Privacy policy

1. Data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is all data with which you can be personally identified. Detailed information on data protection can be found in our data protection declaration listed under this text.

Data acquisition on this website

Who is responsible for data acquisition on this website?

Data processing on this website takes place by the website operator. You can find its contact details in this data protection declaration to the section "Note on the responsible body".

How do we collect your data?

On the one hand, your data will be collected by telling us. Here it can z. B. act about data that you enter in a contact form.

Other data is recorded automatically or after your consent when visiting the website by our IT systems. These are primarily technical data (e.g. internet browser, operating system or time of the page call). This data is recorded automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure error -free provision of the website. Other data can be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right to obtain information about origin, recipient and the purpose of your stored personal data at any time. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the processing of your personal data under certain circumstances. Furthermore, you have a right to complain to the responsible supervisory authority.

You can contact us at any time for further questions about data protection.

Analysis tools and tools from third-party providers

When visiting this website, your surfing behavior can be evaluated statistically. This is mainly done with so -called analysis programs.

You can find detailed information on these analysis programs in the following data protection declaration.

2. Hosting

We host the content of our website with the following provider:

All-inclusive

The provider is the all-inkl.com-New Media Münnich, Inh. René Münnich, Hauptstraße 68, 02742 Friedersdorf (hereinafter All-link). Details can be found in the data protection declaration of All-Inkl: https://all-inkl.com/datenschutzinformationen/.

The use of all-link is based on Art. 6 Para. 1 lit. f GDPR. We have a legitimate interest in the most reliable representation of our website. If a corresponding consent has been queried, the processing takes place exclusively on the basis of Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG, provided that consent is saved in the storage of cookies or access to information in the end device of the user (z. B. Device fingerprinting) in the sense of the TTDSG. The consent can be revoked at any time.

Order processing

We have concluded a contract for order processing (AVV) to use the above service. This is a contract prescribed under data protection law that ensures that it only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

3. General information and compulsory information

data protection

The operators of these pages take the protection of their personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration.

If you use this website, various personal data will be collected. Personal data is data that can be used to personally identify. The present data protection declaration explains which data we collect and for what we use it for. She also explains how and for what purpose it happens.

We would like to point out that data transmission on the Internet (e.g. when communicating by email) can have security gaps. Complete protection of the data before access by third parties is not possible.

Note on the responsible body

The responsible body for data processing on this website is:

Bold & AmbitioS Beauty GmbH
Winterhuder Weg 136a
22085 Hamburg

Telephone: +49 40 80903783
Email: support@bayagebeauty.com

The responsible body is the natural or legal person who decides alone or together with others about the purposes and means of processing personal data (e.g. names, email addresses or similar).

Memory duration

Insofar as no more specific storage duration was mentioned within this data protection declaration, your personal data remains with us until the purpose for data processing is no longer necessary. If you assert a legitimate search for deletion or revoke your consent to data processing, your data will be deleted if we have no other legally permissible reasons for storing your personal data (e.g. tax or commercial law storage periods); In the latter case, the deletion is deleted according to these reasons.

General information on the legal basis of data processing on this website

If you have consented to data processing, we process your personal data based on Art. 6 Para. 1 lit. a GDPR or Art. 9 Para. 2 lit. a GDPR, provided special data categories according to Art. 9 Para. 1 GDPR are processed. In the event of an express consent to the transfer of personal data in third countries, data processing also takes place on the basis of Art. 49 Para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information in your end device (e.g. via device fingerprinting), data processing will also be carried out on the basis of Section 25 (1) TTDSG. The consent can be revoked at any time. If your data is required for the fulfillment of the contract or carry out pre -contractual measures, we process your data based on Art. 6 Para. 1 Lit.B GDPR. Furthermore, we process your data if it is necessary to fulfill a legal obligation based on Art. 6 Para. 1 lit. c GDPR. Data processing can also be carried out on the basis of our legitimate interest in accordance with Art. 6 Para. 1 lit. f GDPR. In the following paragraphs of this data protection declaration, the legal bases relevant in each individual case are informed.

Note on data transfer in data protection law not secure third countries and the transfer to US companies that are not DPF-certified

Among other things, we use Tools of companies based in data protection not safe third countries and US tools, whose providers are not certified according to the EU-US-DATA privacy framework (DPF). If these tools are active, your personal data can be transferred to these states and processed there. We would like to point out that in data protection -insecure third countries, no data protection level comparable to the EU cannot be guaranteed.

We would like to point out that the United States as a safe third -country country generally has a level of data protection comparable to the EU. Data transfer to the USA is permitted if the recipient has certification under the "EU-US-US Privacy Framework" (DPF) or has suitable additional guarantees. Information on transmission to third countries, including the data recipients, can be found in this data protection declaration.

Recipient of personal data

As part of our business, we work with various external positions. In some cases, it is also necessary to transmit personal data to these external bodies. We will only pass on personal data to external bodies if this is necessary in the context of a contract fulfillment if we are legally obliged to do so (e.g. passing on data to tax authorities) if we have a legitimate interest according to Art. 6 Para. 1 Lit. f GDPR have the transfer or if another legal basis allows data transfer. When using order processors, we only pass on personal data from our customers on the basis of a valid contract for order processing. In the event of a joint processing, a contract for joint processing is concluded.

