Privacy Policy

Responsible party pursuant to data protection laws, in particular the EU General Data Protection Regulation (GDPR), is

Julie Hansen & Laura Herold

Your rights as the data subject

You can exercise the following rights at any time using the contact details of our data protection officer:

  • Information on your data stored by us and the processing thereof (Art. 15 GDPR),
  • Rectification of inaccurate personal data (Art. 16 GDPR),
  • Deletion of your data stored by us (Art. 17 GDPR),
  • Restriction of the data processing, provided that we may not delete your data due to legal obligations (Art. 18 GDPR),
  • Objection to the processing of your data with us (Art. 21 GDPR), and
  • Data portability, provide that you have consented to the data processing or have entered into a contract with us (Art. 20 GDPR).

If you have given us consent, you may withdraw it at any time, which will remain in effect in the future.

You can contact a supervisory authority with a complaint at any time, e.g. the supervisory authority of the state of your residence or the authority that oversees us as the responsible party.

You’ll find a list of supervisory authorities (for the non-public area) with their respective addresses at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Collecting general information during a visit to our website

Type and purpose of the processing

When you access our website – i.e. if you do not register or submit information – information of a general nature will be collected automatically. This information (server log files) contains the type of web browser, the operating system used, the domain name of your Internet service provider, your IP address and the like.

It is processed in particular for the following purposes:

  • Ensuring an unproblematic website connection,
  • Ensuring seamless use of our website,
  • Analysis of system security and stability, as well as
  • For additional administrative purposes.

We will not use your data to draw conclusions about your person. This type of information will be statistically analysed by us if necessary to optimise our website and its underlying technology.

Legal basis

The processing occurs according to Art. 6 Para. 1 (f) GDPR, based on our legitimate interest in improving the stability and functionality of our website.

Recipients

Recipients of the data may be technical service providers, who work on the operation and maintenance of our website as the processor.

Retention period

The data will be deleted as soon as they are no longer required for the reason they were collected. This is generally the case, after the respective session has ended, for data that are used to make the website available.

Mandatory or required provision

The provision of the aforementioned personal data is neither legally nor contractually mandatory. Without the IP address however, the service and functionality of our website are not guaranteed. Furthermore, individual services can be unavailable or limited. For this reason, an objection is excluded.

Registration on our website

Type and purpose of the processing

With the registration to use our personalised services, some personal data such as name, address, contact and communication information (e.g. phone number and e-mail address) are collected. If you are registered with us, you can access content and services that we only offer to registered users. Registered users also have the ability to change or delete the data entered during registration at any time. At any time, we will also provide you with information on the personal data about you that we have saved.

Legal basis

The data entered during registration are processed on the basis of the user’s consent (Art. 6 Para. 1 (a) GDPR).

If the registration fulfils the obligations of a contract, whose contractual party is the data subject, or serves to implement pre-contractual measures, the additional legal basis for the data processing is Art. 6 Para. 1 (b) GDPR.

Recipients

Recipients of the data may be technical service providers, who work on the operation and maintenance of our website as the processor.

Retention period

Data are only processed in this context provided that the corresponding consent has been given. The data will be deleted thereafter, provided that no statutory retention obligations prohibit the deletion. To contact us in this regard, please use the contact information provided at the end of this privacy policy.

Mandatory or required provision

The provision of your personal data is voluntary, based solely on your consent. Without the provision of your personal data, we cannot give you access to our content and services.

Newsletter

Type and purpose of the processing

Your data will be used exclusively to send you the newsletter you subscribed for via e-mail. We request your name so that we can address you personally in the newsletter and identify you as needed should you want to exercise your rights as a data subject.

To receive the newsletter, providing your e-mail address is sufficient. When you subscribe to our newsletter, the data you provide will be used exclusively for this purpose. Subscribers can also be notified by e-mail about circumstances that are relevant to the service or registration (such as changes to the newsletter offer or technical matters).

We need a valid e-mail address to complete your registration. In order to verify that a registration is actually made by the owner of an e-mail address, we utilise the ‘double opt-in’ procedure. To this end, we log the newsletter subscription request, when a confirmation e-mail is sent and the receipt of the requested reply. Additional data is not collected. The data will be used exclusively for sending the newsletter and will not be shared with third parties.

