1. Data Controller
This website and the range of services, as well as our social media profiles are operated by:
Bevenroder Strasse 149
Tel.: +49 (0)531 214 929 11
2. General Information
We have designed the development of the website to collect as little data as possible from you. In principle, you can visit our website without providing personal data. The processing of personal data is required only when you decide to take advantage of certain services (e.g., ordering goods in the online shop or using the contact form). In doing so, we always ensure to process your personal data only in accordance with a legal basis or your consent. We comply with the provisions of the General Data Protection Regulation (GDPR), which has been in effect since May 25, 2018, and the respective applicable national regulations, such as the German Federal Data Protection Act, the German Telemedia Act, or other more specific data protection laws.
3. Purpose and Legal Basis of the Processing of Personal Data
We always process your personal data for a specific purpose.
In short, we process your personal data for the following purposes:
|a) To be able to process your request in case of contact inquiries (e.g., email address, first name, last name);|
|b) For the technical implementation of our website and to be able to provide you with our information on this website (e.g., IP address, cookies, browser information);|
The specific purposes are described for the processing presented herein (e.g., contact form, web analysis, order process, etc.).
The following applies with regard to the legal basis for the processing of your personal data:
Personal data that is required for the establishment, implementation or processing of our services (contract execution) on the legal basis of Art. 6 para. 1 (b) of the GDPR. Insofar as we obtain your consent for the processing of your personal data, the consent shall form the legal basis for data processing pursuant to Art. 6 para. 1 (a) of the GDPR. Data processing is also permissible if we process your data to safeguard our legitimate interests and your interests or fundamental rights and freedoms with regard to the processing of personal data do not prevail. Insofar as we use external service providers in the context of the commissioned data processing, the processing shall take place on the legal basis of Art. 28 of the GDPR.
4. Collected and Processed Personal Data
When you visit our website, we collect and process some of your personal data. On the one hand, you can see which data is actually processed by the data you have to provide when filling out forms on the website (e.g., contact form or order form), and on the other hand, we inform you about the data processed for the processing procedures described herein.
In short, we collect and process the following data about you through our website:
General contact information:
- First and last name
- Email address
- Content of the message/comment
5. Collection of Personal Data When You Visit Our Website
If you use the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we will only collect personal data that your browser transmits to our server. If you wish to view our website, we will collect the following data, which is technically necessary for us to display our website to you and to endure its stability and security (legal basis is Art. 6 para. 1 sentence 1 (f) of the GDPR):
- IP address
- date and time of request
- time zone difference from Greenwich Mean Time (GMT)
- content of the request (specific page)
- access status/HTTP status code
- amount of data transferred in each case
- website making the request
- operating system and its interface
- language and version of browser software.
6. Integration of Third-Party Services
Our website uses contents and services of other providers. These are, for example, statistical analysis services for using and visiting our website, or for integrating videos from video platforms such as YouTube. In order for these data to be accessed and displayed in the user’s browser, the user’s IP address must be transmitted to this third-party provider.
On our website, information is collected and stored by using the so-called browser cookies. Cookies are small text files that are stored on your data carrier and that store certain settings and data for exchange with our system via your browser. A cookie usually contains the name of the domain, from which the cookie data was sent, as well as information about the age of the cookie and an alphanumeric identifier.
Cookies allow our systems to recognize the user’s device and to make any presets available immediately. As soon as a user accesses the platform, a cookie is transmitted to the hard disk of the user’s computer. Cookies help us improve our website and offer you a better and more personalized service. They allow us to recognize your computer or your (mobile) end device when you return to our website and thereby:
- Save information about your preferred activities on the website and thus tailor our website to your individual interests.
- Speed up the processing of your requests.
We work with third-party services that help us make the website more interesting for you. Therefore, cookies from these partner companies (third-party providers) will also be stored on your hard drive when you visit the website. These are cookies that are automatically deleted after a predefined period of time.
A list of cookies we set can be found in the following table:
|_ga||Used to distinguish users.|
|_gid||Used to distinguish users.|
|_gat||Used to throttle request rate.|
|cookieAccepted||Used to store whether the cookie hint was read.|
|ga-disable-UA-49390138-7||Used for Google Analytics tracking Opt-Out|
If you do not wish to use browser cookies, you can set your browser so that the storage of cookies is not accepted. Please note that in this case you may only be able to use our website to a limited extent or may not be able to use it at all. If you only wish to accept our own cookies but not those of our service providers and partners, you may choose to “Block third-party cookies” in your browser’s settings. We assume no responsibility for the use of third-party cookies.
The integration of cookies is based on the legal basis of Art. 6 para. 1 (f) of the GDPR, insofar as it concerns the so-called functional cookies that are mandatory for the operation of the website, and on the other hand, on the legal basis of Art. 6 para. 1 (a) of the GDPR, or your consent, for cookies that are used to evaluate user behavior and manage statistics. The legitimate interest within the meaning of Art. 6 para. 1 (f) of the GDPR results from the purposes mentioned in Section 3 b) above.
