld=APDELPADirect .
Mollie
The provider of this payment service is Mollie B.V., Keizersgracht 126, 1015CW Amsterdam, The Netherlands (hereinafter referred to as "Mollie"). With the help of Mollie, we can integrate different payment methods on our website. For details, please refer to Mollie's privacy policy: https://www.mollie.com/de/privacy .
Shopify Payment
The provider of this payment service in the EU is Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter "Shopify Payment").
For details, please refer to Shopify Payment's privacy policy: https://www.shopify.de/legal/datenschutz .
American Express
The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter “American Express”).
American Express may transfer data to its parent company in the United States. Data transmission to the USA is based on the Binding Corporate Rules. Details can be found here: https://www.americanexpress.com/en-pl/company/legal/privacy-centre/european-implementing-principles /.
For more information, please refer to the American Express Privacy Policy: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html .
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter "Mastercard").
Mastercard may transfer data to its parent company in the United States. Data transmission to the USA is based on Mastercard's Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf .
VISA
The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).
Great Britain is regarded as a safe third country under data protection law. This means that Great Britain has a data protection level that corresponds to the data protection level in the European Union.
VISA may transfer data to its parent company in the United States. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html .
For more information, please refer to VISA's Privacy Policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html .