Revocation of your consent to data processing

Many data processing processes are only possible with their express consent. You can revoke an already granted consent at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to object to the data collection in special cases and against direct mail (Art. 21 GDPR)

If the data processing based on Art. 6 para. 1 lit. E or F GDPR, you have the right to object to the processing of your personal data at any time, for reasons that result from your particular situation; This also applies to a profiling based on these provisions. The respective legal basis on which processing is based can be found in this data protection declaration. If you make an objection, we will no longer process your data subject to personal data, unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms or the processing serves to assert, exercise or defend legal claims ( Objection according to Art. 21 Para. 1 GDPR).

If your personal data is processed to operate direct mail, you have the right to object at any time to the processing of personal data relating to the purpose of such advertising; This also applies to profiling, insofar as it is connected to such direct advertising. If you object, your personal data will then no longer be used for direct marketing purposes (objection according to Art. 21 Para. 2 GDPR).

Law of complaint with the responsible supervisory authority

In the event of violations of the GDPR, those affected are entitled to a right to complain to a supervisory authority, in particular in the Member State of their habitual stay, their workplace or the place of the alleged violation. The right to complain is without prejudice to other administrative or judicial remedies.

Right to data portability

You have the right to have data that we automatically process on the basis of your consent or in fulfilling a contract to have yourself handed over in a common, machine -readable format. If you request the direct transfer of the data to another person responsible, this is only done if it is technically feasible.

Information, correction and deletion

As part of the applicable legal provisions, you have the right to free information about your stored personal data, its origin and recipient and the purpose of data processing and, if necessary, the right to correct or delete this data. You can contact us at any time for further questions about personal data.

Right to restriction of processing

You have the right to restrict the processing of your personal data. You can contact us at any time. The right to restriction of processing is there in the following cases:

  • If you deny the correctness of your personal data stored by us, we usually need time to check this. For the duration of the exam, you have the right to restrict the processing of your personal data.
  • If the processing of your personal data was done illegally, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need you to exercise, defend or assert legal claims, you have the right to request the processing of your personal data instead of deleting.
  • If you have lodged an objection in accordance with Art. 21 Para. 1 GDPR, we have to weigh up between your and our interests. As long as it is not yet clear whose interests outweigh you, you have the right to restrict the processing of your personal data.

If you have restricted the processing of your personal data, this data - apart from your storage - may only be possible with your consent or to assert, exercise or defend legal claims or to protect the rights of a different natural or legal person or for reasons of an important public interest the European Union or a Member State.

SSL or TLS encryption

This page uses SSL or TLS encryption for safety reasons and to protect confidential content, such as orders or inquiries that you send to us as site operators. You can see an encrypted connection from the fact that the address line of the browser from "http: //" changes to "https: //" and on the castle symbol in your browser line.

If the SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Encrypted payment transactions on this website

If after the conclusion of a paid contract, there is an obligation to send us your payment details (e.g. account number when the direct debit authorization), this data is required for payment processing.

Payment transactions via the common means of payment (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. You can see an encrypted connection from the fact that the address line of the browser from "http: //" changes to "https: //" and on the castle symbol in your browser line.

If communication is encrypted, your payment details that you transmit to us cannot be read by third parties.

Objection to advertising emails

The use of contact details published within the framework of the imprint obligation to send not expressly requested advertising and information material is hereby objected. The operators of the pages expressly reserve the right to take legal steps in the event of unsolicited sending of advertising formations, for example through spam emails.

4. Data acquisition on this website

Cookies

Our websites use so -called "cookies". Cookies are small data packages and do not do any damage on your end device. You will either be temporarily saved on your device for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after the end of their visit. Permanent cookies remain stored on your end device until you delete it yourself or automatic deletion by your web browser.

Cookies can come from us (first party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g. cookies for processing payment services).

Cookies have different functions. Numerous cookies are technically necessary because certain website functions would not work without them (e.g. the shopping cart function or displaying videos). Other cookies can be used to evaluate user behavior or for advertising purposes.

Cookies that are necessary to carry out the electronic communication process, to provide certain functions you want (e.g. for shopping cart function) or to optimize the website (e.g. cookies to measure the web audience) (necessary cookies) Based on Art. 6 Para. 1 lit. f GDPR, provided that no other legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for technically error -free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been queried, the processing takes place exclusively on the basis of this consent (Art. 6 Para. 1 lit. a GDPR and Section 25 (1) TTDSG); The consent can be revoked at any time.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of the cookies when the browser is closed. When deactivating cookies, the functionality of this website can be restricted.

You can find out which cookies and services are used on this website.

Consent with usercentrics

This website uses usercentics consent technology to obtain your consent to store certain cookies on your end device or to use certain technologies and to document it in accordance with data protection. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, website: https://usercentrics.com/de/ (Below is "Usercentrics").

If you enter our website, the following personal data will be transferred to Usercentrics:

  • Your consent (s) or the revocation of your consent (s)
  • Your IP address
  • Information about your browser
  • Information about your device
  • Time of your visit on the website
  • Geolocation

Furthermore, Usercentrics stores a cookie in your browser in order to be able to assign you the granted consent and its revocation. The data collected in this way are saved until you ask us to delete, delete the usercentrics cookie yourself or the purpose for data storage is no longer necessary. Mandatory statutory retention obligations remain unaffected.