Legal basis

Based on your express consent (Article 6 (1) a DSGVO), we will send you our newsletter on a regular basis or comparable information via e-mail to your specified e-mail address.

The consent to save and use your personal data for the newsletter may be withdrawn at any time and remain in effect in the future. Every newsletter contains a corresponding link, and you can also unsubscribe on this website at any time or inform us of your cancellation via the contact option indicated at the end of this privacy policy.

Recipients

Recipients of the data may be the processors.

Retention period

Data are only processed in this context provided that the corresponding consent has been given. The data will be deleted thereafter.

Mandatory or required provision

The provision of your personal data is voluntary, based solely on your consent. Unfortunately, we cannot send you our newsletter without your consent.

Contact form

Type and purpose of the processing

The data you enter are used for individual communication with you. A valid e-mail address and your name are required for this communication, which serves to organize your inquiry and the respective subsequent reply. Providing additional information is optional.

Legal basis

The processing of the data entered in the contact form occurs on the basis of a legitimate interest (Art. 6 Para. 1 (f) GDPR).

By providing the contact form, our aim is to facilitate an uncomplicated means for you to contact us. The information you enter will be used to process the inquiry and saved for possible follow-up questions.

If you contact us to request an offer, the processing of the information provided in the contact form will occur in order to implement pre-contractual measures (Art. 6 Para. 1 (b) GDPR).

Recipients

Recipients of the data may be the processors.

Retention period

The data will be deleted no later than 6 months after processing the inquiry.

Provided that we enter into a contract together, we will use the statutory retention periods in the German Commercial Code (Handelsgesetzbuch) and delete your data according to the respective stipulated deadlines.

Mandatory or required provision

The provision of your personal data is voluntary. However, we can only process your inquiry if you provide us with your name, e-mail address and the reason for your inquiry.

Using Google Analytics

Type and purpose of the processing

This website uses Google Analytics, a web analytics service of Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043 USA (hereinafter: ‘Google’). Google Analytics uses so-called ‘cookies’, i.e. text files that are stored on your computer and allow an analysis of your use of the website. The information generated by the cookie about your use of this website is typically transmitted to a Google server in the U.S. and stored there. However, due to the activation of IP anonymisation on these websites, your IP address will be truncated beforehand by Google within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the U.S. and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, summarise reports on website activities and provide other services related to website and Internet usage to the website operator. The IP address transferred from your browser as part of Google Analytics will not be combined with other data from Google.

The data processing purposes are the website-use analysis and the summary of reports on activities on the website. Based on the use of the website and the Internet, other related services will be provided.

Google address: Google Building Gordon House, 4 Barrow St, Grand Canal Dock, Dublin 4, D04 V4X7, Ireland

Legal basis

The processing of the data occurs on the basis of the user’s consent (Art. 6 Para. 1 (a) GDPR).

Recipients

The recipient of the data is Google as the processor. For this, we have entered into the corresponding data-processing contract with Google.

Retention period

The deletion of the data occurs as soon as they are no longer necessary for our recording-keeping purposes.

Third country transfers

Google processes your data in the United States of America and is subject to the EU-US Privacy Shield: https://www.privacyshield.gov/EU-US-Framework.

Mandatory or required provision

The provision of your personal data is voluntary, based solely on your consent. If you prevent access, this can lead to functional limitations on the website.

Revocation of consent

You can prevent the storage of cookies by a corresponding setting in your browser software; however, please note that in this case you may not be able to use all the functions of this website in their entirety. Furthermore, you can prevent the collected data generated by the cookie and the data related to your use of the website (including your IP address) being transmitted to Google, as well as the processing of this data by Google, by downloading and installing the browser plug-in available at the following link: browser add-on to deactivate Google Analytics.

In addition, or as an alternative to the browser add-on, you can prevent tracking by Google Analytics on our web pages by clicking this link, which will install an opt-out cookie on your device. This will prevent data collection by Google Analytics for this website and for this browser in the future, as long as the cookie remains installed in your browser.

Profiling:

With the assistance of the tracking tool Google Analytics, the browsing behaviour of the website visitors can be evaluated and their respective interests can be analysed. For this analysis, we create a pseudonymous user profile.

