Privacy
Privacy Policy
1) Introduction and Contact Details of the Responsible Party
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data refers to all data that can be used to personally identify you.
1.2 The party responsible for data processing on this website in accordance with the General Data Protection Regulation (GDPR) is VINELLO retail GmbH, Bärensteiner Str. 30, 01277 Dresden, Germany, Tel.: 035146925655, E-Mail: [email protected]. The individual or legal entity responsible for processing personal data is the one who decides alone or jointly with others about the purposes and means of processing personal data.
1.3 The responsible party has appointed a data protection officer, who can be reached as follows: "René Harnisch, Bärensteiner Str. 30, 01277 Dresden, Phone +49 351 46925655, E-Mail: [email protected]."
2) Data Collection when Visiting Our Website
2.1 When using our website solely for informational purposes, that is, if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to the server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you accessed the page
- Used browser
- Used operating system
- Used IP address (if applicable: in anonymized form)
Processing is carried out in accordance with Article 6 (1) (f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. There is no sharing or other use of the data. However, we reserve the right to review server log files retrospectively should concrete evidence point to unlawful use.
2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party). You can recognize an encrypted connection by the string "https://" and the padlock symbol in your browser's address bar.
3) Hosting & Content Delivery Network
Cloudflare
We use a content delivery network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA
This service allows us to deliver large media files such as graphics, website content, or scripts more quickly over a network of regionally distributed servers. The processing is carried out to maintain our legitimate interest in improving the stability and functionality of our website according to Article 6 (1) (f) GDPR. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.
4) Cookies
To make your visit to our website attractive and to enable the use of certain functions, we use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device longer and allow the storage of site settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the cookie settings overview of your web browser.
If individual cookies we use also process personal data, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the event of granted consent, or in accordance with Art. 6 para. 1 lit. f GDPR for the protection of our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the site visit.
You can set your browser to be informed about the setting of cookies and to decide individually on their acceptance or to exclude the acceptance of cookies in specific cases or generally.
Please note that if cookies are not accepted, the functionality of our website may be limited.
5) Contacting Us
5.1 Own Review Reminder
Exclusively on the basis of your express consent in accordance with Art. 6 para. 1 lit. a GDPR, we use your email address for a one-time reminder to submit a review of your order. You can revoke your consent at any time by sending a message to the data processor responsible.
5.2 ShopVote
For review reminders, we use the services of the following provider: Blickreif GmbH, Schulstraße 46, 80634 Munich, Germany
Exclusively on the basis of your express consent in accordance with Art. 6 para. 1 lit. a GDPR, we transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder via email.
You can revoke your consent at any time for the future to us or the provider.
We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.
5.3 Trustpilot
For review reminders, we use the services of the following provider: Trustpilot A/S, Pilestræde 58, 1112 Copenhagen, Denmark
Exclusively on the basis of your express consent in accordance with Art. 6 para. 1 lit. a GDPR, we transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder via email.
You can revoke your consent at any time for the future to us or the provider.
We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.
5.4 Hubspot
To process customer inquiries, we use the email ticketing system of the following provider: HubSpot Ireland Ltd., 2nd Floor 30 North Wall Quay, Dublin 1, Ireland
If you submit contact inquiries via our website by email, these will be stored and organized in the ticketing system to allow for chronological processing and to improve the service experience. You can always check the current status of your inquiry using the individually assigned ticket number.
For organizing and processing inquiries, personal data is collected according to the extent of their provision, but at least name, first name, and email address are recorded, transmitted to the provider, stored there, and accessed.
The legal basis for the processing of this data is our legitimate interest in efficiently designing our customer service, providing the fastest possible response to your inquiry, and optimizing our service offerings in accordance with Art. 6 para. 1 lit. f GDPR.
We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.
5.5 In the context of contacting us (e.g., via contact form or email), personal data is processed – solely for the purpose of processing and responding to your inquiry and only to the extent necessary for that purpose.
The legal basis for the processing of this data is our legitimate interest in responding to your inquiry in accordance with Art. 6 para. 1 lit. f GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it can be concluded from the circumstances that the matter has been conclusively clarified and as long as no legal retention obligations conflict with this.
6) Comment Function
As part of the comment function on this website, in addition to your comment, information about the time of creation of the comment and the commentator name chosen by you will be stored and published on this website. Furthermore, your IP address will be logged and stored. This storage of the IP address is for security reasons and in case the affected person violates the rights of third parties or posts illegal content through a submitted comment. We need your email address to contact you in case a third party should contest your published content as illegal.
The legal basis for the storage of your data is Article 6(1)(b) and (f) of the GDPR. We reserve the right to delete comments if they are contested as illegal by third parties.
7) Use of Customer Data and Personal Customer Data
We use the data provided to us for:
- Personalization of advertising
- Analysis of user behavior on our websites and apps
- Personalized and non-personalized ads
- Mobile ad identifiers
- Direct advertising
- Order processing
- Online marketing
- Reviews
7a) Data Processing When Opening a Customer Account
According to Article 6(1)(b) of the GDPR, personal data will continue to be collected and processed to the extent necessary when you provide us with this information upon opening a customer account. What data is required for account creation can be found in the input mask of the corresponding form on our website.
