Data protection

Unless otherwise stated below, the provision of your personal data is neither required by law nor contractually, nor is it necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide it has no consequences. This only applies if no other information is provided during subsequent processing operations.

“Personal data” means any information relating to an identified or identifiable natural person.

Server log files

You can visit our websites without providing any personal information.
Every time you access our website, usage data is transmitted to us or our web host/IT service provider through your Internet browser and stored in log data (so-called server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the IP address, the amount of data transferred and the requesting provider.
The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR out of our overriding legitimate interest in ensuring trouble-free operation of our website and in improving our offering.

Your data will be transmitted to Canada, among other places. There is an adequacy decision from the EU Commission for data transfers to Canada.


Contact

Responsible person
Contact us if you wish. The person responsible for data processing is: buah GmbH, Seeholzenstrasse 2, 82166 Gräfelfing Germany, +49 (0)30 330 966 86, info@buah.de

Initiative contact from the customer via email

If you initiate business contact with us via email, we will only collect your personal data (name, email address, message text) to the extent provided by you. The data processing serves to process and answer your contact request.

If the contact is used to carry out pre-contractual measures (e.g. advice if you are interested in buying, preparing an offer) or concerns a contract that has already been concluded between you and us, this data processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR.


If contact is made for other reasons, this data processing is carried out on the basis of Article 6 Paragraph 1 Letter f GDPR due to our overriding legitimate interest in processing and answering your request. In this case, you have the right, for reasons arising from your particular situation, to object at any time to this processing of your personal data based on Article 6 Paragraph 1 Letter f of the GDPR.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.

Collection and processing when using the contact form

When you use the contact form, we only collect your personal data (name, email address, message text) to the extent provided by you. The data processing serves the purpose of establishing contact.
If the contact serves to carry out pre-contractual measures (e.g. advice if you are interested in buying, preparing an offer) or concerns a contract that has already been concluded between you and us, this data processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in processing and answering your request. In this case, you have the right, for reasons arising from your particular situation, to object at any time to this processing of your personal data based on Article 6 Paragraph 1 Letter f of the GDPR.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.

WhatsApp Business
If you contact us for business via WhatsApp, we use the WhatsApp Business version of WhatsApp Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; “WhatsApp”). If you are located outside the European Economic Area, this service is provided by WhatsApp Inc. (1601 Willow Road, Menlo Park, CA 94025, USA).
The data processing serves to process and answer your contact request. For this purpose, we collect and process your mobile phone number stored on WhatsApp, your name if provided, and other data to the extent provided by you. For the service, we use a mobile device whose address book only stores data from users who have contacted us via WhatsApp. Personal data will not be passed on to WhatsApp without you having already given your consent to WhatsApp.
Your data will be transmitted by WhatsApp to Meta Platforms Inc. servers in the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Meta Platforms Inc. is not certified under the TADPF. The data transfer takes place, among other things, on the basis of standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard -contractual-clauses-scc_de.
If the contact is used to carry out pre-contractual measures (e.g. advice if you are interested in buying, preparing an offer) or concerns a contract that has already been concluded between you and us, this data processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR for our overriding legitimate interest in providing quick and easy contact and in answering your request. In this case, you have the right, for reasons arising from your particular situation, to object at any time to this processing of your personal data based on Article 6 Paragraph 1 Letter f of the GDPR.
We only use your personal data to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.
Further information on terms of use and data protection when using WhatsApp can be found at https://www.whatsapp.com/legal/#terms-of-service and https://www.whatsapp.com/legal/#privacy-policy.

Customer account orders

Customer account
When you open a customer account, we collect your personal data to the extent specified there. The data processing serves the purpose of improving your shopping experience and simplifying order processing. Processing is carried out on the basis of Article 6 Paragraph 1 Letter a GDPR with your consent. You can revoke your consent at any time by notifying us, without this affecting the lawfulness of the processing carried out based on your consent before its revocation. Your customer account will then be deleted.

Collection, processing and transfer of personal data when placing orders
When you place an order, we only collect and process your personal data to the extent that this is necessary to fulfill and process your order and to process your inquiries. The provision of the data is necessary for the conclusion of the contract. Failure to provide it will result in no contract being concluded. The processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR and is necessary for the fulfillment of a contract with you.
Your data will be passed on, for example, to the shipping companies and dropshipping providers you have chosen, payment service providers, service providers for order processing and IT service providers. In all cases we strictly observe the legal requirements. The amount of data transmission is limited to a minimum.