The usercentrics banner on this website was configured with the help of eRecht24. You can see this from the fact that the logo of Erecht24 appears in the banner. In order to play the Erecht24 logo in the banner, a connection to the image server of ERecht24 is established. The IP address is also transferred here, which is only saved in the server logs in anonymous form. The image server of ERecht24 is located in Germany with a German provider. The banner itself is provided exclusively by usercentrics.

Usercentrics is used in order to obtain the statutory consent for the use of certain technologies. The legal basis for this is Art. 6 Para. 1 lit. c GDPR.

Order processing

We have concluded a contract for order processing (AVV) to use the above service. This is a contract prescribed under data protection law that ensures that it only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

5. Social media

Facebook

Elements of the social network Facebook are integrated on this website. The provider of this service is the Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the data collected will also be transferred to the USA and other third countries.

An overview of the Facebook social media elements can be found here: https://developers.facebook.com/docs/plugins/?locale=de_DE.

If the social media element is active, a direct connection is established between your end device and the Facebook server. This gives Facebook the information that you have visited this website with your IP address. If you click the Facebook "Like button" while you are logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to assign your user account to visit this website. We would like to point out that as providers of the pages we receive no knowledge of the content of the transmitted data and its use by Facebook. Further information can be found in Facebook's data protection declaration at: https://de-de.facebook.com/privacy/explanation.

Insofar as consent (consent) has been obtained, the above -mentioned is used. Service based on Art. 6 Para. 1 lit. a GDPR and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, the service is used on the basis of our legitimate interest in the most comprehensive visibility in the social media.

Insofar as we and the Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are responsible for this data processing with the help of the tools described here and forwarded to Facebook (Art. 26 GDPR). Common responsibility is limited exclusively to the recording of the data and its transfer to Facebook. The processing by Facebook after the forwarding is not part of the common responsibility. The obligations incumbent on us together were recorded in an agreement on joint processing. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for the granting of data protection information when using the Facebook tool and for the data protection law secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. You can assert directly on Facebook If you assert the rights of concerns to us, we are obliged to forward them to Facebook.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Instagram

Functions of the Instagram service are integrated on this website. These functions are offered by the Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland.

If the social media element is active, a direct connection is established between your end device and the Instagram server. This gives Instagram information about visiting this website through you.

If you are logged into your Instagram account, you can link the content of this website with your Instagram profile by clicking the Instagram button. This allows Instagram to assign visiting this website to your user account. We would like to point out that as providers of the pages we receive no knowledge of the content of the transmitted data and its use by Instagram.

Insofar as consent (consent) has been obtained, the above -mentioned is used. Service based on Art. 6 Para. 1 lit. a GDPR and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, the service is used on the basis of our legitimate interest in the most comprehensive visibility in the social media.

Insofar as we and the Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland are responsible for this data processing with the help of the tool described here and forwarded to Facebook or Instagram. Art. 26 GDPR). Common responsibility is limited exclusively to the recording of the data and its transfer to Facebook or Instagram. The processing by Facebook or Instagram after the forwarding is not part of the common responsibility. The obligations incumbent on us together were recorded in an agreement on joint processing. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for the granting of data protection information when using the Facebook or Instagram tool and for data protection law secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook or Instagram products. You can assert directly on Facebook If you assert the rights of concerns to us, we are obliged to forward them to Facebook.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381.

Further information can be found in the data protection declaration of Instagram: https://privacycenter.instagram.com/policy/.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Pinterest

On this website we use elements of the Pinterest social network, which is operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.

If you call up a page that contains such an element, your browser establishes a direct connection to the Pinterest servers. This social media element transmits protocol data to the Pinterest server into the USA. These protocol data may contain your IP address, the address of the websites visited, which also contain pinterest functions, type and settings of the browser, date and time of the request, your usage of Pinterest and cookies.

Insofar as consent (consent) has been obtained, the above -mentioned is used. Service based on Art. 6 Para. 1 lit. a GDPR and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, the service is used on the basis of our legitimate interest in the most comprehensive visibility in the social media.

Further information on the purpose, scope and further processing and use of the data by Pinterest as well as your rights and options for protecting your privacy can be found in the data protection information from Pinterest: https://policy.pinterest.com/de/privacy-policy.

6. Analysis tools and advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The Google Tag Manager is a tool with which we can integrate tracking or statistics tools and other technologies on our website. The Google Tag Manager itself does not create user profiles, do not save cookies and do not make independent analyzes. It only serves to manage and play the tools integrated over him. However, the Google Tag Manager records its IP address, which can also be transferred to Google's parent company to the United States.

The Google Tag Manager is used on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in fast and uncomplicated integration and management of various tools on his website. If a corresponding consent has been queried, the processing takes place exclusively on the basis of Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG, provided that consent is saved in the storage of cookies or access to information in the end device of the user (z. B. Device fingerprinting) in the sense of the TTDSG. The consent can be revoked at any time.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google Analytics

This website uses functions of the Google Analytics web analysis service. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as B. page views, length of stay, operating systems used and origin of the user. This data is summarized in a user ID and assigned to the respective end device of the website seeker.

Furthermore, we can use Google Analytics etc. Record their mouse and scroll movements and clicks. Google Analytics also uses various modeling approaches to supplement the recorded data records and use machine learning technologies in data analysis.