Deleting your customer account is possible at any time and can be done by sending a message to the above-mentioned address of the responsible party. After the deletion of your customer account, your data will be deleted, provided that all contracts concluded in this regard have been fully settled, no legal retention periods oppose it, and we have no legitimate interest in further storage.
8) Use of Customer Data for Direct Advertising
8.1 Subscription to our E-Mail Newsletter
If you subscribe to our e-mail newsletter, we will regularly send you information about our offers. The only required information for sending the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. For the newsletter dispatch, we use the so-called double opt-in procedure, which ensures that you only receive newsletters after you have expressly confirmed your consent to receive the newsletter by activating a verification link sent to the provided email address.
By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Article 6(1)(a) of the GDPR. In this process, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of the subscription to trace any potential misuse of your email address at a later point. The data we collect during the newsletter registration is used strictly for the intended purpose.
You can unsubscribe from the newsletter at any time via the dedicated link in the newsletter or by sending a corresponding message to the responsible party mentioned above. After unsubscribing, your email address will be deleted from our newsletter distribution list immediately, as long as you haven’t expressly consented to further use of your data or we reserve the right to further use of your data that is legally permitted and of which we inform you in this declaration.
8.2 Sending the E-Mail Newsletter to Existing Customers
If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services, similar to those already purchased, from our range via email. For this, we do not need to obtain separate consent from you according to § 7 Abs. 3 UWG. The data processing is based solely on our legitimate interest in personalized direct advertising in accordance with Article 6(1)(f) of the GDPR. If you initially objected to the use of your email address for this purpose, no email will be sent by us.
You have the right to object to the use of your email address for the aforementioned advertising purpose at any time with effect for the future by sending a notice to the responsible party mentioned above. For this, you only incur transmission costs according to the basic rates. Upon receipt of your objection, the use of your email address for advertising purposes will be stopped immediately.
8.3 CleverReach
The sending of our email newsletters is handled by this provider: CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany
Based on our legitimate interest in effective and user-friendly newsletter marketing, we pass your data provided during the newsletter registration to this provider in accordance with Article 6(1)(f) of the GDPR so that they can carry out the newsletter sending on our behalf.
Subject to your express consent under Article 6(1)(a) of the GDPR, the provider also conducts a statistical evaluation of the success of newsletter campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the newsletter contents. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and evaluated, but not merged with other data sets.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have entered into a data processing agreement with the provider that protects our visitors' data and prohibits transfer to third parties.
8.4 Newstroll
The sending of our email newsletters is handled by this provider: Marco Ahrendt, Maustäle 18, 72793 Pfulingen, Germany
Based on our legitimate interest in effective and user-friendly newsletter marketing, we pass your data provided during the newsletter registration to this provider in accordance with Article 6(1)(f) of the GDPR so that they can carry out the newsletter shipping on our behalf.
Subject to your express consent under Article 6(1)(a) of the GDPR, the provider also conducts statistical evaluations of newsletter campaign success using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the content of the newsletters. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and evaluated, but not merged with other data sets.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have entered into a data processing agreement with the provider that protects our visitors' data and prohibits transfer to third parties.
8.5 OneSignal
On this website, you have the option to sign up for regular push notifications with information about our offer.
For this, we use the services of the following provider: OneSignal Inc., 2850 S Delaware St #201, San Mateo, CA 94403, USA
In the course of registration, through which you give your express consent to receive push notifications and the related processing in accordance with Article 6(1)(a) of the GDPR, the provider collects, stores, and uses your browser ID and device ID for the correct assignment and display of notifications.
Subject to your express consent under Article 6(1)(a) of the GDPR, the provider also conducts statistical evaluations of push integrations and interactions, with further information (e.g., time of access, IP address) being collected and evaluated, but not merged with other data sets.
You can revoke your consent to data processing for receiving push notifications and for statistical success measurement at any time with effect for the future by disabling the service in your browser settings or - depending on the operating system - by interacting with the respective push notification to unsubscribe from receiving.
We have entered into a data processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorized transfer to third parties.
For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on a decision of adequacy by the European Commission, ensures compliance with European data protection standards.
8.6 Advertising by Mail
Based on our legitimate interest in personalized direct advertising, we reserve the right to store your first and last name, your postal address, and - to the extent we have received these additional details from you in the context of the contractual relationship - your title, academic degree, year of birth, and your professional, industry, or business designation in accordance with Article 6(1)(f) of the GDPR and to use this for sending interesting offers and information about our products by mail.
You can object to the storage and use of your data for this purpose at any time.
You can set your browser to be informed about the setting of cookies and to decide individually on their acceptance or to exclude the acceptance of cookies for specific cases or in general.
Please note that if cookies are not accepted, the functionality of our website may be limited.
5) Contacting Us
5.1 Own Review Reminder
Exclusively based on your express consent in accordance with Article 6(1)(a) of the GDPR, we use your email address to remind you once to submit a review of your order. You can revoke your consent at any time by sending a message to the data processing responsible party.
