Privacy policy
Privacy Policy
This English version is provided for convenience. The German version of this privacy policy is the authoritative one.
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: 3 September 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Transmission of Personal Data
- International Data Transfers
- General Information on Data Storage and Erasure
- Rights of Data Subjects
- Business Services
- Business Processes and Procedures
- Use of Online Platforms for Sales and Marketing Purposes
- Providers and Services Used in the Course of Business
- Payment Procedures
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Registration, Login and User Account
- Blogs and Publication Media
- Contact and Inquiry Management
- Chatbots and Chat Functions
- Newsletters and Electronic Notifications
- Promotional Communication via E-Mail, Post, Fax or Telephone
- Web Analysis, Monitoring and Optimisation
- Online Marketing
- Customer Reviews and Rating Procedures
- Profiles in Social Networks (Social Media)
- Plug-ins and Embedded Functions and Content
- Changes and Updates
- Definitions
Controller
Dr. Berndsen GmbH
Wasserstr. 25
59423 Unna
Germany
Authorised representatives: Managing Director: Sabine Berndsen
E-mail address: service@drberndsen.de
Phone: +49 2303 89991
Overview of Processing Activities
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Inventory data.
- Payment data.
- Location data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Event data (Facebook).
- Log data.
Categories of Data Subjects
- Service recipients and clients.
- Prospective customers.
- Communication partners.
- Users.
- Business and contractual partners.
- Third parties.
- Customers.
Purposes of Processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organisational procedures.
- Remarketing.
- Conversion measurement.
- Audience building.
- Organisational and administrative procedures.
- Feedback.
- Marketing.
- Profiles with user-related information.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
- Financial and payment management.
- Public relations.
- Sales promotion.
- Business processes and business management procedures.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) - The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
Note on the applicability of the GDPR and the Swiss FADP: This privacy notice serves to provide information pursuant to both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For this reason, please note that the terms of the GDPR are used due to their broader territorial application and comprehensibility. In particular, instead of the terms "processing" of "personal data", "overriding interest" and "particularly sensitive personal data" used in the Swiss FADP, the terms "processing" of "personal data", "legitimate interest" and "special categories of data" as used in the GDPR are applied. However, within the scope of the Swiss FADP, the legal meaning of these terms continues to be determined in accordance with the Swiss FADP.
Applicability of data protection rules in the country of domicile: In the country in which the controller is domiciled, national data protection regulations apply in addition to the General Data Protection Regulation (GDPR).
Security Measures
In accordance with legal requirements and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the threat to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, entry of, disclosure of, availability of and separation of the data. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the erasure of data and responses to threats to the data. We also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principles of data protection by design and by default.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services from unauthorised access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is signalled by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Transmission of Personal Data
In the course of our processing of personal data, it may happen that such data is transmitted to, or disclosed to, other bodies, companies, legally independent organisational units or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
International Data Transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of the use of third-party services or the disclosure or transmission of data to other persons, bodies or companies (which can be recognised by the postal address of the respective provider or where the privacy policy expressly refers to data transfers to third countries), this is always done in accordance with the legal requirements.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers, which comply with the requirements of the EU Commission and establish contractual obligations to protect your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should any changes occur within the framework of the DPF, the standard contractual clauses will step in as a reliable fallback option. In this way, we ensure that your data always remains adequately protected, even in the event of any political or legal changes.
For the individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, corresponding security measures apply, in particular standard contractual clauses, express consent or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General Information on Data Storage and Erasure
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consents are withdrawn or no further legal bases for the processing exist. This applies to cases in which the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule exist where legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the pursuit of legal claims or for the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.
Where there are several indications regarding the retention period or erasure deadlines for a piece of data, the longest period is always decisive. Data that is no longer retained for its originally intended purpose but due to legal requirements or other reasons is processed exclusively for the reasons justifying its retention.
Commencement of periods at the end of the year: If a period does not expressly begin on a specific date and is at least one year in length, it automatically commences at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the context of which data is stored, the event triggering the period is the date on which the termination or other ending of the legal relationship takes effect.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, arising in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about this data as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without undue delay, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
- Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State in which you habitually reside, or the supervisory authority of your place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Business Services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively "contractual partners"), for the initiation, performance and settlement of contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken upon request as well as communication in connection with the respective contractual relationship.
The processing serves in particular the fulfilment of our primary and ancillary contractual obligations. This includes the provision of the agreed services, any update and information obligations, the handling of warranty claims and other service disruptions, the processing of withdrawals, terminations of continuing obligations, reversals, refunds and the handling of other contract-related declarations and inquiries. Both one-off contracts and ongoing contractual relationships are covered.
The data processed includes, in particular, master data such as name, address and, where applicable, company name, contact data such as e-mail address and telephone number, contract and service data such as the subject matter of the contract, contract term, order or transaction number, usage and performance data, payment and billing data, as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of carrying out an order.
In addition, we process the data to safeguard our rights and to fulfil legal obligations. This includes, in particular, retention obligations under commercial and tax law, documentation obligations and, where applicable, obligations to provide evidence and accountability. Processing is also carried out on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners against misuse and threats to data, secrets and other legal interests. This may also include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisers or other vicarious agents, insofar as this is necessary for the performance of the contract or the fulfilment of legal obligations.
Personal data is passed on to third parties only insofar as this is necessary for the performance of the contract, for the implementation of pre-contractual measures, for the protection of legitimate interests or for the fulfilment of legal obligations. We provide separate information about processing beyond this, in particular for marketing purposes, within the scope of this privacy policy.
We inform contractual partners which data is required in each individual case at the time the data is collected, for example in online forms by means of appropriate labelling or in personal contact.
The data is erased as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations prevent this. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the context of a specific order is erased after completion of the order and expiry of any retention periods, provided that no further legal or contractual storage obligations exist.