Google Analytics uses technologies that enable the user's recognition for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information recorded by Google about the use of this website is usually transferred to a Google server in the USA and stored there.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://privacy.google.com/businesses/controllerterms/mccs/.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

IP anonymization

Google Analytics IP anonymization is activated. This reduces your IP address from Google within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area before the transmission to the United States. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activities and to provide other services related to the website operator. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.

Browser plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

You can find more information on dealing with user data at Google Analytics in Google's data protection declaration: https://support.google.com/analytics/answer/6004245?hl=de.

Google signals

We use Google signals. When you visit our website, Google Analytics and a. Your location, search history and YouTube history as well as demographic data (visitor data). This data can be used for personalized advertising using Google signal. If you have a Google account, the visitor data from Google signal will be linked to your Google account and used for personalized advertising messages. The data is also used for the creation of anonymized statistics on the user behavior of our users.

Order processing

We have concluded a contract for order processing with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

Google Analytics e-commerce measurement

This website uses the "E-Commerce measurement" function from Google Analytics. With the help of e-commerce measurement, the website operator can analyze the buying behavior of website visitors to improve their online marketing campaigns. Information, such as the orders made, average order values, shipping costs and the time from the view to the purchase of a product are recorded. This data can be summarized by Google under a transaction ID that is assigned to the respective user or the device.

Microsoft Advertising

The website operator uses Microsoft Advertising. Microsoft Advertising is an online advertising program of the Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Microsoft Advertising enables us to play advertisements in the bing search engine or on third-party websites if the user enters certain search terms at Bing (keyword stargeting). In addition, targeted advertisements can be played on the basis of the user data available at Microsoft (e.g. location data and interests) (target group stargeting). As the website operator, we can quantize this data, for example by analyzing which search terms have led to the performance of our advertisements and how many advertisements have led to corresponding clicks.

On this page we use the universal event tracking (UET) by Microsoft Advertising. Pseudonymized data is recorded in order to track which actions you carry out on our website after you have clicked on an advertisement at Microsoft Advertising. This includes your IP address (anonymized), device identifiers, information about device and browser settings, Microsoft Click ID (saved in Cookie), stay on the website, which areas of the website have been called through which display you can use to reach the website are and clicked clicked keyword.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://learn.microsoft.com/de-de/compliance/regulatory/offering-eu-model-clauses.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000KzNaAAK&status=Active

Hotjar

This website uses Hotjar. The provider is the Hotjar Ltd., Level 2, ST Julian's Business Center, 3, Elia Zammit Street, St Julean Stj 1000, Malta, Europe (website: https://www.hotjar.com).

Hotjar is a tool for analyzing your user behavior on this website. With Hotjar we can Record their mouse and scroll movements and clicks. Hotjar can also determine how long they remained in a certain point with the mouse pointer. From this information, Hotjar creates so -called heat maps, which can be used to determine which website areas are preferred by website visitors.

We can also determine how long you stayed on one side and when you left you. We can also determine where you have broken off your entries into a contact form (so-called conversion funnels).

In addition, direct feedback from website visitors can be obtained with Hotjar. This function serves to improve the website of the website operator.

Hotjar uses technologies that enable the user to recognize the user behavior (e.g. cookies or use device fingerprinting) for the purpose of analyzing user behavior).

Insofar as consent (consent) has been obtained, the use of DESO. G.Dienstes exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, this service is used on the basis of Art. 6 Para. 1 lit. f GDPR; The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.

Deactivate Hotjar

If you would like to deactivate the data acquisition through Hotjar, click on the following link and follow the instructions there: https://www.hotjar.com/policies/do-not-track/

Please note that Hotjar has to be deactivated for each browser or for each end device separately.

More information about Hotjar and the data collected can be found in the data protection declaration of Hotjar at the following link: https://www.hotjar.com/privacy

Order processing

We have concluded a contract for order processing (AVV) to use the above service. This is a contract prescribed under data protection law that ensures that it only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

Google ads

The website operator uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads enables us to play advertisements in the Google search engine or on third-party websites if the user enters Google's certain search terms (keyword stargeting). In addition, targeted advertisements can be played on the basis of the user data available on Google (e.g. location data and interests) (target group stargeting). As the website operator, we can quantize this data, for example by analyzing which search terms have led to the performance of our advertisements and how many advertisements have led to corresponding clicks.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google Adsense

This website uses Google Adsense, a service to integrate advertisements. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

With the help of Google Adsense, we can have targeted advertisements from third -party companies show on our website. The content of the advertisements depends on your interests, which Google determines based on its previous user behavior. Furthermore, when selecting the appropriate advertisement, context information, such as your location, the content of the website visited or the Google search terms entered by you are also taken into account.

Google Adsense uses cookies, web beacons (invisible graphics) and comparable recognition technologies. In this way, information such as visitor traffic on these pages can be evaluated.

The information recorded by Google Adsense about the use of this website (including your IP address) and delivery of advertising formats are transmitted to a Google server in the USA and stored there. This information can be passed on by Google to Google's contractual partner. However, Google will not bring your IP address together with other data you have stored.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://privacy.google.com/businesses/controllerterms/mccs/.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google ads remarketing

This website uses the functions of Google Ads Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

With Google Ads remarketing, we can assign people who interact with our online offer to assign certain target groups in order to then display interest-related advertising in the Google advertising network (remarketing or retargeting).