5.2 ShopVote
For review reminders, we use the services of the following provider: Blickreif GmbH, Schulstraße 46, 80634 Munich, Germany
Exclusively based on your express consent in accordance with Article 6(1)(a) of the GDPR, we transmit your email address and possibly further customer data to the provider so that they can contact you with a review reminder via email.
You can revoke your consent at any time with effect for the future to us or to the provider.
We have entered into a data processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorized transfer to third parties.
5.3 Trustpilot
For review reminders, we use the services of the following provider: Trustpilot A/S, Pilestræde 58, 1112 Copenhagen, Denmark
Exclusively based on your express consent in accordance with Article 6(1)(a) of the GDPR, we transmit your email address and possibly further customer data to the provider so that they can contact you with a review reminder via email.
You can revoke your consent at any time with effect for the future to us or to the provider.
We have entered into a data processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorized transfer to third parties.
5.4 Hubspot
For processing customer inquiries, we use the email ticketing system of the following provider: HubSpot Ireland Ltd., 2nd Floor 30 North Wall Quay, Dublin 1, Ireland
If you submit contact inquiries via our website, these are stored and organized in the ticketing system to enable chronological processing and improve the service experience. You can always check the current status of your request using the assigned ticket number.
For the organization and processing of inquiries, personal data will be collected to the extent of its provision, at least name, first name, and email address, transmitted to the provider, stored there, and read out.
The legal basis for the processing of this data is our legitimate interest in efficiently shaping our customer service, answering your inquiries as quickly as possible, and optimizing our service offerings in accordance with Article 6(1)(f) of the GDPR.
We have entered into a data processing agreement with the provider that ensures the protection of our visitors' data and prohibits unauthorized transfer to third parties.
5.5 In the context of contacting us (e.g., via contact form or email), personal data will be processed exclusively for the purpose of processing and answering your request and only to the necessary extent.
The legal basis for the processing of this data is our legitimate interest in answering your request in accordance with Article 6(1)(f) of the GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Article 6(1)(b) of the GDPR. Your data will be deleted when it is clear from the circumstances that the affected matter has been conclusively clarified and as long as there are no legal retention obligations opposing it.
9) Data Processing for Order Processing
9.1 As far as necessary for the processing of the contract for delivery and payment purposes, the personal data collected by us will be passed on in accordance with Art. 6 para. 1 lit. b GDPR to the commissioned transport company and the commissioned credit institution.
Insofar as we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details (name, address, email address) provided by you during the order to inform you personally about upcoming updates within the legally prescribed period in accordance with our legal information obligations pursuant to Art. 6 para. 1 lit. c GDPR through suitable communication channels (for example by post or email). Your contact details will only be used for notifications about the updates we owe you, and will only be processed to the extent necessary for the respective information.
To process your order, we also cooperate with the following service provider(s) who partially or fully support us in carrying out closed contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.
9.2 Billbee
For order processing, we use the following provider: Billbee GmbH, Arolser Str. 10, 34477 Twistetal, Germany
Name, address, and possibly other personal data are passed on to the provider exclusively for the purpose of processing the online order in accordance with Art. 6 para. 1 lit. b GDPR. The transmission of your data takes place only to the extent that it is actually necessary for the processing of the order.
9.3 Disclosure of Personal Data to Shipping Service Providers
- Deutsche Post
As a transport service provider, we use the following provider: Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany
We pass on your email address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, we only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The disclosure takes place only to the extent that it is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.
The consent can be revoked at any time with effect for the future against the responsible party named above or against the provider.
- DHL
As a transport service provider, we use the following provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany
We pass on your email address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, we only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The disclosure takes place only to the extent that it is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.
The consent can be revoked at any time with effect for the future against the responsible party named above or against the provider.
- DHL Express
As a transport service provider, we use the following provider: DHL Express Germany GmbH, Heinrich-Brüning-Str. 5, 53113 Bonn, Germany
We pass on your email address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, we only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The disclosure takes place only to the extent that it is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.
The consent can be revoked at any time with effect for the future against the responsible party named above or against the provider.
- DPD
As a transport service provider, we use the following provider: DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany
We pass on your email address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, we only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The disclosure takes place only to the extent that it is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.
The consent can be revoked at any time with effect for the future against the responsible party named above or against the provider.
- UPS
As a transport service provider, we use the following provider: United Parcel Service Deutschland Inc. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany
We pass on your email address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, we only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The disclosure takes place only to the extent that it is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.
The consent can be revoked at any time with effect for the future against the responsible party named above or against the provider.
9.4 Use of Payment Service Providers
- Apple Pay
If you decide to use the payment method "Apple Pay" from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing will occur via the "Apple Pay" function of your device running iOS, watchOS, or macOS through the charge of a payment card stored with "Apple Pay." Apple Pay utilizes security features that are integrated into your device's hardware and software to protect your transactions. To authorize a payment, you are required to enter a code previously set by you and verify using the "Face ID" or "Touch ID" function of your device.
For payment processing, the information you provided during the ordering process, along with details about your order, will be forwarded to Apple in encrypted form. Apple subsequently encrypts this data again with a developer-specific key before the data is transmitted to the payment service provider of the payment card stored in Apple Pay. The encryption ensures that only the website through which the purchase was made can access the payment data. After the payment has been completed, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the payment success.