Your data will be transmitted to Canada, among other places. There is an adequacy decision from the EU Commission for data transfers to Canada.


Reviews advertising


Data collection when writing a comment or rating
When commenting/rating an article or post, we only collect your personal data (name, email address, comment text) to the extent you provide it. The processing serves the purpose of enabling comments/ratings and displaying comments/ratings.
For the purpose of verifying your rating, we also collect the following data: Order number.
By submitting the comment/review, you consent to the processing of the transmitted data. Processing is carried out on the basis of Article 6 Paragraph 1 Letter a GDPR with your consent. You can revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out based on your consent before its revocation. Your personal data will then be deleted.

When your comment is published, only the name you provide will be published.

Use of your personal data to send you postal advertising
We use your personal data (name, address), which we received in the context of selling a good or service, to send you postal advertising, unless you have objected to this use. The provision of this data is necessary for the conclusion of the contract. Failure to provide it will result in no contract being concluded.
The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in direct advertising. You can object to this use of your address data at any time by notifying us. The contact details for exercising your objection can be found in the legal notice.

Use of the email address to send newsletters
Regardless of the contract processing, we use your email address exclusively for our own advertising purposes to send newsletters, provided you have expressly agreed to this. Processing is carried out on the basis of Article 6 Paragraph 1 Letter a GDPR with your consent. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation. You can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or by notifying us. Your email address will then be removed from the distribution list.

Use of the email address to send direct mail
We use your email address, which we received as part of the sale of a good or service, to electronically send advertising for our own goods or services that are similar to those that you have already purchased from us, to the extent that you do so have not objected to use. Providing the email address is necessary for the conclusion of the contract. Failure to provide it will result in no contract being concluded. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in direct advertising. You can object to this use of your email address at any time by notifying us. The contact details for exercising your objection can be found in the legal notice. You can also use the link provided in the promotional email. There are no costs for this other than the transmission costs according to the basic tariffs.

Using Klaviyo

We use the service of Klaviyo Inc. (125 Summer St Floor 7, Boston, MA 02111, USA; “Klaviyo”) to send the newsletter as part of order processing.
We pass on the information you provided when registering for the newsletter (email address, first and last name if applicable) to Klaviyo. The data processing serves the purpose of sending the newsletter and its statistical evaluation.
In order to evaluate newsletter campaigns, the newsletters sent contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any integrated links. In this context, we collect your personal data such as IP address, browser type and device as well as the time. Usage profiles can be created from this data under a pseudonym. The data collected will not be used to identify you personally. The data collected is only used for statistical evaluation to improve newsletter campaigns.
Your data is usually transmitted to Klaviyo servers in the USA and stored there. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Klaviyo is not certified according to the TADPF. The data transfer takes place, among other things, on the basis of standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard -contractual-clauses-scc_de.
Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in a targeted, advertising-effective and user-friendly newsletter system. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
Further information on data protection at Klaviyo can be found at https://www.klaviyo.com/legal/privacy-notice and at https://www.klaviyo.com/legal/data-processing-agreement.

Use of the mobile phone number to send SMS advertising
Regardless of the contract processing, we use your mobile phone number exclusively for our own advertising purposes to send SMS advertising, provided you have expressly agreed to this.
Processing is carried out on the basis of Article 6 Paragraph 1 Letter a GDPR with your consent. You can revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out based on your consent before its revocation. Your mobile phone number will then be removed from the distribution list.

Your mobile phone number will be passed on to a service provider for sending SMS messages as part of order processing.



Shipping service provider merchandise management



Passing on the email address to shipping companies for information about shipping status
We pass on your email address to the transport company as part of the contract processing, provided you have expressly agreed to this in the ordering process. The purpose of the transfer is to inform you by email about the shipping status. Processing is carried out on the basis of Article 6 Paragraph 1 Letter a GDPR with your consent. You can revoke your consent at any time by notifying us or the transport company, without affecting the lawfulness of the processing carried out based on your consent before its revocation.
Use of an external merchandise management system
We use an inventory management system to process the contract as part of order processing. For this purpose, your personal data collected as part of the order will be sent to
Xentral ERP Software GmbH, Fuggerstraße 11, 86150 Augsburg
transmitted.