Furthermore, the advertising target groups created with Google Ads remarketing can be linked to Google's cross-device functions. In this way, interest-related, personalized advertising messages, which are adapted to you on another of your end devices (e.g. tablet or PC) depending on your previous usage and surfing behavior on a end device (e.g. cell phone).

If you have a Google account, you can object to personalized advertising under the following link: https://www.google.com/settings/ads/onweb/.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Further information and data protection regulations can be found in Google's data protection declaration at: https://policies.google.com/technologies/ads?hl=de.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Target group formation with customer comparison

For target group formation, we use Google Ads Remarketing customer comparison. Here we hand over certain customer data (e.g. email addresses) from our customer lists to Google. If the relevant customers are logged in Google users and in their Google account, suitable advertising messages within the Google network (e.g. on YouTube, Gmail or in the search engine) are displayed.

Google Conversion tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

With the help of Google Conversion tracking, Google and we can see whether the user has carried out certain actions. For example, we can evaluate which buttons clicked on our website and which products have been viewed or bought particularly frequently. This information is used to create conversion statistics. We learn the total number of users who clicked on our ads and which actions they have carried out. We do not receive any information with which we can personally identify the user. Google itself uses cookies or comparable recognition technologies for identification.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

You can find more information about Google Conversion Tracking in Google's data protection regulations: https://policies.google.com/privacy?hl=de.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Clavy

We have integrated claviyo on this website. The provider is the Klaviyo Inc., 125 Summer Street, Floor 6, Boston, MA, 02110, USA (hereinafter referred to as a clavy).

Klaviyo is a marketing automation tool for sending emails, SMS, push messages and to record customer reviews for eCommerce retailers.

For this purpose, Klaviyo stores consent to email marketing. The following data can be processed in particular: Name, telephone number, email address, address data, IP address, device detections, usage data (such as interactions between a user and the online system from Klaviyo, website or email , used browser, operating system used, referrer URL).

Claviyo is used on the basis of Art. 6 Para. 1 lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Further details can be found in the data protection declaration of the provider at https://www.klaviyo.com/legal/privacy.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt00000012uf9AAA&status=Active

The provider applies standard contract clauses for the transfer of personal data in third countries. You can find details here: https://www.klaviyo.com/legal/data-processing-agreement.

Order processing

We have concluded a contract for order processing (AVV) to use the above service. This is a contract prescribed under data protection law that ensures that it only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

Meta pixel (formerly Facebook Pixel)

This website uses the conversion measurement of the visitor action pixels from Facebook/Meta. The provider of this service is the Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the data collected will also be transferred to the USA and other third countries.

In this way, the behavior of the side visitors can be tracked after they have been forwarded to the provider's website by clicking on a Facebook advertisement. This enables the effectiveness of Facebook advertisements to be evaluated for statistical and market research purposes and future advertising measures can be optimized.

The data collected is anonymous for us as the operator of this website, we cannot draw any conclusions about the identity of the users. However, the data is saved and processed by Facebook, so that a connection to the respective user profile is possible and Facebook the data for its own advertising purposes, according to the Facebook data usage directive (https://de-de.facebook.com/about/privacy/). This enables Facebook to be able to switch advertisements on Facebook and outside of Facebook. This use of the data cannot be influenced by us as a site operator.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

We use the function of expanded comparison within the meta pixels.

The extended comparison enables us to have different types of data (e.g. residence, state, state, postal code, crashed email addresses, names, gender, date of birth or telephone number) of our customers and interested parties, which we collect on META ( Facebook). With this activation, we can cut our advertising campaigns on Facebook even more precisely to people who are interested in our offers. In addition, the extended comparison improves allocation of website conversions and expands custom audience.

Insofar as we and the Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are responsible for this data processing with the help of the tools described here and forwarded to Facebook (Art. 26 GDPR). Common responsibility is limited exclusively to the recording of the data and its transfer to Facebook. The processing by Facebook after the forwarding is not part of the common responsibility. The obligations incumbent on us together were recorded in an agreement on joint processing. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for the granting of data protection information when using the Facebook tool and for the data protection law secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. You can assert directly on Facebook If you assert the rights of concerns to us, we are obliged to forward them to Facebook.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

In Facebook's data protection information you will find further information on the protection of your privacy: https://de-de.facebook.com/about/privacy/.

You can also use the remarketing function "Custom Audiences" in the area of ​​settings for advertisements under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen deactivate. To do this, you must be registered on Facebook.

If you do not have a Facebook account, you can deactivate Facebook usage -based advertising on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Facebook Conversion API

We integrated Facebook Conversion API on this website. The provider of this service is the Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the data collected will also be transferred to the USA and other third countries.

Facebook Conversion API enables us to record the website of the website seeker with our website and pass it on to Facebook to improve the advertising performance on Facebook.