If personal data is processed in the described transmissions, processing will occur exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Apple retains anonymized transaction data, including the approximate purchase amount, approximate date and time, and an indication of whether the transaction was successfully completed. Anonymization completely excludes any personal reference. Apple uses the anonymized data to improve "Apple Pay" and other Apple products and services.
If you use Apple Pay on an iPhone or Apple Watch to complete a purchase made through Safari on a Mac, the Mac and the authorization device communicate over an encrypted channel on Apple's servers. Apple does not process or store any of this information in a format that can identify you. You can deactivate the ability to use Apple Pay on your Mac in your iPhone settings. Go to "Wallet & Apple Pay," and disable "Allow payments on Mac."
Further details on data protection regarding Apple Pay can be found at the following internet address: https://support.apple.com/de-de/HT203027
- bancontact
This website offers one or more online payment methods from the following provider: Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium
If you select a payment method from this provider where you pay in advance (e.g., credit card payment), your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be forwarded to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data occurs solely for the purpose of payment processing with the provider and only to the extent necessary for this.
- Billie GmbH
This website offers one or more online payment methods from the following provider: Billie GmbH, Charlottenstraße 4, 10969 Berlin, Germany
If you select a payment method from this provider where you pay in advance (e.g., credit card payment), your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be forwarded to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data occurs solely for the purpose of payment processing with the provider and only to the extent necessary for this.
If you select a payment method where the provider pays in advance (e.g., invoice or installment purchase or direct debit), you will also be asked to provide certain personal data (first name and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly information on an alternative payment method) during the ordering process.
To protect our legitimate interest in determining the creditworthiness of our customers, this data will be forwarded to the provider by us in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks based on the personal data you provided and other data (such as shopping cart, invoice amount, order history, payment experiences) whether the payment option you selected can be granted considering risks of default in payment and/or claims.
For the decision in the context of the application review, in addition to internal criteria from the provider pursuant to Art. 6 para. 1 lit. f GDPR, identity and creditworthiness information from the following credit agencies may also be included:
- Creditreform Berlin Wolfram KG, Karl-Heinrich-Ulrichs-Straße 1, 10787 Berlin, Germany
- Creditreform Boniversum GmbH, Hammfelddamm 13, 41460 Neuss, Germany
- SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, Germany
- Euler Hermes Deutschland, Friedensallee 254, 22763 Hamburg, Germany
The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data is taken into account in the calculation of score values, among others, but not exclusively.
You can object to this processing of your data at any time by sending a message to us or the provider. However, the provider may still be entitled to process your personal data if necessary for the contractual payment processing.
- Klarna
This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden
If you select a payment method from this provider where you pay in advance (e.g., credit card payment), your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be forwarded to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data occurs solely for the purpose of payment processing with the provider and only to the extent necessary for this.
If you select a payment method where the provider pays in advance (e.g., invoice or installment purchase or direct debit), you will also be asked to provide certain personal data (first name and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly information on an alternative payment method) during the ordering process.
To protect our legitimate interest in determining the creditworthiness of our customers, this data will be forwarded to the provider by us in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks based on the personal data you provided and other data (such as shopping cart, invoice amount, order history, payment experiences) whether the payment option you selected can be granted considering risks of default in payment and/or claims.
For the decision in the context of the application review, in addition to internal criteria from the provider pursuant to Art. 6 para. 1 lit. f GDPR, identity and creditworthiness information from the following credit agencies may also be included:
https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies
The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data is taken into account in the calculation of score values, among others, but not exclusively.
You can object to this processing of your data at any time by sending a message to us or the provider. However, the provider may still be entitled to process your personal data if necessary for the contractual payment processing.
- Mollie
This website offers one or more online payment methods from the following provider: Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands
If you select a payment method from this provider where you pay in advance (e.g., credit card payment), your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be forwarded to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data occurs solely for the purpose of payment processing with the provider and only to the extent necessary for this.
- Paypal
This website offers one or more online payment methods from the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
If you select a payment method from this provider where you pay in advance, your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be forwarded to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data occurs solely for the purpose of payment processing with the provider and only to the extent necessary for this.
If you select a payment method where we pay in advance, you will also be asked to provide certain personal data (first name and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly information on an alternative payment method) during the ordering process.
To protect our legitimate interest in determining your creditworthiness in such cases, this data will be forwarded to the provider by us in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks based on the personal data you provided and other data (such as shopping cart, invoice amount, order history, payment experiences) whether the payment option you selected can be granted considering risks of default in payment and/or claims.
The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data is taken into account in the calculation of score values, among others, but not exclusively.
You can object to this processing of your data at any time by sending a message to us or the provider. However, the provider may still be entitled to process your personal data if necessary for the contractual payment processing.
- SOFORT
This website offers one or more online payment methods from the following provider: SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany
If you select a payment method from this provider where you pay in advance (e.g., credit card payment), your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be forwarded to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data occurs solely for the purpose of payment processing with the provider and only to the extent necessary for this.