8. Contact (Contact Forms, etc.)
You can contact us by email or by using our contact form. In this case, we will store the personal data you provide to process your request and to contact you to process your request. If we request information via our contact form, the mandatory fields will be marked accordingly (in bold). The optional information helps us ensure the concretization and the improved processing of your request. The data requested is transmitted to us by you on a purely voluntary basis.
Depending on the nature of the request, the legal basis for such processing is Art. 6 para. 1 (b) of the GDPR for requests that you submit yourself as part of a pre-contractual measure, or Art. 6 para. 1 sentence 1 (f) of the GDPR if your request is of a different nature. The legitimate interest results from the purposes stated under Section 3 a). Should personal data be requested, which we do not need for the fulfillment of a contract or for the protection of legitimate interests, the transmission of data to us is based on consent given by you pursuant to Art. 6 para. 1 (a) of the GDPR.
9. Google Analytics
Our website uses Google Analytics, a web analysis service. The provider of the web analysis service is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States.
Google Analytics uses “cookies.” These are small text files that your web browser stores on your device. They enable an analysis of website usage. The information generated by cookies about your use of our website is transmitted to a Google server and stored there. The server is usually located in the United States.
Google Analytics cookies are set on the basis of Art. 6 para. 1 (f) of the GDPR. As the operator of this website, we have a legitimate interest in analyzing user behavior in order to optimize our website and, where applicable, our advertising.
We use Google Analytics in conjunction with IP anonymization. It ensures that Google shortens your IP address within the Member States of the European Union or in other State Parties to the Agreement on the European Economic Area prior to transmission to the United States. There may be exceptional cases in which Google transmits the full IP address to a server in the United States and shortens it there. Google will use this information on our behalf to evaluate your use of the website, create reports on website activity, and provide us with other services relating to website and Internet use. The IP address transmitted by Google Analytics will not be combined with any other data held by Google.
You can opt out from the setting of cookies by your web browser. However, some functions of our website may be limited as a result. You can also opt out from the collection of data about your use of the website, including your IP address, and subsequent processing by Google. You can do this by downloading and installing the browser plugin accessible via the following link: https://tools.google.com/dlpage/gaoptout?hl=en
To fully comply with the legal data protection requirements, we have concluded a commissioned processing agreement with Google.
Alternatively, you can prevent data collection from Google Analytics by setting an opt-out cookie by clicking Disable Google Analytics. If you delete the cookies in your browser, you will need to click this link again.
10. Google AdWords and Google Conversion Tracking
Our website uses Google AdWords. It is provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States.
AdWords is an online advertising program. As part of the online advertising program, we work with conversion tracking. After you click on an ad placed by Google, a cookie will be set for conversion tracking. Cookies are small text files that your web browser stores on your device. Google AdWords cookies expire after 30 days and are not used for personal identification of the users. The cookie lets Google and us recognize that you clicked on an ad and were redirected to our website. Conversion cookies are stored on the basis of Art. 6 para. 1 (f) of the GDPR. As the website operator, we have a legitimate interest in analyzing user behavior in order to optimize our website and our advertising.
Each Google AdWords customer receives a different cookie. Cookies cannot be tracked through AdWords customer websites. Conversion cookies are used to generate conversion statistics for AdWords customers who use conversion tracking. AdWords customers can see how many users clicked on their ad and were redirected to the pages with a conversion tracking tag. However, AdWords customers do not receive any information that enables personal identification of the users. If you do not wish to participate in tracking, you can opt out from it. To do this, you need to disable conversion cookies in the browser’s user settings. In addition, you will not be included in the conversion tracking statistics.
With a modern web browser, you can monitor, restrict, or stop the setting of cookies. Disabling cookies may limit the functionality of our website.
11. Google AdWords/Remarketing
12. Google Tag Manager
This website uses Google Tag Manager. Google Tag Manager is a solution that enables marketers to manage site tags via an interface. The tool itself (which implements the tags) is a cookie-less domain and does not collect personally identifiable information. The tool triggers other tags which may, in turn, collect data. Google Tag Manager does not access this data. If disabled at the domain or cookie level, it remains in effect for all tracking tags implemented via Google Tag Manager.
13. Amazon Associates Program
for further information on data processing through Amazon.
14. The Use of YouTube
For video content integration and display, on our website we use YouTube plugins, an entity operated by Google. The provider of the video portal is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.
When you access a page where the YouTube plugin is embedded, a connection to the YouTube servers is created. This way, YouTube knows which of our pages you have visited.
If you are logged in to your YouTube account, YouTube can associate your browsing history directly to your personal profile. You can prevent this by logging out beforehand.
We use YouTube in the interest of displaying our online offer in an appealing way. This constitutes a legitimate interest as defined by Art. 6 par. 1 subparagraph f of the GDPR.
15. Social Media Buttons
We display social media buttons (Facebook, Instagram, Twitter, LinkedIn, etc.) on our website in the form of a static link to our social media pages on the corresponding platforms. These do not represent a direct integration of the respective providers.