Payment service provider credit report



Use of PayPal
We use the PayPal payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the payment service. By selecting and using payment via PayPal, the data required for payment processing will be transmitted to PayPal in order to be able to fulfill the contract with you using the selected payment method. This processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR.

All PayPal transactions are subject to the PayPal Privacy Policy. You can find these at https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Using PayPal Express
We use the PayPal Express payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the PayPal Express payment service. In order to integrate this payment service, it is necessary for PayPal to collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when you access the website. Cookies can also be used for this purpose. The cookies enable your browser to be recognized.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in a customer-oriented offer of various payment methods. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
By selecting and using PayPal Express, the data required for payment processing will be transmitted to PayPal in order to be able to fulfill the contract with you using the selected payment method. This processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR. Further information on data processing when using the PayPal Express payment service can be found in the associated data protection declaration at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE#Updated_PS.

Using Klarna payment options
We use the payment service of Klarna Bank AB (publ) (Sveavägen 46, 111 34 Stockholm, Sweden; “Klarna”) on our website. By selecting and using payment via Klarna, the data required for payment processing will be transmitted to Klarna in order to be able to fulfill the contract with you using the selected payment method. This processing is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR.

“Pay Later” (invoice), “Pay Now” (payment by direct debit), “Financing” (purchase in installments)
For individual payment methods such as “Pay Later” (invoice), “Pay Now” (payment by direct debit), “Financing” (purchase in installments), Klarna reserves the right, if necessary, to obtain credit information based on mathematical and statistical procedures using credit agencies.
For this purpose, Klarna transmits the personal data required for a credit check, such as first and last name, address, gender, email address, IP address as well as data relating to the order to a credit agency for the purpose of identity and credit checks and uses the information received about the statistical probability of a payment default for a balanced decision on the establishment, implementation or termination of the contractual relationship. The credit report can contain probability values ​​(score values) that are calculated on the basis of scientifically recognized mathematical-statistical methods and whose calculation includes, among other things, address data. Your concerns will be considered in accordance with the statutory provisions. The data processing serves the purpose of checking your creditworthiness to initiate a contract. The processing is carried out on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in protecting against non-payment if Klarna makes advance payments. For reasons arising from your particular situation, you have the right to object at any time to this processing of your personal data based on Article 6 Paragraph 1 Letter f of the GDPR by notifying Klarna. The provision of the data is necessary for the conclusion of the contract with the payment method you require. Failure to provide this means that the contract cannot be concluded using the payment method you have chosen.
Further information, in particular to which credit agencies Klarna passes on your personal data, can be found for Germany at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies and for Austria at https:// cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/credit_rating_agencies
General information about Klarna can be found for Germany at: https://www.klarna.com/de/ and for Austria at https://www.klarna.com/at/. Your personal information will be processed by Klarna in accordance with the applicable data protection regulations and in accordance with the information in Klarna's data protection regulations for Germany at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy and for Austria at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy.


Cookies

Our website uses cookies. Cookies are small text files that are stored in the Internet browser or by the Internet browser on a user's computer system. When a user accesses a website, a cookie can be stored on the user's operating system. This cookie contains a characteristic string that allows the browser to be uniquely identified when the website is accessed again.

Cookies are stored on your computer. Therefore, you have full control over the use of cookies. By selecting the appropriate technical settings in your internet browser, you can be notified before cookies are set and decide individually whether to accept them and prevent the storage of the cookies and the transmission of the data they contain. Cookies that have already been saved can be deleted at any time. However, we would like to point out that you may then not be able to fully use all of the functions of this website.

You can find out how you can manage cookies in the most important browsers (including deactivating them) using the links below:
Chrome: https://support.google.com/accounts/answer/61416?hl=de
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablassen
Safari: https://support.apple.com/de-de/guide/safari/manage-cookies-and-website-data-sfri11471/mac
Technically necessary cookies
Unless otherwise stated in the data protection declaration below, we only use these technically necessary cookies for the purpose of making our offering more user-friendly, effective and secure. Cookies also enable our systems to recognize your browser even after you change pages and to offer you services. Some functions of our website cannot be offered without the use of cookies. For this it is necessary that the browser is recognized even after a page change.