- TWINT
This website offers one or more online payment methods from the following provider: TWINT AG (Stauffacherstrasse 31, CH-8004 Zurich, Switzerland)
If you select a payment method from this provider where you pay in advance (e.g., credit card payment), your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be forwarded to them in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data occurs solely for the purpose of payment processing with the provider and only to the extent necessary for this.
For the transfer of data to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
9.5 We reserve the right to transfer your data to the collection service provider Creditreform Dresden, Augsburger Straße 4, 01309 Dresden, Tel +49 (0) 351 - 4444 - 444, as long as our payment claim has not been settled despite prior reminders. In this case, the claim will be collected directly by the collection service provider.
The transfer of your data serves to fulfill the contract in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR as well as to safeguard our predominantly legitimate interests in an effective assertion or enforcement of our payment claims in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
10) Online-Marketing
Google AdSense
This website uses Google AdSense, a web advertising service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google AdSense uses so-called cookies, which are text files stored on your computer that allow an analysis of your use of the website. Furthermore, Google AdSense also uses so-called "web beacons" (small invisible graphics) to collect information, enabling the recording, collection, and evaluation of simple actions, such as visitor traffic on the website. The information generated by the cookie and/or web beacon (including your IP address) about your use of this website is usually transmitted to a Google server and stored there. This may also involve transmission to the servers of Google LLC in the USA.
Google uses the information obtained to evaluate your usage behavior concerning the AdSense ads. The IP address transmitted by your browser in connection with Google AdSense is not merged with other data from Google. The information collected by Google may be transferred to third parties if required by law and/or to the extent that third parties process these data on behalf of Google.
All processes described above, especially reading information on the device used via cookies and/or web beacons, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of Google AdSense will not occur during your visit to the site.
You can withdraw your consent at any time with future effect by deactivating this service in the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
Google's privacy policy can be viewed here: https://www.google.de/policies/privacy/ and more information about how Google uses personal data can be found here: https://business.safety.google/privacy/
11) Web Analytics Services
11.1 Google Analytics 4
This website uses Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which allows an analysis of your usage of our website.
By default, when visiting the website, Google Analytics 4 sets cookies, which are small text fragments stored on your device that collect certain information. This information also includes your IP address, which is shortened by Google to exclude direct personal reference.
The information is transmitted to Google servers and processed there. Transfers to Google LLC based in the USA are also possible.
Google uses the collected information on our behalf to evaluate your use of the website, compile reports about website activities for us, and provide further services related to website use and internet usage. The shortened IP address transmitted by your browser in connection with Google Analytics is not merged with other data from Google. The data collected during the use of Google Analytics 4 is stored for a period of two months and then deleted.
All processes described above, especially setting cookies on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
Without your consent, the use of Google Analytics 4 will not occur during your visit to the site. You can withdraw your consent at any time with future effect. To exercise your revocation right, please deactivate this service via the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with Google that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.
Further legal information on Google Analytics 4 can be found at https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites
Demographic Features
Google Analytics 4 uses the special feature "demographic features" and can create statistics that make statements about the age, gender, and interests of site visitors. This is done by analyzing advertisements and information from third parties. This allows for the identification of target groups for marketing activities. However, the collected data cannot be attributed to any specific person and will be deleted after being stored for a period of two months.
Google Signals
As an extension to Google Analytics 4, Google Signals can be used on this website to create cross-device reports. If you have activated personalized ads and linked your devices to your Google account, Google may, subject to your consent for the use of Google Analytics in accordance with Art. 6 para. 1 lit. a GDPR, analyze your usage behavior across devices and create database models, including for cross-device conversions. We do not receive any personal data from Google, only statistics. If you wish to stop the cross-device analysis, you can deactivate the "Personalized Advertising" feature in the settings of your Google account. To do this, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de More information about Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de
UserIDs
As an extension to Google Analytics 4, the "UserIDs" feature can be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Art. 6 para. 1 lit. a GDPR, set up an account on this website, and log in with this account on various devices, your activities, including conversions, can be analyzed across devices.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
11.2 Google Tag Manager
This website uses the "Google Tag Manager," a service of the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").
The Google Tag Manager provides a technical basis for consolidating various web applications, including tracking and analytics services, and calibrating, controlling, and tying them to conditions through a unified user interface. The Google Tag Manager itself does not store information on user devices or read it out. The service also does not conduct independent data analyses. However, when accessing the page, your IP address is transmitted to Google via the Google Tag Manager and may be stored there. A transmission to Google LLC servers in the USA is also possible.
This processing will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of Google Tag Manager will not occur during your visit to the site. You can withdraw your consent at any time with future effect. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
Further legal information on Google Tag Manager can be found at https://policies.google.com/privacy?hl=de&gl=de
12) Retargeting/ Remarketing and Conversion Tracking
12.1 Criteo
This website uses retargeting technology from the following provider: Criteo SA, 32 Rue Blanche, 75009 Paris, France
This allows us to target visitors to our websites with personalized, interest-based advertising who have already shown interest in our shop and products. The display of the advertising materials occurs based on a cookie-based analysis of past and current usage behavior, but no personal data is stored. In cases using retargeting technology, a cookie is stored on your computer or mobile device to collect pseudonymized data about your interests and to tailor the advertising to the stored information. These cookies are small text files stored on your computer or mobile device. You will see advertising that is likely to match your product and information interests.