The legal basis for the processing is Art. 6 para. 1 lit. b GDPR for the implementation of pre-contractual measures and the performance of the respective contractual relationship, as well as Art. 6 para. 1 lit. c GDPR for the fulfilment of legal obligations. Insofar as the processing is based on legitimate interests, it is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Insofar as the processing is based on Art. 6 para. 1 lit. f GDPR, it is carried out to safeguard our legitimate interests in a proper and efficient business organisation, the internal administration and documentation of business transactions, the assertion and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, and the economic management and further development of our business operations. These interests consist in particular in ensuring secure and legally compliant business operations and in preserving our entrepreneurial capacity to act.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and e-mail addresses or telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients; prospective customers. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; security measures; communication; office and organisational procedures; organisational and administrative procedures. Business processes and business management procedures.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Online shop, order forms, e-commerce and service fulfilment: We process our customers' data to enable them to select, purchase or order the chosen products, goods and associated services, as well as their payment and provision, delivery or performance. Where necessary for the execution of an order, we use service providers, in particular postal, freight and shipping companies, to carry out the delivery or performance for our customers. For the processing of payment transactions, we use the services of banks and payment service providers. The required information is marked as such in the context of the order or comparable purchase process and includes the information needed for delivery or provision and invoicing, as well as contact information to enable any necessary consultation.
Business Processes and Procedures
Personal data of service recipients and clients - including customers, clients or, in specific cases, mandators, patients or business partners as well as other third parties - is processed in the context of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates business management workflows in areas such as customer management, sales, payment transactions, accounting and project management.
The data collected serves to fulfil contractual obligations and to organise operational processes efficiently. This includes the handling of business transactions, the management of customer relationships, the optimisation of sales strategies and the assurance of internal invoicing and financial processes. In addition, the data supports the safeguarding of the controller's rights and promotes administrative tasks and the organisation of the company.
Personal data may be passed on to third parties insofar as this is necessary for the fulfilment of the stated purposes or legal obligations. After expiry of statutory retention periods or when the purpose of processing no longer applies, the data is erased. This also includes data that must be stored for longer periods due to tax-law and statutory evidence obligations.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Log data (e.g. log files concerning logins or the retrieval of data or access times).
- Data subjects: Service recipients and clients; customers; prospective customers; communication partners; business and contractual partners; third parties. Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; office and organisational procedures; business processes and business management procedures; security measures; provision of our online offering and user-friendliness; communication; marketing; sales promotion; public relations; financial and payment management. Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR).
Further information on processing operations, procedures and services:
- Contact management and contact maintenance: Procedures required in the context of organising, maintaining and securing contact information (e.g. setting up and maintaining a central contact database, regular updates of contact information, monitoring data integrity, implementing data protection measures, ensuring access controls, performing backups and restorations of contact data, training employees in the effective use of contact management software, regular review of communication history and adjustment of contact strategies).
- Customer account: Customers can create an account within our online offering (e.g. customer or user account, in short "customer account"). If the registration of a customer account is required, customers are informed of this as well as of the information required for registration. Customer accounts are not public and cannot be indexed by search engines. As part of the registration and subsequent logins and use of the customer account, we store customers' IP addresses along with the access times in order to be able to prove registration and to prevent any misuse of the customer account. If the customer account has been terminated, the customer account data will be erased after the date of termination, unless it is retained for purposes other than provision in the customer account or must be retained for legal reasons (e.g. internal storage of customer data, order transactions or invoices). It is the customers' responsibility to back up their data upon termination of the customer account.
- General payment transactions: Procedures required in the execution of payment transactions, the monitoring of bank accounts and the control of payment flows (e.g. creation and verification of bank transfers, processing of direct debit transactions, checking of account statements, monitoring of incoming and outgoing payments, chargeback management, account reconciliation, cash management).
- Accounting, accounts payable, accounts receivable: Procedures required in the recording, processing and control of business transactions in the area of accounts payable and accounts receivable (e.g. creation and verification of incoming and outgoing invoices, monitoring and management of open items, execution of payment transactions, handling of dunning procedures, account reconciliation in the context of receivables and payables, accounts payable and accounts receivable bookkeeping).
- Financial accounting and taxes: Procedures required in the recording, management and control of finance-related business transactions as well as in the calculation, reporting and payment of taxes (e.g. account assignment and posting of business transactions, preparation of quarterly and annual financial statements, execution of payment transactions, handling of dunning procedures, account reconciliation, tax advice, preparation and submission of tax returns, handling of tax matters).
- Marketing, advertising and sales promotion: Procedures required in the context of marketing, advertising and sales promotion (e.g. market analysis and target group determination, development of marketing strategies, planning and implementation of advertising campaigns, design and production of advertising materials, online marketing including SEO and social media campaigns, event marketing and trade fair participation, customer loyalty programmes, sales promotion measures, performance measurement and optimisation of marketing activities, budget management and cost control).
- Public relations: Procedures required in the context of public relations work (e.g. development and implementation of communication strategies, planning and implementation of PR campaigns, creation and distribution of press releases, maintenance of media contacts, monitoring and analysis of media response, organisation of press conferences and public events, crisis communication, creation of content for social media and company websites, management of corporate branding).
Use of Online Platforms for Sales and Marketing Purposes
We offer our services on online platforms operated by other service providers. In this context, the privacy policies of the respective platforms apply in addition to our privacy notices. This applies in particular with regard to the execution of the payment process and the procedures used on the platforms for reach measurement and interest-based marketing.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and e-mail addresses or telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; marketing. Business processes and business management procedures.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- shopify: Platform through which e-commerce services are offered and carried out. The services and the processes carried out in connection with them include, in particular, online shops, websites, their offerings and content, community elements, purchase and payment transactions, customer communication, as well as analysis and marketing; Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Website: https://www.shopify.com/de/. Privacy policy: https://www.shopify.com/de/legal/datenschutz.