16. Social Media Profiles
We use various social media profiles to provide information on the respective social media platforms and to be able to contact you. Please note that cookies may be stored in your browser by the respective platform operator, in which your user behavior will be stored for market research and advertising purposes. These user profiles can also be created across devices. The platform operators evaluate these user profiles to display personalized advertising for you. Data processing may also affect persons who are not registered as users on the respective social media platform.
We receive information about visits to our social media profile from the platform operator. This may also include personal data. The processing of your personal data when you visit one of our social media profiles is based on our legitimate interests in a diverse external appearance of our company and the use of effective methods of information and communication with you. The legal basis for this is Art. 6 para. 1 (f) of the GDPR. If you have given your consent to data processing to a platform operator, Art. 6 para. 1 (a) of the GDPR shall be the legal basis.
Further information about data processing on social media platforms and opting out can be found here:
Provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States
Provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, United States
Provider: LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland
Provider: Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, United States
17. Rights of the Data Subject
You have the right:
- to request information about your personal data processed by us pursuant to Art. 15 of the GDPR. In particular, you can request information about the purposes of data processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of the right to correction, deletion, restriction of processing, or objection, the existence of the right of appeal, the source of your data if not collected by us, as well as the existence of automated decision-making including profiling and any other meaningful detailed information about the data;
- to request the rectification of incorrect or completion of personal data stored by us immediately pursuant to Art. 16 of the GDPR;
- to request the erasure of your personal data stored by us unless the processing is required for exercising the right to freedom of expression and information, for fulfilling a legal obligation, for reasons of public interest, or for the assertion, exercise or defense of legal claims pursuant to Art. 17 of the GDPR;
- to request the restriction of the processing of your personal data pursuant to Art. 18 of the GDPR if the accuracy of the data is disputed by you, the processing is unlawful, but you refuse to have it erased and we no longer need the data, but you need it to assert, exercise or defend legal claims, or you have filed an objection to the processing in accordance with Art. 21 of the GDPR;
- to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request its transmission to another controller pursuant to Art. 20 of the GDPR (data portability);
- to revoke your consent provided to us at any time pursuant to Art. 7 para. 3 of the GDPR. As a result, we will no longer be able to continue the processing of data based on this consent with effect for the future; and
- to appeal to a supervisory authority pursuant to Art. 77 of the GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or work, or our company headquarters.
- Right to object
If your personal data is processed on the basis of legitimate interests in accordance with Art. 6 para. 1 sentence 1 (f) of the GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 of the GDPR provided that there are reasons for this arising from your particular situation or the objection is directed against direct mail advertising. In the latter case, you have a general right to object, which we will implement without specifying a particular situation.
If you wish to exercise your right to revoke your consent or object, please send an email to firstname.lastname@example.org
18. Transfer of Your Personal Data
Your personal data is transferred as described below.
The website is hosted by an external service provider in Germany. In doing so, we ensure that data processing takes place in Germany alone. This is necessary for the operation of the website, as well as for the establishment, implementation and execution of the existing user contract, and is also possible without your consent.
In addition, data is also transferred if we are entitled or obliged to transfer data due to statutory provisions and/or official or judicial orders. In particular, this may include the provision of information for law enforcement and security purposes, or for the enforcement of intellectual property rights.
Insofar as your data is transferred to service providers to the required extent, they will only have access to your personal data to the extent necessary to fulfill their obligations. These service providers are obliged to process your personal data in accordance with the applicable data protection laws, in particular the GDPR. As far as the so-called commissioned processing is concerned, we have concluded commissioned processing contracts with the service provider in accordance with Art. 28 of the GDPR.
We will not transmit your data to third parties without your consent beyond the aforementioned circumstances. In particular, we do not transfer personally identifiable information to any place in a third country or an international organization.
19. Data Security
Unfortunately, the transmission of information over the Internet is never 100% secure, which is why we cannot guarantee the security of data transmitted to our website over the Internet.
However, we use technical and organizational measures to secure our website against loss, destruction, access, modification, or dissemination of your data by unauthorized persons.
In particular, your personal data is transmitted in encrypted form. In doing so, we use the SSL/TLS (Secure Sockets Layer/Transport Layer Security) coding system. Our security measures are continuously improved in line with the technological developments.
20. Duration of Storage of Personal Data
With regard to the storage duration, we delete personal data as soon as its storage is no longer necessary for the fulfillment of the original purpose and there are no longer any statutory retention periods. The statutory retention periods ultimately form the criterion for the final duration of the storage of personal data. The corresponding data is routinely deleted after the period has expired. If there are any retention periods, the processing is restricted by blocking the data.
21. References and Links
Third-party service providers may have different and specific provisions with regard to the collection, processing, and use of personal data. We therefore recommend that you learn about the practice for the handling of personal data before entering your personal data on the websites of third parties.
23. Data Protection Officer
We have appointed a data protection officer.