For this purpose, the time of the call, the website, your IP address and your user agent as well as possibly other specific data (e.g. purchased products, value of the shopping cart and currency) are recorded. You can find a complete overview of the capable data here: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Insofar as we and the Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are responsible for this data processing with the help of the tools described here and forwarded to Facebook (Art. 26 GDPR). Common responsibility is limited exclusively to the recording of the data and its transfer to Facebook. The processing by Facebook after the forwarding is not part of the common responsibility. The obligations incumbent on us together were recorded in an agreement on joint processing. The wording of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for the granting of data protection information when using the Facebook tool and for the data protection law secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. You can assert directly on Facebook If you assert the rights of concerns to us, we are obliged to forward them to Facebook.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

In Facebook's data protection information you will find further information on the protection of your privacy: https://de-de.facebook.com/about/privacy/.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Order processing

We have concluded a contract for order processing (AVV) to use the above service. This is a contract prescribed under data protection law that ensures that it only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

Facebook Custom Audiences

We use Facebook Custom Audiences. The provider of this service is the Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

If you visit or use our websites and apps, take advantage of our free or paid offers, transmit data to us or interact with the Facebook content of our company, we collect your personal data. If you give us consent to use Facebook Custom Audiences, we will transmit this data to Facebook with which Facebook can play out suitable advertising. Furthermore, target groups can be defined with your data (Lookalike Audiences).

Facebook processes this data as our processor. Details can be found in Facebook's usage agreement: https://www.facebook.com/legal/terms/customaudience.

This service is used on the basis of your consent in accordance with Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG. The consent can be revoked at any time.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Pinterest day

We have integrated Pinterest Day on this website. Provider is the Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.

Pinterest day serves to record certain actions that you run on our website. The data can then be used to show you on our website or on a different page of the Pinterest-Tag advertising network.

For this purpose, the Pinterest day and a. A day ID, your location and the referrer URL. Furthermore, action -specific data, such as the order value, order quantity, order number, category of purchased items and video views, can be recorded.

Pinterest-Day uses technologies that enable the user's cross-page recognition to analyze the user behavior (e.g. cookies or device fingerprinting).

Insofar as consent (consent) has been obtained, the above -mentioned is used. Service exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and § 25 TTDSG. The consent can be revoked at any time. If no consent has been obtained, this service is used on the basis of Art. 6 Para. 1 lit. f GDPR; The website operator has a legitimate interest in the most effective marketing measures.

Pinterest is a global company, so that data transfer to the USA can also take place. According to Pinterest, this data transmission is based on the EU Commission's standard contract clauses. You can find details here: https://policy.pinterest.com/de/privacy-policy.

More information about Pinterest Day can be found here: https://help.pinterest.com/de/business/article/track-conversions-with-pinterest-tag.

Order processing

We have concluded a contract for order processing (AVV) to use the above service. This is a contract prescribed under data protection law that ensures that it only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

7. Newsletter

Newsletter data

If you would like to obtain the newsletter offered on the website, we need an email address from you and information that allows us to check that you are the owner of the specified email address and agree to the receipt of the newsletter . Further data is not collected or only collected on a voluntary basis. We only use this data to send the requested information and do not pass it on to third parties.

The data entered in the newsletter registration form is processed exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke the consent to the storage of the data, the email address and its use to send the newsletter at any time, for example via the "Hire" link in the newsletter. The legality of the data processing processes that have already taken place remains unaffected by the revocation.

The data you have stored for the purpose of the newsletter reference will be saved by us or the newsletter from us or the newsletter service provider and deleted from the newsletter list after the newsletter has been canceled or after the continuation of the newsletter. We reserve the right to delete or block email addresses from our newsletter distributor at our own discretion within the framework of our legitimate interest in accordance with Art. 6 Para. 1 lit. f GDPR.

Data that we have stored for other purposes remain unaffected.

After your edition from the newsletter list list, your email address will be saved in a blacklist with us or the newsletter service provider, if necessary to prevent future mailings. The data from the blacklist are only used for this purpose and not merged with other data. This serves both your interest and our interest in compliance with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR). The storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.

8. Plugins and tools

YouTube

This website integrates videos of the YouTube website. The website operator is the Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

If you visit one of our websites on which YouTube is integrated, a connection to the YouTube servers is established. The YouTube server is communicated which of our pages you have visited.

Furthermore, YouTube can save various cookies on your end device or use comparable technologies for recognition (e.g. Device fingerprinting). In this way, YouTube can receive information about visitors to this website. This information is Used to capture video statistics, improve user friendliness and prevent fraud attempts.

If you are logged into your YouTube account, enable youtube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

YouTube is used in the interest of an appealing presentation of our online offers. This represents a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. TTDSG, insofar as the consent includes the storage of cookies or access to information in the end device of the user (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

Further information on dealing with user data can be found in the data protection declaration of YouTube at: https://policies.google.com/privacy?hl=de.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Vimeo

This website uses plugins from the Vimeo video portal. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

If you visit one of our pages equipped with a Vimeo video, a connection to the Vimeo servers is established. The Vimeo server is communicated which of our pages you have visited. Vimeo also gains her IP address. This also applies if you are not logged in at Vimeo or do not have an account at Vimeo. The information recorded by Vimeo is transmitted to the Vimeo server in the USA.

If you are logged into your Vimeo account, make Vimeo enable your surfing behavior to be assigned to your personal profile directly. You can prevent this by logging out of your Vimeo account.

Vimeo uses cookies or comparable recognition technologies (e.g. device fingerprinting) to recognize website visitors.

Vimeo is used in the interest of an appealing presentation of our online offers. This represents a legitimate interest within the meaning of Art. 6 Para. 1 Lit. f GDPR. TTDSG, insofar as the consent includes the storage of cookies or access to information in the end device of the user (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

The data transfer to the USA is based on the standard contract clauses of the EU Commission and, according to Vimeo, on "authorized business interests". You can find details here: https://vimeo.com/privacy.