Providers and Services Used in the Course of Business
In the course of our business activities, we use additional third-party services, platforms, interfaces or plug-ins (in short "services") in compliance with the legal requirements. Their use is based on our interests in the proper, lawful and economical management of our business operations and our internal organisation.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation). Contract data (e.g. subject matter of the contract, term, customer category).
- Data subjects: Service recipients and clients; prospective customers. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; office and organisational procedures. Business processes and business management procedures.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Evey Events & Tickets: Sale and management of event tickets (e.g. seminars); processing of participant data for ticket issuance; Service provider: StayTuned Digital, Inc. (Zenpire), 9 Murray Street, 11NE, New York, NY 10007, USA; Website: https://eveyevents.com/. Privacy policy: https://staytuned.digital/privacy-policy/.
- Cowlendar appointment booking: Online appointment booking for consultations and coaching; Service provider: PENIDA SAS, 14 Rue Charles V, 75004 Paris, France; Website: https://cowlendar.com/. Privacy policy: https://cowlendar.com/privacy-policy.
Payment Procedures
In the context of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, use other service providers in addition to banks and credit institutions (collectively "payment service providers"). Payment transactions are carried out exclusively via encrypted connections in accordance with the state of the art, so that the data entered is protected from unauthorised access during transmission.
The data processed by the payment service providers includes inventory data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, amount and recipient-related information. This information is required to carry out the transactions. However, the data entered is processed and stored only by the payment service providers. This means that we do not receive any account- or credit-card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers may transmit the data to credit agencies. The purpose of this transmission is to verify identity and creditworthiness. In this regard, we refer to the terms and conditions and privacy notices of the payment service providers.
The terms and conditions and privacy notices of the respective payment service providers apply to payment transactions and can be accessed within the respective websites or transaction applications. We also refer to these for further information and for the assertion of withdrawal, access and other data subject rights.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Contact data (e.g. postal and e-mail addresses or telephone numbers).
- Data subjects: Service recipients and clients; business and contractual partners. Prospective customers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations. Business processes and business management procedures.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Apple Pay: Payment services (technical integration of online payment methods); Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Website: https://www.apple.com/de/apple-pay/. Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
- Google Pay: Payment services (technical integration of online payment methods); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://pay.google.com/intl/de_de/about/. Privacy policy: https://business.safety.google/privacy/.
- Klarna: Payment services (technical integration of online payment methods); Service provider: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden; Website: https://www.klarna.com/de. Privacy policy: https://www.klarna.com/de/datenschutz.
- Mollie: Payment services (technical integration of online payment methods); Service provider: Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands; Website: https://www.mollie.com/de. Privacy policy: https://www.mollie.com/de/legal/privacy.
- PayPal: Payment services (technical integration of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Website: https://www.paypal.com/de. Privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full.
- Shopify Payments: Payment services (technical integration of online payment methods). Payments are processed via Shopify Payments, Shopify's integrated payment platform. It enables customers to use various supported payment methods, depending on the region. Payment processing takes place on the basis of the Shopify Payments terms of use, which are displayed to the customer during the checkout process. Further information is available at https://www.shopify.com/de/payments; Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Website: https://www.shopify.de. Privacy policy: https://www.shopify.de/legal/datenschutz.
Provision of the Online Offering and Web Hosting
We process users' data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); log data (e.g. log files concerning logins or the retrieval of data or access times). Content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation).
- Data subjects: Users (e.g. website visitors, users of online services). Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Provision of the online offering on rented storage space: For the provision of our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also called a "web host").
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, the browser type and version, the user's operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to avoid server overload (particularly in the case of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability. Erasure of data: Log file information is stored for a maximum of 30 days and then erased or anonymised. Data whose further retention is required for evidentiary purposes is exempt from erasure until the respective incident has been finally resolved.
- Amazon Web Services (AWS): Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxembourg; Website: https://aws.amazon.com/de/; Privacy policy: https://aws.amazon.com/de/privacy/. Data processing agreement: https://aws.amazon.com/de/compliance/gdpr-center/.
Use of Cookies
The term "cookies" refers to functions that store information on users' devices and read it from them. Cookies can also be used for various purposes, for example for the functionality, security and convenience of online offerings and for the creation of analyses of visitor flows. We use cookies in accordance with the statutory provisions. To this end, we obtain the users' prior consent where required. Where consent is not necessary, we rely on our legitimate interests. This applies where the storage and reading of information is essential in order to be able to provide expressly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We provide clear information about its scope and which cookies are used.
Notes on legal bases under data protection law: Whether we process personal data using cookies depends on consent. Where consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage period: With regard to the storage period, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device is closed. For example, the login status can be saved and preferred content can be displayed directly when the user visits a website again. Likewise, user data collected with the aid of cookies can be used for reach measurement. Unless we provide users with explicit information about the type and storage duration of cookies (e.g. when obtaining consent), they should assume that they are permanent and that the storage period can be up to two years.
General information on withdrawal and objection (opt-out): Users can withdraw the consents they have given at any time and also declare an objection to processing in accordance with the legal requirements, including by means of the privacy settings of their browser.
- Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a consent management solution in which users' consent to the use of cookies or to the procedures and providers named in the consent management solution is obtained. This procedure serves to obtain, log, manage and withdraw consents, in particular with regard to the use of cookies and comparable technologies used to store, read and process information on users' devices. As part of this procedure, users' consents are obtained for the use of cookies and the associated processing of information, including the specific processing operations and providers named in the consent management procedure. Users also have the option of managing and withdrawing their consents. The declarations of consent are stored in order to avoid repeated requests and to be able to provide proof of consent in accordance with the legal requirements. Storage takes place server-side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies in order to be able to assign the consent to a specific user or their device. If no specific information on the providers of consent management services is available, the following general information applies: the duration of storage of the consent is up to two years. A pseudonymous user identifier is created and stored together with the time of consent, information on the scope of the consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, the system and the device used.