The use of cookies or comparable technologies is based on Section 25 Paragraph 2 TTDSG. Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective design of our offering.
You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
Use of GDPR Legal Cookies
We use the consent management tool GDPR Legal Cookie from beeclever GmbH (Universitätsstraße 3, 56070 Koblenz a. Rh.; “beeclever”) on our website. The tool enables you to grant consent to data processing via the website, in particular the setting of cookies, and to make use of your right to revoke consent that has already been given.
The data processing serves the purpose of obtaining and documenting the necessary consent for data processing and thus complying with legal obligations. Cookies can be used. The following information, among others, can be collected and transmitted to beeclever: anonymized IP address, date and time of consent, URL from which the consent was sent, anonymous, random, encrypted key, consent status. This data will not be passed on to other third parties.
Data processing is carried out to fulfill a legal obligation based on Article 6 Paragraph 1 Letter c GDPR.
Further information on terms of use and data protection at beeclever can be found at: https://gdpr-legal-cookie.com/pages/terms-conditions and at https://gdpr-legal-cookie.com/pages/datenschutzerklarung.


Advertising tracking analysis


Use of Google Analytics
On our website we use the web analysis service Google Analytics from Google Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”).
The data processing serves the purpose of analyzing this website and its visitors as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. The following information can be collected, among other things: IP address, date and time of page access, click path, information about the browser you use and the device you use, pages visited, referrer URL (website through which you visit our website). website), location data, purchasing activities. The IP address transmitted by your browser as part of Google Analytics is not combined with other Google data.
Google Analytics uses technologies such as cookies, web storage in the browser and web beacons that enable analysis of your use of the website. The information generated in this way about your use of this website is usually transmitted to a Google server in the USA and stored there. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google is not certified according to the TADPF. The data transfer is based, among other things, on standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks and https://business.safety.google/adsprocessorterms/. Both Google and US government authorities have access to your data. Your data may be linked by Google with other data, such as your search history, your personal accounts, your usage data from other devices and any other data that Google has about you.
IP anonymization is activated on this website. As a result, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in the needs-based and targeted design of the website. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
You can prevent Google from collecting the data generated by Google Analytics and related to your use of the website (including your IP address) and from processing this data by Google by downloading the browser plug-in available under the following link and install: https://tools.google.com/dlpage/gaoptout?hl=de
To prevent data collection and storage by Google Analytics across devices, you can set an opt-out cookie. Opt-out cookies prevent your data from being collected in the future when you visit this website. You must opt ​​out on all systems and devices you use for this to be effective. If you delete the opt-out cookie, requests will be sent to Google again. If you click here, the opt-out cookie will be set: Deactivate Google Analytics.
Further information on terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html or at https://www.google.de/intl/de/policies/ and at https:/ /policies.google.com/technologies/cookies?hl=de.
Use of Google Analytics 4
On our website we use the web analysis service Google Analytics from Google Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”).
The data processing serves the purpose of analyzing this website and its visitors as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator.
The following information can be collected, among other things: IP address, date and time of page access, click path, information about the browser you use and the device you use, pages visited, referrer URL (website through which you visit our website). website), location data, purchasing activities. The IP address transmitted by your browser as part of Google Analytics is not combined with other Google data.
Google uses technologies such as cookies, web storage in the browser and web beacons that enable analysis of your use of the website. The information generated in this way about your use of this website is usually transmitted to a Google server in the USA and stored there. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google is not certified according to the TADPF. The data is transferred based, among other things, on standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks. Both Google and US government authorities have access to your data. Your data may be linked by Google with other data, such as your search history, your personal accounts, your usage data from other devices and any other data that Google has about you.
When using Google Analytics 4, the IP address transmitted by your website is automatically collected and processed in anonymized form. The IP address is previously shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in the needs-based and targeted design of the website. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
You can prevent Google from collecting the data generated by Google Analytics and related to your use of the website (including your IP address) and from processing this data by Google by downloading the browser plug-in available under the following link and install: https://tools.google.com/dlpage/gaoptout?hl=de