All the processing described above, particularly the setting of cookies for reading information on the used device, is only carried out if you have expressly consented in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology will not occur during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie-Consent-Tool" provided on the website.
12.2 Google Ads Remarketing
This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
For this purpose, Google sets a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID based on the pages you have visited. Further data processing only takes place if you have agreed with Google that your Internet and app browsing history will be linked to your Google account and that information from your Google account will be used to personalize advertisements you view on the web. If you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. In this context, your personal data may be temporarily linked by Google with Google Analytics data to form audiences. Using Google Ads Remarketing might also entail the transfer of personal data to the servers of Google LLC in the USA.
All the processing described above, particularly the setting of cookies for reading information on the used device, is only carried out if you have expressly consented in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology will not occur during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie-Consent-Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
Details about the processes initiated by Google and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites
Google's privacy policy can be viewed here: https://www.google.de/policies/privacy/
12.3 Microsoft Advertising
This website uses retargeting technology from the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
This allows us to target visitors to our websites with personalized, interest-based advertising who have already shown interest in our shop and products. The display of the advertising materials occurs based on a cookie-based analysis of past and current usage behavior, but no personal data is stored. In cases using retargeting technology, a cookie is stored on your computer or mobile device to collect pseudonymized data about your interests and to tailor the advertising to the stored information. These cookies are small text files stored on your computer or mobile device. You will see advertising that is likely to match your product and information interests.
All the processing described above, particularly the setting of cookies for reading information on the used device, is only carried out if you have expressly consented in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology will not occur during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie-Consent-Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
12.4 Google Ads Conversion Tracking
This website uses the online advertising program "Google Ads" and within Google Ads the conversion tracking of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). We use the Google Ads offering to draw attention to our attractive offers on external websites using advertising materials (so-called Google AdWords). We can determine how successful the individual advertising measures are based on the data from the advertising campaigns. We aim to display advertisements that are of interest to you, make our website more interesting for you, and achieve a fair calculation of the incurred advertising costs.
The conversion tracking cookie is set when a user clicks on an ad displayed by Google. Cookies are small text files that are stored on your device. These cookies generally expire after 30 days and do not serve for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was forwarded to this page. Each Google Ads customer receives a different cookie. Therefore, cookies cannot be tracked across the websites of Google Ads customers. The information collected through conversion cookies is used to create conversion statistics for Google Ads customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were forwarded to a page marked with a conversion tracking tag. However, they do not receive information that can be used to personally identify users. In the context of using Google Ads, there may also be a transfer of personal data to the servers of Google LLC in the USA.
Details about the processes initiated by Google Ads Conversion Tracking and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites
All the processing described above, particularly the setting of cookies for reading information on the used device, is only carried out if you have expressly consented in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie-Consent-Tool" provided on the website.
You can also permanently object to the setting of cookies through Google Ads Conversion Tracking by downloading and installing the browser plug-in from Google available at the following link:
https://www.google.com/settings/ads/plugin?hl=de
Please note that certain functions of this website may not be available or may be limited if you have disabled the use of cookies.
Google's privacy policy can be viewed here: https://www.google.de/policies/privacy/
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
12.5 Google Marketing Platform
This website uses the online marketing tool Google Marketing Platform operated by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("GMP").
GMP uses cookies to serve relevant ads to users, improve campaign performance reports, or prevent a user from seeing the same ads multiple times. Google collects which ads are served in which browser through a cookie ID and can thereby prevent them from being displayed multiple times. Furthermore, GMP can collect so-called conversions related to ad requests using cookie IDs. This happens, for example, when a user sees a GMP ad and later visits the advertiser's website using the same browser and makes a purchase through that website. According to Google, GMP cookies do not contain personal information.
Due to the marketing tools used, your browser automatically establishes a direct connection with Google’s server.
We have no influence over the scope and further use of the data collected by Google through the use of this tool and therefore inform you according to our current knowledge as follows: By integrating GMP, Google receives the information that you have accessed the relevant part of our online presence or clicked on an ad from us. If you are registered with a Google service, Google may assign the visit to your account. Even if you are not registered with Google or are not logged in, there is a possibility that the provider could learn and store your IP address. In the context of using GMP, there may also be a transfer of personal data to the servers of Google LLC in the USA.
All the processing described above, particularly the setting of cookies for reading information on the used device, is only carried out if you have expressly consented in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie-Consent-Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
The privacy policy of GMP by Google can be found here: https://www.google.de/policies/privacy/
12.6 Microsoft Advertising Universal Event Tracking
This website uses conversion tracking technology from the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
For the use of Universal Event Tracking, a tag is placed on each page of our website that interacts with the conversion cookie set by Microsoft. This interaction makes user behavior on our website traceable and sends the information collected to Microsoft. The purpose of this is to statistically capture and evaluate certain predefined goals such as purchases or leads in order to make the orientation and content of our offerings more relevant to interests. The tags are never used for the personal identification of users.