Registration, Login and User Account
Users can create a user account. As part of the registration process, users are informed of the required mandatory information, which is processed for the purpose of providing the user account on the basis of the fulfilment of contractual obligations. The data processed includes, in particular, the login information (username, password and an e-mail address).
When users make use of our registration and login functions and use the user account, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests as well as those of the users in protection against misuse and other unauthorised use. This data is generally not passed on to third parties unless it is necessary for the pursuit of our claims or there is a legal obligation to do so.
Users may be informed by e-mail about events relevant to their user account, such as technical changes.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Log data (e.g. log files concerning logins or the retrieval of data or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; security measures; organisational and administrative procedures. Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure". Erasure upon termination.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Erasure of data after termination: If users have terminated their user account, their data relating to the user account will be erased, subject to any legal permission, obligation or consent of the users.
- No obligation to retain data: It is the users' responsibility to back up their data before the end of the contract in the event of termination. We are entitled to irretrievably erase all user data stored during the term of the contract.
Blogs and Publication Media
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data is processed for the purposes of the publication medium only to the extent necessary for its presentation and the communication between authors and readers, or for reasons of security. In all other respects, we refer to the information on the processing of visitors to our publication medium within the scope of this privacy notice.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via online form). Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, e-mail, telephone or via social media) and in the context of existing user and business relationships, the details of the inquiring persons are processed insofar as this is necessary to respond to the contact inquiries and any requested measures.
- Types of data processed: Contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via online form). Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Further information on processing operations, procedures and services:
- Contact form: When contacting us via our contact form, by e-mail or other communication channels, we process the personal data transmitted to us in order to respond to and handle the respective request. This usually includes information such as name, contact information and, where applicable, other information communicated to us that is necessary for appropriate handling. We use this data exclusively for the stated purpose of contact and communication.
- weclapp: Software for customer management, process and sales support (multi-channel communication, i.e. management of customer inquiries from various channels, sales, process management, analyses and feedback functions); Service provider: weclapp SE, Neue Mainzer Straße 66 - 68, 60311 Frankfurt am Main, Germany; Website: https://www.weclapp.com/de/. Privacy policy: https://www.weclapp.com/de/datenschutz/.
Chatbots and Chat Functions
We offer online chats and chatbot functions as a means of communication (collectively referred to as "chat services"). A chat is an online conversation conducted with a certain degree of immediacy. A chatbot is software that answers users' questions or informs them via messages. When you use our chat functions, we may process your personal data.
If you use our chat services within an online platform, your identification number within the respective platform is also stored. We may also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via the chat services and log registration and consent processes in order to be able to prove them in accordance with legal requirements.
We advise users that the respective platform provider may learn that and when users communicate with our chat services, and may collect technical information about the device used by the users and, depending on the settings of their device, also location information (so-called metadata) for the purposes of optimising the respective services and for security purposes. Likewise, the metadata of communication via chat services (i.e., for example, the information about who communicated with whom) could be used by the respective platform providers, in accordance with their provisions, to which we refer for further information, for marketing purposes or to display advertising tailored to users.
If users agree to a chatbot activating information with regular messages, they can unsubscribe from the information at any time for the future. The chatbot informs users how and with which terms they can unsubscribe from the messages. When users unsubscribe from chatbot messages, their data is deleted from the list of message recipients.
We use the aforementioned information to operate our chat services, e.g. to address users personally, to answer their inquiries, to transmit any requested content and also to improve our chat services (e.g. to "teach" chatbots answers to frequently asked questions or to identify unanswered inquiries).
Notes on legal bases: We use the chat services on the basis of consent if we have previously obtained the users' permission to process their data in the context of our chat services (this applies to cases in which users are asked for consent, e.g. so that a chatbot can send them regular messages). Insofar as we use chat services to answer users' inquiries about our services or our company, this is done for contractual and pre-contractual communication. Otherwise, we use chat services on the basis of our legitimate interests in optimising the chat services, their economic efficiency and increasing the positive user experience.
Withdrawal, objection and erasure: You can withdraw consent you have given at any time or object to the processing of your data in the context of our chat services.
- Types of data processed: Contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Shopify Inbox (chat): Chat function for customer inquiries in our online shop; Service provider: Shopify International Ltd., c/o Intertrust Ireland, 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland; Website: https://www.shopify.com/de/inbox. Privacy policy: https://www.shopify.com/legal/privacy.
Newsletters and Electronic Notifications
We send newsletters, e-mails and other electronic notifications (hereinafter "newsletters") exclusively with the consent of the recipients or on the basis of a legal permission. If the contents of the newsletter are specified when registering for it, those contents are decisive for the users' consent. Providing your e-mail address is normally sufficient to register for our newsletter. However, in order to be able to offer you a personalised service, we may ask you to provide your name for a personal address in the newsletter, or further information if this is necessary for the purpose of the newsletter.
Erasure and restriction of processing: We may store unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to prove that consent was previously given. The processing of this data is restricted to the purpose of potentially defending against claims. An individual erasure request is possible at any time, provided that the former existence of consent is confirmed at the same time. In the event of obligations to permanently observe objections, we reserve the right to store the e-mail address solely for this purpose in a block list (so-called "blocklist").
The logging of the registration process is carried out on the basis of our legitimate interests for the purpose of proving that it was conducted properly. Insofar as we commission a service provider to send e-mails, this is done on the basis of our legitimate interests in an efficient and secure delivery system.
Contents:Information about us, our services, promotions and offers.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and e-mail addresses or telephone numbers); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by e-mail or post).