To prevent data collection and storage by Google Analytics across devices, you can set an opt-out cookie. Opt-out cookies prevent your data from being collected in the future when you visit this website. You must opt ​​out on all systems and devices you use for this to be effective. If you delete the opt-out cookie, requests will be sent to Google again. If you click here, the opt-out cookie will be set: Deactivate Google Analytics.
Further information on terms of use and data protection can be found at https://policies.google.com/technologies/partner-sites and at https://policies.google.com/privacy?hl=de&gl=de.
Using Hotjar
We use the analysis tool from Hotjar Ldt on our website. (Level 2, St Julian's Business Centre, 3, Elia Zammit Street, St Julians STJ1000, Malta; “Hotjar”).
The data processing serves the purpose of needs-based design, optimization and analysis of our website.
The tool is used to randomly record the movements of site visitors on the website. This creates a log of mouse movements, scrolling behavior, length of stay and clicks on the website (so-called heatmap).
For this purpose, Hotjar uses cookies, among other things. The following information may be collected, among other things: IP address (in anonymized form), information about the device you use (screen size, devices, unique device identifier), information about the browser you use, location data (exclusively about the country), preferred language Operating system used to display the website. Detailed information about the cookies used, their function and storage period can be found here: https://help.hotjar.com/hc/en-us/articles/115011789248-Hotjar-Cookies.
User profiles are created from this data under a pseudonym. The data is not used to personally identify the visitor to the website and is not combined with personal data of the bearer of the pseudonym. Hotjar is contractually prohibited from selling the data collected to other third parties.
Your data may be transferred to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Hotjar is not TADPF certified. The data transfer takes place, among other things, on the basis of appropriate protective measures. Hotjar will provide you with further information on the measures taken upon request.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in the needs-based and targeted design of the website. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
To prevent Hotjar from collecting and storing data, you can set an opt-out cookie here: https://www.hotjar.com/legal/compliance/opt-out. Opt-out cookies prevent your data from being collected in the future when you visit this website. You must implement the opt-out cookie on all systems and devices used for this to work across devices. If you delete the opt-out cookie, data will be transmitted to Hotjar again.
Further information on data protection when using Hotjar can be found here: https://www.hotjar.com/legal/policies/privacy#enduserenglish.
Use of the Facebook Pixel
We use the “Custom Audiences” remarketing function from Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland “Facebook”) on our website.
Meta Platforms Ireland and we are jointly responsible for the collection of your data when you integrate the service and the transmission of this data to Facebook. The basis for this is an agreement between us and Meta Platforms Ireland on the joint processing of personal data, which sets out the respective responsibilities. The agreement can be accessed at https://www.facebook.com/legal/controller_addendum. Thereafter, we are in particular responsible for fulfilling the information obligations in accordance with Articles 13 and 14 of the GDPR, for compliance with the security requirements of Article 32 of the GDPR with regard to the correct technical implementation and configuration of the service, and for compliance with the obligations under Article 33 , 34 GDPR, to the extent that a personal data breach affects our obligations under the joint processing agreement. Meta Platforms Ireland is responsible for enabling the rights of those affected in accordance with Articles 15 - 20 of the GDPR, of complying with the security requirements of Article 32 of the GDPR with regard to the security of the service and of fulfilling the obligations under Articles 33 and 34 of the GDPR in the event of a violation the protection of personal data concerns Meta Platforms Ireland's obligations under the Joint Processing Agreement.
The purpose of the application is to target visitors to the website with interest-based advertising on the social network Facebook. For this purpose, Facebook's remarketing tag was implemented on the website. This tag is used to establish a direct connection to the Facebook servers when you visit the website. This sends information to the Facebook server about which of our pages you have visited. Facebook assigns this information to your personal Facebook user account. When you visit the social network Facebook, you will be shown personalized, interest-based Facebook ads.
Your data may be transferred to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Meta is not certified according to the TADPF. The data is transferred based, among other things, on standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://www.facebook.com/legal/EU_data_transfer_addendum.
Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in targeting site visitors with interest-based advertising. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation. You can deactivate the “Custom Audiences” remarketing function here.
Further information on the collection and use of data by Facebook, your rights in this regard and options for protecting your privacy can be found in Facebook's data protection information at https://www.facebook.com/about/privacy/.
Use of Google Ads conversion tracking
We use the online advertising program “Google Ads” on our website and, in this context, conversion tracking (visit action evaluation). Google Conversion Tracking is an analysis service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).
If you click on an ad placed by Google, a cookie for conversion tracking will be stored on your computer. These cookies have a limited validity, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages on our website and the cookie has not yet expired, Google and we can recognize that you clicked on the ad and were redirected to that page. Each Google Ads customer receives a different cookie. There is therefore no possibility that cookies can be tracked via the websites of Ads customers.