Google AdWords

Type and purpose of the processing

Our website uses Google Conversion Tracking. The operating company of the Google AdWords services is Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. If you have reached our website via a Google advertisement, Google Adwords will place a cookie on your computer. The conversion tracking cookie is used when a user clicks on an ad from Google.

If the user visits certain pages on our website, and the cookie has not expired, we and Google can recognise that the user clicked on the ad and was redirected to this page. Every Google AdWords customer receives a different cookie. Thus, cookies cannot be tracked by the websites of AdWords customers. The information gathered by the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. The customers see the total number of users who clicked on their advertisement and were redirected to a conversion tracking tag page. However, they do not receive information that personally identifies users.

Legal basis

Your consent is the legal basis for the integration of Google AdWords and the associated data transfer to Google (Art. 6 Para. 1 (a) GDPR).

Recipients

Whenever you visit our website, your personal information, including your IP address, is transferred to Google in the U.S. This personal information is saved by Google. Google may transfer such personal data collected through the technical process to third parties.

Our company does not receive information from Google that could identify the data subject.

Retention period

These cookies lose their validity after 30 days and are not used for personal identification.

Third country transfers

Google processes your data in the United States of America and is subject to the EU-US Privacy Shield https://www.privacyshield.gov/EU-US-Framework.

Revocation of consent

If you do not want to participate in the tracking, you can reject the required cookie use – for example via a general browser setting that disables the automatic use of cookies or configures your browser to block cookies from the domain ‘googleleadservices.com’.

Please note that you should not delete the opt-out cookies as long as you do not want to save measurement data. If you have deleted all your cookies in the browser, you must use the respective opt-out cookie again.

Mandatory or required provision

The provision of your personal data is voluntary, based solely on your consent. If you prevent access, this can lead to functional limitations on the website.

Revision of our privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. Your next visit will be subject to the new privacy policy.

Questions for the data protection officer

If you have any questions pertaining to data protection, please send us an e-mail or contact the person responsible for data protection in our organization

Revision of our privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. Your next visit will be subject to the new privacy policy.

Questions for the data protection officer
If you have any questions pertaining to data protection, please send us an e-mail or contact the person responsible for data protection in our organization
[output id=”dsb”]

The privacy policy was created via the activeMind AG Privacy Policy Generator (Version: 2018-09-24).

TRUSTMARK WITH REVIEWS

Integration of the Trusted Shops Trustbadge

The Trusted Shops Trustbadge is integrated on this website to display our Trusted Shops Trustmark and the collected reviews as well as to offer Trusted Shops products to buyers after an order.

This is necessary to safeguard our legitimate prevailing interests in an optimal marketing by ensuring the safety of your purchase according to Article 6 (1) f GDPR. The Trustbadge and the services advertised with it are an offer of the Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, _Germany. The Trustbadge is made available by a CDN provider (Content-Delivery-Network) as part of order processing. The Trusted Shops GmbH uses also service provider from the USA. An adequate level of data protection is guaranteed. Further information to the data security of the Trusted Shops GmbH can be found here: https://www.trustedshops.co.uk/imprint/

When the Trustbadge is called up, the web server automatically saves a server log file which contains, for example, your IP address, the date and time of the call, the amount of data transferred and the requesting provider (access data) and documents the call. Individual access data are stored in a security database for the analysis of security problems. The log files are automatically deleted 90 days after creation at the latest.

Further personal data will be transferred to Trusted Shops GmbH if you decide to use Trusted Shops products after completing an order or have already registered for use. The contractual agreement made between you and Trusted Shops applies. For this purpose personal data is automatically collected from the order data. Whether or not you are already registered as a Trusted Shops customer is automatically checked by means of a neutral parameter, the e-mail address hashed by cryptological one-way function. The e-mail address is converted to this hash value, which cannot be decrypted by Trusted Shops before it is transmitted. After checking for a match, the parameter is deleted automatically.

This is necessary for the fulfillment of our and Trusted Shops' legitimate prevailing interests in the provision of the buyer protection linked to the specific order and the transactional review services in accordance with Art. 6 para. 1 s. 1 lit. f GDPR. Further details, including your right to object, can be found in the Trusted Shops Privacy Policy linked above and within the Trustbadge.