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
- Opt-out: You can cancel the receipt of our newsletter at any time, i.e. withdraw your consents or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter or you can otherwise use one of the contact options given above, preferably e-mail.
Further information on processing operations, procedures and services:
- Shopify Email (newsletter delivery): Delivery of our newsletter via Shopify Email; Service provider: Shopify International Ltd., c/o Intertrust Ireland, 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland; Website: https://www.shopify.com/de/email-marketing. Privacy policy: https://www.shopify.com/legal/privacy.
- Measurement of open and click rates: The newsletters contain a so-called "web beacon", i.e. a pixel-sized file that is retrieved from our server, or from the server of the delivery service provider if we use one, when the newsletter is opened. As part of this retrieval, technical information such as details about the browser and your system, as well as your IP address and the time of retrieval, are initially collected. This information is used for the technical improvement of our newsletter based on the technical data or the target groups and their reading behaviour, based on their retrieval locations (which can be determined using the IP address) or the access times. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. The information collected is assigned to the individual newsletter recipients and stored in their profiles until erasure. On this basis, user profiles are created in which usage behaviour and user characteristics are stored. The measurement of open and click rates, the storage of the measurement results in the users' profiles and their further processing are carried out on the basis of the users' consent. A separate withdrawal from the performance measurement is unfortunately not possible; in this case, the entire newsletter subscription must be cancelled or objected to. In that case, the stored profile information will be erased.
- Reminder e-mails for the ordering process: If users do not complete an ordering process, we may remind users of the ordering process by e-mail and send them a link to continue it. This function can be useful, for example, if the purchase process could not be continued due to a browser crash, an oversight or forgetting. The e-mails are sent on the basis of consent, which users can withdraw at any time.
Promotional Communication via E-Mail, Post, Fax or Telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as e-mail, telephone, post or fax, in accordance with the legal requirements.
The recipients have the right to withdraw any consents given at any time or to object to the promotional communication at any time free of charge via the contact options mentioned above.
After withdrawal or objection, we store the data required to prove the previous authorisation for contact or delivery for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is restricted to the purpose of a possible defence against claims. On the basis of the legitimate interest in permanently observing the users' withdrawal or objection, we also store the data required to avoid renewed contact (e.g. depending on the communication channel, the e-mail address, telephone number, name).
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and e-mail addresses or telephone numbers). Content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by e-mail or post); marketing. Sales promotion.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Web Analysis, Monitoring and Optimisation
Web analysis (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offering and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the aid of reach analysis, we can, for example, identify at what time our online offering or its functions or content are used most frequently, or invite reuse. It is also possible for us to understand which areas require optimisation.
In addition to web analysis, we may also use testing procedures, for example to test and optimise different versions of our online offering or its components.
Unless otherwise stated below, profiles, i.e. data aggregated for a usage process, may be created for these purposes and information may be stored in a browser or device and then read from it. The information collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data vis-à-vis us or vis-à-vis the providers of the services we use, the processing of location data is also possible.
In addition, the IP addresses of the users are stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear user data (such as e-mail addresses or names) is stored in the context of web analysis, A/B testing and optimisation, but pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for the data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles). Provision of our online offering and user-friendliness.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- MIDA session recording and heatmaps: Recording of sessions (mouse movements, clicks, scrolling behaviour) and creation of heatmaps to analyse and improve our online shop. Used only with consent; the recordings are not linked to customer accounts; Service provider: MIDA (BSS Commerce), 14-16-18-19F Viwaseen Tower, 48 To Huu Str, Trung Van Ward, Nam Tu Liem Dist., Hanoi, Vietnam; Website: https://mida-app.io/. Privacy policy: https://mida-app.io/privacy-policy/.
- Intelligems A/B and price testing: A/B tests and price tests to optimise our offering. Used only with consent; Service provider: Intelligems, Inc., 651 N Broad St., Suite 206, Middletown, DE 19709, USA; Website: https://www.intelligems.io/. Privacy policy: https://www.intelligems.io/privacy-policy.
- Bugsnag error monitoring: Technical error monitoring to ensure the stability of our online shop; Service provider: SmartBear Software Inc., 450 Artisan Way, Somerville, MA 02145, USA (EU representative: SmartBear, Mayoralty House, Flood Street, Galway, Ireland); Website: https://www.bugsnag.com/. Privacy policy: https://smartbear.com/privacy/.
-
Google Analytics: We use Google Analytics to measure and analyse the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or e-mail addresses. It serves to assign analysis information to a device in order to recognise which content users have accessed within one or various usage processes, which search terms they have used, have accessed again or have interacted with our online offering. The time of use and its duration are also stored, as well as the sources of the users who refer to our online offering and technical aspects of their devices and browsers.
In the process, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. Analytics does, however, provide coarse geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, the IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. It is not logged, is not accessible and is not used for any further purposes. When Google Analytics collects measurement data, all IP lookups are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymisation of the IP address); Privacy policy: https://business.safety.google/privacy/; Data processing agreement: https://business.safety.google/adsprocessorterms/; Opt-out: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and data processed). - Google as recipient of consent: The consent given by users in the context of a consent dialogue (also known as "cookie opt-in/consent", "cookie banner", etc.) serves several purposes. On the one hand, it serves to fulfil our obligation to obtain consent for the storage and reading of information on and from the users' devices in accordance with the ePrivacy requirements. On the other hand, it covers the processing of users' personal data in accordance with data protection requirements. Furthermore, this consent also applies vis-à-vis Google, as the company is obliged under the provisions of the Digital Markets Act (DMA) to obtain effective consent for personalised services. For this reason, we share the status of the consents given or refused by users with Google. Our consent management software informs Google whether consent has been given or not. The aim is to ensure that users' decisions are taken into account when using Google measurement services - in particular in the context of reach measurement, conversion tracking and personalised advertising (e.g. Google Analytics, Google Ads and comparable services) - as well as when integrating other functions and external services. The processing is dynamic and depends on the respective user selection, including any withdrawal of consent; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://support.google.com/analytics/answer/9976101?hl=de. Privacy policy: https://business.safety.google/privacy/.