The information collected using the conversion cookie is used to create conversion statistics. Here we find out the total number of users who clicked on one of our ads and were redirected to a page with a conversion tracking tag. However, we do not receive any information that can be used to personally identify users.
Your data may be transmitted to Google LLC servers in the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google is not certified according to the TADPF. The data transfer is based, among other things, on the basis of standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks and https://business.safety.google/adscontrollerterms/.
Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in targeting site visitors with interest-based advertising. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
You can deactivate personalized advertising for you in Google's advertising settings. Instructions can be found at https://support.google.com/ads/answer/2662922?hl=de
Alternatively, you can prevent the use of cookies by third parties by accessing the Network Advertising Initiative deactivation page at https://www.networkadvertising.org/choices/ and implementing the further opt-out information provided there. You will then not be included in the conversion tracking statistics.
Further information and Google's privacy policy can be found at: https://www.google.de/policies/privacy/
Use of Google AdSense
We use the AdSense function of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) on our website.
The data processing serves the purpose of renting out advertising space on the website and targeting website visitors with interest-based advertising. Using this function, visitors to the provider's website are shown personalized, interest-based advertising ads from the Google Display Network. Google uses cookies that enable analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google is not certified according to the TADPF. The data transfer is based, among other things, on the basis of standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks and https://business.safety.google/adscontrollerterms/. Google may transfer this information to third parties if this is required by law or if third parties process this data on behalf of Google. Under no circumstances will Google associate your IP address with other Google data.
Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in targeting site visitors with interest-based advertising. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
You can permanently deactivate Google's use of cookies by following the following link, downloading and installing the plug-in provided there: https://support.google.com/ads/answer/7395996?hl=de. Alternatively, you can prevent the use of cookies by third parties by accessing the Network Advertising Initiative deactivation page at https://www.networkadvertising.org/choices/ and implementing the further opt-out information provided there. Further information and Google's privacy policy can be found at: https://www.google.com/policies/technologies/ads/ and https://www.google.de/policies/privacy/
Use of the remarketing or “similar target groups” function of Google Inc.
We use the remarketing or “similar target groups” function of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) on our website.
The application serves the purpose of analyzing visitor behavior and visitor interests. Google uses cookies to carry out the analysis of website usage, which forms the basis for creating interest-based advertisements. The cookies record visits to the website as well as anonymized data about the use of the website. There is no storage of personal data of visitors to the website. If you subsequently visit another website in the Google Display Network, you will be shown advertisements that most likely take into account previously accessed product and information areas.
Your data may be transmitted to Google LLC servers in the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google is not certified according to the TADPF. The data is transferred based, among other things, on standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks.
Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in targeting site visitors with interest-based advertising. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
You can permanently deactivate Google's use of cookies by following the following link, downloading and installing the plug-in provided there: https://support.google.com/ads/answer/7395996?hl=de
Alternatively, you can prevent the use of cookies by third parties by accessing the Network Advertising Initiative deactivation page at https://www.networkadvertising.org/choices/ and implementing the further opt-out information provided there.
Further information about Google Remarketing and the associated data protection declaration can be found at: https://www.google.com/privacy/ads/
Using the Pinterest tag
We use the Pinterest tag from Pinterest Europe Limited (Palmerston House, 2nd, Fenian Street, Floor, Dublin 2, Ireland "Pinterest") on our website.
The purpose of the application is to target visitors to the website with interest-based advertising on the social network Pinterest. For this purpose, the Pinterest conversion tag was implemented on the website. This tag creates a direct connection to the Pinterest servers when you visit the website. This sends information to the Pinterest server about which of our pages you have visited. Pinterest assigns this information to your personal Pinterest user account if you are logged in to the social network. When you visit Pinterest, you will then see personalized, interest-based Pinterest ads.