Further information on dealing with user data can be found in Vimeo's data protection declaration at: https://vimeo.com/privacy.

Google Fonts

This page uses so -called Google Fonts for the uniform representation of fonts, which are provided by Google. When calling a page, your browser loads the fonts required to your browser cache to correctly display texts and fonts.

For this purpose, the browser you use connection to the Google servers must. This gives Google knowledge that this website has been accessed via your IP address. The use of Google Fonts is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the uniform representation of the typeface on his website. If a corresponding consent has been queried, the processing takes place exclusively on the basis of Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG, provided that consent is saved in the storage of cookies or access to information in the end device of the user (z. B. Device fingerprinting) in the sense of the TTDSG. The consent can be revoked at any time.

If your Google Fonts browser does not support, a standard font will be used by your computer.

More information about Google Fonts can be found at https://developers.google.com/fonts/faq and in the data protection declaration of Google: https://policies.google.com/privacy?hl=de.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google Maps

This page uses the map service Google Maps. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

To use the functions of Google Maps, it is necessary to save your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this page has no influence on this data transmission. If Google Maps is activated, Google can use Google Fonts for the purpose of the uniform representation of the fonts. When calling Google Maps, your browser invites the web fonts you need to correctly display texts and fonts.

The use of Google Maps takes place in the interest of an appealing presentation of our online offers and in the easy finding of the locations specified by us on the website. This represents a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. TTDSG, insofar as the consent includes the storage of cookies or access to information in the end device of the user (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

You can find more information on dealing with user data in Google's data protection declaration: https://policies.google.com/privacy?hl=de.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google Recaptcha

We use "Google Recaptcha" (hereinafter "Recaptcha") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Recaptcha is to check whether the data input on this website (e.g. in a contact form) is carried out by a person or through an automated program. For this purpose, Recaptcha analyzes the behavior of the website searcher based on various characteristics. This analysis begins automatically as soon as the website visitors enter the website. For analysis, Recaptcha evaluates various information (e.g. IP address, length of stay of the website seeker on the website or mouse movements made by the user). The data recorded during the analysis are forwarded to Google.

The recaptcha analyzes run completely in the background. Website visitors are not pointed out that an analysis takes place.

The storage and analysis of the data takes place on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting his web offers from improper automated spying and spam. If a corresponding consent has been queried, the processing takes place exclusively on the basis of Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG, provided that consent is saved in the storage of cookies or access to information in the end device of the user (z. B. Device fingerprinting) in the sense of the TTDSG. The consent can be revoked at any time.

Further information on Google Recaptcha can be found in the Google data protection regulations and Google Use conditions at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.

The company has certification according to the "EU-US-US-DATA privacy framework" (DPF). The DPF is an agreement between the European Union and the United States, which is intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified according to the DPF undertakes to comply with these data protection standards. Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Zapier

We integrated Zapier on this website. The provider is the Zapier Inc., Market St. #62411, San Francisco, CA 94104-5401, USA (hereinafter Zapier).

Zapier enables us to link various functionalities, databases and tools with our website and synchronize them with each other. In this way, for example, it is possible to automatically play content that we publish on our website on our social media channels or to export content from marketing and analysis tools. Depending on the functionality, Zapier can also record various personal data.

Zapier is used on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the most effective integration of the tools used. If a corresponding consent has been queried, the processing takes place exclusively on the basis of Art. 6 Para. 1 Lit. a GDPR and Section 25 (1) TTDSG, provided that consent is saved in the storage of cookies or access to information in the end device of the user (z. B. Device fingerprinting) in the sense of the TTDSG. The consent can be revoked at any time.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://zapier.com/tos.

Order processing

We have concluded a contract for order processing (AVV) to use the above service. This is a contract prescribed under data protection law that ensures that it only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

9. Ecommerce and payment providers

Processing of customer and contract data

We collect, process and use personal customer and contract data for justification, design and change our contractual relationships. We only collect, process and use personal data on the use of this website (usage data), if necessary, to enable or bill the use of the service to the user. The legal basis for this is Art. 6 Para. 1 lit. b GDPR.

The collected customer data will be deleted after the order or termination of the business relationship and the course of the existing legal retention periods. Statutory retention periods remain unaffected.

Data transmission when the contract is concluded for online shops, retailers and shipping

If you order goods from us, we pass on your personal data to the transport company entrusted for delivery and to the payment service provider commissioned with the payment processing. Only data that the respective service provider needs to fulfill his task are published. The legal basis for this is Art. 6 Para. 1 lit. b GDPR, which allows the processing of data to fulfill a contract or pre -contractual measures. If you have given the appropriate consent in accordance with Art. 6 Para. 1 Lit. a GDPR, we will hand over your email address to the transport company entrusted with the delivery so that you can inform you by email about the shipping status of your order ; You can revoke your consent at any time.

Payment services

We bind payment services from third -party companies on our website. If you make a purchase from us, your payment data (e.g. name, payment amount, account connection, credit card number) will be processed by the payment service provider for the purpose of payment processing. The respective contract and data protection regulations of the respective providers apply to these transactions. The payment service providers are used on the basis of Art. 6 Para. 1 lit. b GDPR (contract processing) and in the interest of a smooth, comfortable and secure payment process (Art. 6 Para. 1 lit. f GDPR). Insofar as your consent is queried for certain actions, Art. 6 Para. 1 lit. a GDPR is the legal basis for data processing; Consenting can be revoked at any time for the future.