Online Marketing
We process personal data for the purpose of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as "content") based on the potential interests of users, as well as the measurement of its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (the so-called "cookie"), or similar procedures are used, by means of which the information about the user relevant to the display of the aforementioned content is stored. This may include, for example, content viewed, websites visited, online networks used, but also communication partners and technical information such as the browser used, the computer system used and information on usage times and functions used. If users have consented to the collection of their location data, this may also be processed.
In addition, the IP addresses of the users are stored. However, we use available IP masking procedures (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear user data (such as e-mail addresses or names) is stored in the context of the online marketing procedure, but pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.
The statements in the profiles are usually stored in the cookies or by means of similar procedures. These cookies can generally also be read later on other websites that use the same online marketing procedure, analysed for the purpose of displaying content, and supplemented with further data and stored on the server of the online marketing procedure provider.
Exceptionally, it is possible to assign clear data to the profiles, primarily when the users are, for example, members of a social network whose online marketing procedure we use and the network links the user profiles with the aforementioned information. We ask you to note that users can make additional agreements with the providers, for example by giving consent as part of the registration process.
In principle, we only receive access to aggregated information about the success of our advertisements. However, in the context of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e., for example, to the conclusion of a contract with us. Conversion measurement is used solely to analyse the success of our marketing measures.
Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.
Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for the data processing is that permission. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Notes on withdrawal and objection:
We refer to the privacy notices of the respective providers and the objection options indicated for the providers (so-called "opt-out"). If no explicit opt-out option has been indicated, you have the option of switching off cookies in your browser settings. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered collectively for the respective territories:
a) Europe: https://youronlinechoices.eu/.
b) Canada: https://youradchoices.ca/.
c) USA: https://optout.aboutads.info/.
d) Cross-territorial: https://optout.aboutads.info.
- Types of data processed: Content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Event data (Facebook) ("event data" is information that is sent to the provider Meta, for example via the Meta Pixel (whether via apps or other channels), and relates to persons or their actions. This data includes, for example, details of website visits, interactions with content and functions, app installations and product purchases. The event data is processed with the aim of creating target groups for content and advertising messages (custom audiences). It is important to note that event data does not include actual content such as written comments, login information or contact information such as names, e-mail addresses or telephone numbers. "Event data" is deleted by Meta after a maximum of two years, and the target groups formed from it disappear when our Meta user accounts are deleted.).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest-/behaviour-based profiling, use of cookies); conversion measurement (measurement of the effectiveness of marketing measures); audience building; marketing; profiles with user-related information (creation of user profiles); provision of our online offering and user-friendliness. Remarketing.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Meta Pixel and audience building (custom audiences): With the help of the Meta Pixel (or comparable functions for transmitting event data or contact information via interfaces in apps), Meta is able, on the one hand, to identify the visitors to our online offering as a target group for the display of advertisements (so-called "Meta ads"). Accordingly, we use the Meta Pixel to display the Meta ads placed by us only to those users on Meta platforms and within the services of partners cooperating with Meta (the so-called "Audience Network" https://www.facebook.com/audiencenetwork/) who have also shown an interest in our online offering or who have certain characteristics (e.g. interest in certain topics or products, which become apparent from the websites visited) that we transmit to Meta (so-called "custom audiences"). With the help of the Meta Pixel, we also want to ensure that our Meta ads correspond to the potential interest of the users and do not appear intrusive. With the help of the Meta Pixel, we can also track the effectiveness of the Meta ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta ad (so-called "conversion measurement"); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Further information: User event data, i.e. behavioural and interest data, is processed for the purposes of targeted advertising and audience building on the basis of the joint controllership agreement ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company domiciled in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which concerns in particular the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
- Facebook ads: Placement of advertisements within the Facebook platform and evaluation of the advertisement results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Opt-out: We refer to the privacy and advertising settings in the users' profile on the Facebook platforms as well as to Facebook's consent procedures and contact options for exercising access and other data subject rights, as described in Facebook's privacy policy; Further information: User event data, i.e. behavioural and interest data, is processed for the purposes of targeted advertising and audience building on the basis of the joint controllership agreement ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company domiciled in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which concerns in particular the transmission of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
- Google Ads and conversion measurement: Online marketing procedure for the purpose of placing content and advertisements within the service provider's advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who have a presumed interest in the advertisements. Furthermore, we measure the conversion of the advertisements, i.e. whether the users have taken them as an occasion to interact with the advertisements and to make use of the advertised offers (so-called conversions). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing conditions between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
- Google Ads remarketing: Google remarketing, also called retargeting, is a technology by which users who use an online service are included in a pseudonymous remarketing list so that advertisements can be displayed to the users on other online offerings based on their visit to the online service; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://marketingplatform.google.com; Privacy policy: https://business.safety.google/privacy/; Further information: Types of processing and data processed: https://business.safety.google/adsservices/. Data processing conditions between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
- Instagram ads: Placement of advertisements within the Instagram platform and evaluation of the advertisement results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/; Opt-out: We refer to the privacy and advertising settings in the users' profile on the Instagram platform as well as to Instagram's consent procedures and Instagram's contact options for exercising access and other data subject rights in Instagram's privacy policy; Further information: User event data, i.e. behavioural and interest data, is processed for the purposes of targeted advertising and audience building on the basis of the joint controllership agreement ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). The joint controllership is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company domiciled in the EU. The further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which concerns in particular the transmission of the data to the parent company Meta Platforms, Inc. in the USA.