All the processing described above, particularly the setting of cookies for reading information on the used device, is only carried out if you have expressly consented in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology will not occur during your visit to the site.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie-Consent-Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision by the European Commission.
13) Page Functionalities
13.1 ShopVote Graphics
On our website, graphic elements from the following provider are integrated to display external customer reviews and/or an externally awarded quality seal: Blickreif GmbH, Schulstraße 46, 80634 Munich, Germany
When you access a page of our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to properly load the elements. In this process, certain browser information, including your IP address, is transmitted to the provider.
Insofar as personal data is also processed, this is done in accordance with Article 6(1)(f) GDPR based on our legitimate interest in the optimal marketing of our offerings and the appealing design of our online presence.
13.2 TrustPilot
On our website, graphic elements from the following provider are integrated to display external customer reviews and/or an externally awarded quality seal: Trustpilot A/S, Pilestræde 58, 1112 Copenhagen, Denmark
When you access a page of our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to properly load the elements. In this process, certain browser information, including your IP address, is transmitted to the provider.
Insofar as personal data is also processed, this is done in accordance with Article 6(1)(f) GDPR based on our legitimate interest in the optimal marketing of our offerings and the appealing design of our online presence.
13.3 Cloudflare Turnstile
On this website, we use the CAPTCHA service from the following provider: Cloudflare, Inc., 101 Townsend St. San Francisco, CA 94107, USA
The service checks whether an input is made by a natural person or abusively by machine and automated processing, and blocks spam, DDoS attacks, and similar automated malicious accesses. To ensure that an action is taken by a human and not by an automated bot, Cloudflare Turnstile collects the IP address of the device used, recognition data of the browser and operating system type used, as well as the date and duration of the visit, and transmits this for evaluation to the provider's servers.
The legal basis is our legitimate interest in determining individual accountability on the Internet and preventing abuse and spam in accordance with Article 6(1)(f) GDPR.
We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.
13.4 Google Customer Reviews (formerly Google Certified Shops Program)
We collaborate with Google under the program "Google Customer Reviews". The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). This program allows us to request customer reviews from users of our website. After a purchase on our website, you will be asked if you want to participate in an email survey from Google.
If you give your consent in accordance with Article 6(1)(a) GDPR, we transmit your email address to Google. You will receive an email from Google Customer Reviews asking you to rate your purchase experience on our website. The rating you provide will then be aggregated with our other ratings and displayed in our logo for Google Customer Reviews as well as in our Merchant Center dashboard. Additionally, your rating will be used for Google Seller Ratings. As part of using Google Customer Reviews, there may also be a transfer of personal data to the servers of Google LLC in the USA.
You can revoke your consent at any time by sending a message to the data processing officer or to Google.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European data protection level.
13.5 Applications for Job Openings via Email
On our website, we currently advertise vacant positions in a separate section, where interested parties can apply via email to the provided contact address.
Applicants must provide all personal data necessary for an informed assessment, including general information such as name, address, and contact options, as well as performance-related evidence and, if applicable, health-related information. Details regarding the application can be found in the job advertisement.
Upon receipt of the application by email, the data will be stored and evaluated solely for the purpose of processing the application. For follow-up questions, we use either the email address or phone number of the applicant. The processing is based on Article 6(1)(b) GDPR (or § 26(1) BDSG), under which the application process is considered the initiation of an employment contract.
In the context of the application process, if special categories of personal data within the meaning of Article 9(1) GDPR (e.g., health data such as information about disability status) are requested from applicants, the processing is done in accordance with Article 9(2)(b) GDPR, so that we can exercise the rights arising from labor law and social security and social protection law and meet our corresponding obligations.
Collectively or alternatively, the processing of the special categories of data can also be based on Article 9(1)(h) GDPR if it is for the purposes of health care or occupational medicine, for assessing the applicant's fitness for work, for medical diagnostics, care or treatment in the health or social field, or for managing systems and services in the health or social field.
If an applicant is not selected or withdraws their application early, the transmitted data as well as all electronic correspondence including the application email will be deleted after a corresponding notification, no later than 6 months afterwards. This period is based on our legitimate interest in answering any follow-up questions regarding the application and, if necessary, fulfilling our documentation obligations under regulations regarding equality of treatment of applicants.
In the event of a successful application, the provided data will be processed based on Article 6(1)(b) GDPR (for processing in Germany in conjunction with § 26(1) BDSG) for the purpose of executing the employment relationship.
13.6 Online Applications via a Form
On our website, we currently advertise vacant positions in a separate section, where interested parties can apply through a corresponding form.
Applicants must provide all personal data necessary for an informed assessment, including general information such as name, address, and contact options, as well as performance-related evidence and, if applicable, health-related information. Details regarding the application can be found in the job advertisement.
Upon submission of the form, the applicant data will be transmitted to us encrypted according to the state of the art, stored by us, and evaluated solely for the purpose of processing the application. The processing is based on Article 6(1)(b) GDPR (or § 26(1) BDSG), under which the application process is considered the initiation of an employment contract.