We use the following payment services / payment service providers as part of this website:

PayPal

The provider of this payment service is PayPal (Europe) S.à.r.l. et cie, s.c.a., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal").

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.

Details can be found in PayPal's data protection declaration: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

Apple Pay

The provider of the payment service is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. The Apple data protection declaration can be found at: https://www.apple.com/legal/privacy/de-ww/.

Google Pay

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. You can find Google's data protection declaration here: https://policies.google.com/privacy.

Stripe

The Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter "Stripe") is the provider of customers within the EU.

Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://stripe.com/de/privacy and https://stripe.com/de/guides/general-data-protection-regulation.

You can read details about this in the data protection declaration of Stripe at the following link: https://stripe.com/de/privacy.

Clear

The provider is the Klarna, Sveafen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers various payment options (e.g. purchase in installments). If you choose the payment with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the Klarna checkout solution. Details on the use of Klarna cookies can be found in the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.

You can read details about this in the data protection declaration of Klarna at the following link: https://www.klarna.com/de/datenschutz/.

Paydirekt

The provider of this payment service is Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main, Germany (hereinafter "Paydirekt"). If you carry out the payment using a Paydirekt, Paydirekt collects various transaction data and forwards it to the bank, in which you are registered with Paydirekt. In addition to the data required for the payment, Paydirekt collects other data such as B. Delivery address or individual positions in the shopping cart. Paydirekt then authentifies the transaction using the authentication procedure stored by the bank. The payment amount is then transferred from your account to our account. Neither we nor third parties have access to their account details. Details on payment with Paydirekt can be found in the terms and conditions and the data protection regulations of Paydirekt at: https://www.paydirekt.de/agb/index.html.

Sofortüberweisung

The provider of this payment service is SOFORT GmbH, Theresienhöhe 12, 80339 Munich (hereinafter referred to as "Immediate GmbH"). With the help of the "Sofortüberweisung" procedure, we receive a payment confirmation from Sofort GmbH in real time and can immediately start fulfilling our liabilities. If you have chosen the "Sofortüberweisung" payment method, send the PIN and a valid TAN to the Sofort GmbH with which it can log into your online banking account. Immediate GmbH automatically checks your account balance after logging in and carries out the transfer to us with the help of the TAN you transmit. Then she immediately sends us a transaction confirmation. After logging in, your sales, the credit line of the overdraft facility and the presence of other accounts as well as their stocks are also automatically checked. In addition to the PIN and the TAN, the payment data you enter and data on your person will also be transmitted to Sofort GmbH. The data on your person is the first and last name, address, telephone number (s), email address, IP address and, if necessary, other data required for payment processing. The transmission of this data is necessary in order to determine your identity without doubt and to prevent fraud attempts. Details for payment with Sofortüberweisung can be found in the following links: https://www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/.

Amazon Pay

The provider of this payment service is the Amazon Payments Europe S.C.A., 38 Avenue J.F. Kennedy, L-1855 Luxembourg.

You can read details about dealing with your data in the data protection declaration of Amazon Pay at the following link: https://pay.amazon.de/help/201212490?ld=APDELPADirect.

Dot

The provider of this payment service is Mollie B.V., Kezersgracht 126, 1015cw Amsterdam, Netherlands (hereinafter referred to as "Mollie"). With the help of Mollie we can integrate various payment methods on our website. Details can be found in Mollie's data protection declaration: https://www.mollie.com/de/privacy.

Payone

The provider of this payment service is Payone GmbH, Lyoner Straße 9, 60528 Frankfurt am Main (hereinafter referred to as "Payone"). Details can be found in Payone's data protection declaration: https://www.payone.com/DE-de/datenschutz.

giropay

Paydirekt GmbH, Stephanstraße 14 - 16, 60313 Frankfurt am Main (hereinafter "Giropay") is the provider of this payment service.

Details can be found in Giropay's data protection declaration: https://www.paydirekt.de/agb/index.html.

Shopify Payment

The provider of this payment service in the EU is the Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter "Shopify Payment").

Details can be found in the data protection declaration of Shopify Payment: https://www.shopify.de/legal/datenschutz.

American Express

The provider of this payment service is the American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter "American Express").

American Express can transmit data to his parent company to the USA. The data transfer to the USA is based on the Binding Corporate Rules. You can find details here: https://www.americanexpress.com/en-pl/company/legal/privacy-centre/european-implementing-principles/.

Further information can be found in the American Express data protection declaration: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html.

Mastercard

The provider of this payment service is the Mastercard Europe SA, CHAUSSEEEE de Tervuren 198a, B-1410 Waterloo, Belgium (hereinafter "Mastercard").

Mastercard can transmit data to his parent company to the USA. The data transfer to the USA is based on the Binding Corporate Rules by MasterCard. You can find details here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.

Visa

The provider of this payment service is Visa Europe Services Inc., London branch, 1 Sheldon Square, London W2 6TT, Great Britain (hereinafter "Visa").

Great Britain is considered a safe third -country country under data protection law. This means that Britain has a data protection level that corresponds to the data protection level in the European Union.

Visa can transfer data to his parent company to the USA. Data transfer to the USA is based on the standard contract clauses of the EU Commission. You can find details here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.

Further information can be found in Visa's data protection declaration: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.