Customer Reviews and Rating Procedures
We participate in review and rating procedures in order to evaluate, optimise and promote our services. When users rate us via the participating rating platforms or procedures or otherwise provide feedback, the general terms and conditions or terms of use and the privacy notices of the providers also apply. As a rule, submitting a rating also requires registration with the respective providers.
In order to ensure that the persons submitting reviews have actually used our services, we transmit, with the customers' consent, the data required for this purpose relating to the customer and the service used to the respective rating platform (including name, e-mail address and order number or article number). This data is used solely to verify the authenticity of the user.
- Types of data processed: Contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients. Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via online form). Marketing.
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Further information on processing operations, procedures and services:
- Reviews.io customer reviews: Collection and display of customer reviews of our shop and our products; Service provider: REVIEWS.io Limited, 29 St Nicholas Place, Leicester, LE1 4LD, United Kingdom; Website: https://www.reviews.io/. Privacy policy: https://www.reviews.io/legal/user-privacy-policy.
-
Trusted Shops (Trustbadge): Rating platform - Within the scope of the joint controllership existing between us and Trusted Shops, please preferably contact Trusted Shops for data protection questions and to assert your rights, using the contact options specified in the privacy information. Irrespective of this, you can always contact the controller of your choice. Your request will then, if necessary, be forwarded to the other controller for a response.
The Trustbadge is provided by a US-American CDN provider (content delivery network). An adequate level of data protection is ensured by standard data protection clauses and further contractual measures.
When the Trustbadge is accessed, the web server automatically stores a so-called server log file, which also contains your IP address, the date and time of the retrieval, the volume of data transferred and the requesting provider (access data) and documents the retrieval. The IP address is anonymised immediately after collection, so that the stored data cannot be assigned to your person. The anonymised data is used in particular for statistical purposes and error analysis.
If you have given your consent, the Trustbadge accesses order information stored on your device after completion of the order (order total, order number, product purchased if applicable) as well as your e-mail address, and your e-mail address is hashed using a cryptological one-way function. The hash value is then transmitted to Trusted Shops together with the order information in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR. This serves to check whether you are already registered for Trusted Shops services. If this is the case, further processing takes place in accordance with the contractual agreement made between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will subsequently be given the opportunity to register manually for the use of the services or to conclude the protection within the scope of your possibly already existing user agreement.
For this purpose, the Trustbadge accesses the following information stored on the device you are using after completion of your order: order total, order number and e-mail address. This is necessary so that we can offer you buyer protection. The data is only transmitted to Trusted Shops when you actively decide to conclude the buyer protection by clicking on the correspondingly labelled button in the so-called Trustcard. If you decide to use the services, further processing is governed by the contractual agreement with Trusted Shops in accordance with Art. 6 para. 1 lit. b GDPR, in order to be able to complete your registration for buyer protection and secure the order, and, if applicable, to subsequently send you review invitations by e-mail.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Art. 6 para. 1 lit. f GDPR for the purpose of ensuring trouble-free operation. Processing may take place in third countries (USA and Israel). An adequate level of data protection is ensured in the case of the USA by standard data protection clauses and further contractual measures, and in the case of Israel by an adequacy decision.
; Service provider: Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, Germany; Website: https://www.trustedshops.de. Privacy policy: https://www.trustedshops.de/impressum-datenschutz/.
Profiles in Social Networks (Social Media)
We maintain online presences within social networks and, in this context, process user data in order to communicate with the users active there or to offer information about ourselves.
We would like to point out that user data may be processed outside the European Union. This may result in risks for users because, for example, it could make it more difficult to enforce users' rights.
Furthermore, user data within social networks is usually processed for market research and advertising purposes. For example, usage profiles can be created based on users' usage behaviour and the interests resulting from it. The latter may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the users' interests. For these purposes, cookies are usually stored on the users' computers, in which the usage behaviour and interests of the users are stored. In addition, data may also be stored in the usage profiles independently of the devices used by the users (particularly if they are members of the respective platforms and are logged in there).
For a detailed description of the respective forms of processing and the objection options (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
In the case of requests for information and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the latter have access to the user data and can take appropriate measures and provide information directly. If you still need help, you can contact us.
- Types of data processed: Contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and contributions as well as information relating to them, such as details of authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; feedback (e.g. collecting feedback via online form). Public relations.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure".
- Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Instagram: Social network, enables the sharing of photos and videos, commenting on and favouriting posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/.
- Facebook pages: Profiles within the social network Facebook - The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page ("fan page"). This includes, in particular, information about user behaviour (e.g. content viewed or interacted with, actions taken) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). More details can be found in the Facebook data policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical evaluations via the "Page Insights" service, which provide information about how people interact with our page and its content. The basis for this is an agreement with Facebook ("Information about Page Insights": https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures and the exercise of data subject rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users can therefore direct requests for information or erasure directly to Facebook. The rights of the users (in particular access, erasure, objection, complaint to a supervisory authority) remain unaffected. The joint controllership is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for further processing, including any transmission to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.facebook.com. Privacy policy: https://www.facebook.com/privacy/policy/.
- YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Privacy policy: https://business.safety.google/privacy/. Opt-out: https://myadcenter.google.com/.
Plug-ins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may be, for example, graphics, videos or city maps (hereinafter uniformly referred to as "content").
The integration always requires that the third-party providers of this content process the users' IP address, since without the IP address they could not send the content to their browser. The IP address is therefore required for the display of this content or these functions. We endeavour to use only content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, the time of the visit and other information about the use of our online offering, and may also be combined with such information from other sources.
Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for the data processing is that permission. Otherwise, user data is processed on the basis of our legitimate interests (i.e. interest in efficient, economical and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved). Location data (information on the geographical position of a device or person).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest-/behaviour-based profiling, use of cookies); audience building. Marketing.