In the context of the application process, if special categories of personal data within the meaning of Article 9(1) GDPR (e.g., health data such as information about disability status) are requested from applicants, the processing is done in accordance with Article 9(2)(b) GDPR, so that we can exercise the rights arising from labor law and social security and social protection law and meet our corresponding obligations.
Collectively or alternatively, the processing of the special categories of data can also be based on Article 9(1)(h) GDPR if it is for the purposes of health care or occupational medicine, for assessing the applicant's fitness for work, for medical diagnostics, care or treatment in the health or social field, or for managing systems and services in the health or social field.
If an applicant is not selected or withdraws their application early, the transmitted data from the form as well as all electronic correspondence including the application email will be deleted after a corresponding notification, no later than 6 months afterwards. This period is based on our legitimate interest in answering any follow-up questions regarding the application and, if necessary, fulfilling our documentation obligations under regulations regarding equality of treatment of applicants.
In the event of a successful application, the provided data will be processed based on Article 6(1)(b) GDPR (for processing in Germany in conjunction with § 26(1) BDSG) for the purpose of executing the employment relationship.
14) Tools and Others
14.1 - DATEV
For the completion of accounting, we use the service of the cloud-based accounting software from the following provider: DATEV eG, Paumgartnerstr. 6-14, 90429 Nuremberg, Germany
The provider processes incoming and outgoing invoices as well as any bank movements of our company, in order to automatically capture invoices, match them to transactions, and create financial accounting in a semi-automated process.
If personal data is also processed in this context, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in efficient organization and documentation of our business processes.
14.2 Cookie Consent Tool
This website uses a so-called "Cookie Consent Tool" to obtain effective user consents for consent-required cookies and cookie-based applications. The "Cookie Consent Tool" is displayed to users upon page access in the form of an interactive user interface, where consents for certain cookies and/or cookie-based applications can be granted by checking boxes. By using the tool, all consent-required cookies/services are only loaded if the respective user gives the appropriate consents by checking boxes. This ensures that such cookies are only set on the user's device in the event of consent being granted.
The tool sets technically necessary cookies to store your cookie preferences. Personal user data is generally not processed in this context.
If it becomes necessary in individual cases to store, allocate, or log cookie settings, and this involves the processing of personal data (such as the IP address), it is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a legally compliant, user-specific, and user-friendly consent management for cookies, and thus in a legally compliant design of our online presence.
Another legal basis for processing is also Art. 6 para. 1 lit. c GDPR. As controllers, we are legally obligated to make the use of technically unnecessary cookies dependent on the respective user consent.
If necessary, we have concluded a data processing agreement with the provider that ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.
Further information about the operator and the settings options of the Cookie Consent Tool can be found directly in the corresponding user interface on our website.
14.3 Doofinder
This website uses the search technology service of the following provider: DooFinder S.L., Madrid 28037, Rufino González 23 bis, 1º 1, Spain
For providing the search function for articles via the search field and for navigation and filtering, the provider collects and stores certain user information (such as the user or session ID) in anonymized form.
If personal data is also processed in this context, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in providing a fault-tolerant search for articles and thus in optimal marketing of our offerings.
15) Rights of the Data Subject
15.1 The applicable data protection law grants you the following rights against the controller regarding the processing of your personal data (rights to information and intervention), with reference made to the stated legal basis for each exercise requirement:
- Right to information according to Art. 15 GDPR;
- Right to rectification according to Art. 16 GDPR;
- Right to deletion according to Art. 17 GDPR;
- Right to restriction of processing according to Art. 18 GDPR;
- Right to notification according to Art. 19 GDPR;
- Right to data portability according to Art. 20 GDPR;
- Right to withdraw consent given according to Art. 7 para. 3 GDPR;
- Right to lodge a complaint according to Art. 77 GDPR.
15.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA BASED ON A BALANCE OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, FOR REASONS RELATING TO YOUR PARTICULAR SITUATION, TO THIS PROCESSING WITH FUTURE EFFECT.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE PERSONAL DATA CONCERNED. HOWEVER, FURTHER PROCESSING MAY BE RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
IF WE PROCESS YOUR PERSONAL DATA FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA CONCERNING SUCH MARKETING. YOU CAN EXERCISE THE OPT-OUT AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE PERSONAL DATA CONCERNED FOR DIRECT MARKETING PURPOSES.
16) Duration of Storage of Personal Data
The duration of storage of personal data is determined based on the respective legal basis, the processing purpose, and—if applicable—additionally based on the respective statutory retention period (e.g., commercial and tax law retention periods).
When processing personal data on the basis of explicit consent according to Art. 6 para. 1 lit. a GDPR, the affected data will be stored until you withdraw your consent.
If there are statutory retention periods for data processed in the context of contractual or contract-like obligations based on Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the end of the retention periods, provided they are no longer necessary for the fulfillment of the contract or for the initiation of a contract and/or we have no legitimate interest in further storage.
When processing personal data on the basis of Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object according to Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
When processing personal data for the purposes of direct marketing on the basis of Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object according to Art. 21 para. 2 GDPR.
Unless otherwise stated from the other information in this statement regarding specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.