- Retention and erasure: Erasure in accordance with the information in the section "General Information on Data Storage and Erasure". Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users' devices for a period of two years).
- Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
- Logbase cart functions (Dealeasy, Selleasy, Rebolt): Discount and additional offers in the shopping cart and ordering process; Service provider: Logbase Technologies LLP, PSG STEP E-Lab, PSG College of Technology, Peelamedu, Coimbatore, TN 641004, India; Website: https://www.logbase.io/. Privacy policy: https://www.logbase.io/privacy-policy.
- Terms and Conditions Popup (Torden Apps): Obtaining consent to our terms and conditions during the ordering process; Service provider: Torden Apps, Curitiba, Brazil (legal form and address not publicly stated); Website: https://tordenapps.com/. Privacy policy: https://tordenapps.com/privacy.
- Integration of third-party software, scripts or frameworks (e.g. jQuery): We integrate software into our online offering that we retrieve from servers of other providers (e.g. function libraries that we use for the purpose of displaying our online offering or improving its user-friendliness). In doing so, the respective providers collect the users' IP address and may process it for the purposes of transmitting the software to the users' browser as well as for security purposes and for the evaluation and optimisation of their offering.
- Google Maps: We integrate the maps of the "Google Maps" service of the provider Google. The data processed may include, in particular, IP addresses and location data of the users; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; Website: https://mapsplatform.google.com/. Privacy policy: https://business.safety.google/privacy/.
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://www.youtube.com; Privacy policy: https://business.safety.google/privacy/. Opt-out: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff.
Changes and Updates
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and please verify the information before contacting them.
Definitions
This section provides you with an overview of the terms used in this privacy policy. Where the terms are defined by law, their legal definitions apply. The following explanations, on the other hand, are primarily intended to aid understanding.
- Inventory data: Inventory data comprises essential information required for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include, among other things, personal and demographic information such as names, contact information (addresses, telephone numbers, e-mail addresses), dates of birth and specific identifiers (user IDs). Inventory data forms the basis for any formal interaction between persons and services, institutions or systems by enabling unambiguous assignment and communication.
- Content data: Content data comprises information generated in the course of creating, editing and publishing content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content, but also includes metadata that provides information about the content itself, such as tags, descriptions, author information and publication dates.
- Contact data: Contact data is essential information that enables communication with persons or organisations. It includes, among other things, telephone numbers, postal addresses and e-mail addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Conversion measurement: Conversion measurement (also referred to as "visit action evaluation") is a procedure that can be used to determine the effectiveness of marketing measures. For this purpose, a cookie is usually stored on the users' devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, this allows us to track whether the advertisements we have placed on other websites were successful.
- Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about the way in which data is processed, transmitted and managed. Metadata, also known as data about data, comprises information that describes the context, origin and structure of other data. It may include information on file size, creation date, the author of a document and change histories. Communication data records the exchange of information between users via various channels, such as e-mail traffic, call logs, messages in social networks and chat histories, including the persons involved, timestamps and transmission paths. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, logs of transactions and activities, and audit logs used for tracking and reviewing operations.
- Usage data: Usage data refers to information that records how users interact with digital products, services or platforms. This data encompasses a wide range of information showing how users use applications, which functions they prefer, how long they stay on certain pages and via which paths they navigate through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. In addition, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of "profiles with user-related information", or "profiles" for short, includes any type of automated processing of personal data that consists of using this personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used to analyse system problems, for security monitoring or to create performance reports.
- Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and may include the behaviour or interests of visitors in certain information, such as the content of websites. With the aid of reach analysis, operators of online offerings can, for example, see at what time users visit their websites and what content they are interested in. This enables them, for example, to better adapt the content of their websites to the needs of their visitors. Pseudonymous cookies and web beacons are frequently used for reach analysis purposes in order to recognise returning visitors and thus obtain more precise analyses of the use of an online offering.
- Remarketing: "Remarketing" or "retargeting" refers to the practice of noting, for example for advertising purposes, which products a user was interested in on a website in order to remind the user of these products on other websites, e.g. in advertisements.
- Location data: Location data is generated when a mobile device (or another device with the technical requirements for location determination) connects to a radio cell, a WLAN or similar technical means and functions of location determination. Location data serves to indicate the geographically determinable position on earth at which the respective device is located. Location data can be used, for example, to display map functions or other information dependent on a location.
- Tracking: "Tracking" refers to the ability to trace the behaviour of users across several online offerings. As a rule, behavioural and interest information relating to the online offerings used is stored in cookies or on the servers of the providers of the tracking technologies (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
- Controller: The "controller" is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically every handling of data, be it collection, evaluation, storage, transmission or erasure.
- Contract data: Contract data is specific information relating to the formalisation of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged or sold. This category of data is essential for the management and fulfilment of contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include start and end dates of the contract, the type of services or products agreed, price agreements, payment terms, termination rights, renewal options and special conditions or clauses. It serves as the legal basis for the relationship between the parties and is crucial for clarifying rights and obligations, enforcing claims and resolving disputes.
- Payment data: Payment data comprises all information required for processing payment transactions between buyers and sellers. This data is of crucial importance for electronic commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers and billing information. Payment data may also contain information about payment status, chargebacks, authorisations and fees.
- Audience building: Audience building (also "custom audiences") refers to the determination of target groups for advertising purposes, e.g. the display of advertisements. For example, a user's interest in certain products or topics on the internet can be used to conclude that this user is interested in advertisements for similar products or the online shop in which they viewed the products. "Lookalike audiences" (or similar target groups) in turn refers to the display of content deemed suitable to users whose profiles or interests presumably correspond to the users for whom the profiles were formed. Cookies and web beacons are usually used for the purposes of creating custom audiences and lookalike audiences.