If you access our website via a pin on the social network Pinterest, a cookie for conversion tracking will be stored on your computer. These cookies have a limited validity, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages on our website and the cookie has not yet expired, Pinterest and we can recognize that you clicked on the pin and were redirected to that page. The information collected using the conversion cookie serves the purpose of creating conversion statistics and thus optimizing our website. The following information, among others, can be processed here: total number of users who clicked on one of our pins and were redirected to our website, sub-pages visited on our website (e.g. category or product pages), search queries on our website, your shopping cart contents, completed ones Transactions.
Your data may be transferred to the USA. There is no adequacy decision from the EU Commission for the USA. The data transfer takes place, among other things, on the basis of standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard -contractual-clauses-scc_de.
Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in targeting site visitors with interest-based advertising. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation. You can deactivate personalized advertising in the personalization settings on Pinterest or via the AdChoices website optout.aboutads.info. You can prevent the storage of cookies by selecting the appropriate technical settings in your browser software; However, we would like to point out that in this case you may not be able to fully use all of the functions of this website.
Further information on how Pinterest collects and uses data, your rights in this regard and options for protecting your privacy can be found in Pinterest's data protection information at https://policy.pinterest.com/de/privacy-policy.
Using Criteo
We use the technology of the provider Criteo SA (32 Rue Blanche, 75009 Paris, France; “Criteo”) on our website.
The purpose of the application is to target website visitors with interest-based advertising, as personalized advertising banners on other websites (so-called publishers). To do this, Criteo uses technologies such as cookies that enable your browser to be recognized.
The following information, among other things, can be collected and transmitted to Criteo: Referrer URL, pages visited on our website, date and time of visit, advertising ID of your smartphone, information about the browser and device you use, shopping cart contents. Usage profiles can be created from the data collected in this way using pseudonyms. However, it is not possible to personally identify users.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in the needs-based and targeted design of the website. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation. In order to permanently object to the collection of data and the creation of pseudonymized user profiles in the future, you can download the following so-called opt-out cookie: Criteo registration https://www.criteo.com/de/privacy.
Further information on data processing and data protection can be found at https://www.criteo.com/de/privacy and https://www.criteo.com/de/privacy/how-we-use-your-data/.
Plug-ins and others
Using Google Tag Manager
We use the Google Tag Manager from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This application manages JavaScript tags and HTML tags, which are used to implement tracking and analysis tools in particular. The data processing serves the purpose of tailoring and optimizing our website.
The Google Tag Manager itself neither stores cookies nor processes personal data. However, it enables the triggering of additional tags that can collect and process personal data.
Further information on terms of use and data protection can be found here.
Use of Google reCAPTCHA
We use the reCAPTCHA service from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website. The query serves the purpose of distinguishing between input by a human or by automated, machine processing. For this purpose, your input will be transmitted to Google and used there. In addition, the IP address and any other data required by Google for the reCAPTCHA service are transmitted to Google. This data is processed by Google within the European Union and may also be transmitted to Google LLC servers in the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google is not certified according to the TADPF. The data is transferred based, among other things, on standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR out of our overriding legitimate interest in protecting our website from automated spying, misuse and SPAM. For reasons arising from your particular situation, you have the right to object at any time to this processing of your personal data based on Article 6 Paragraph 1 Letter f of the GDPR.
Further information about Google reCAPTCHA and the associated data protection declaration can be found at: https://www.google.com/recaptcha/intro/android.html and https://www.google.com/privacy.
Using Cloudfront
We use the content delivery network Cloudfront CDN from Amazon Web Services EMEA SARL (38 avenue John F. Kennedy, L-1855, Luxembourg; “Cloudfront”) on our website.

This is a supra-regional network of servers in various data centers to which our web server connects and through which certain content on our website is delivered.
The data processing serves the purpose of optimizing the loading times of our website and thus making our offering more user-friendly. The following information, among other things, can be collected: IP address, system configuration information, information about traffic to and from customer websites (so-called server log files) .
Your data may be transferred to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Cloudfront is not TADPF certified. The data transfer takes place, among other things, on the basis of standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard -contractual-clauses-scc_de.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in the needs-based and targeted design of the website. For reasons arising from your particular situation, you have the right to object at any time to this processing of your personal data based on Article 6 Paragraph 1 Letter f of the GDPR.
Further information on data protection when using Cloudfront can be found at https://docs.aws.amazon.com/de_de/AmazonCloudFront/latest/DeveloperGuide/data-protection-summary.html and at https://d1.awsstatic.com /legal/aws-gdpr/AWS_GDPR_DPA.pdf.

Use of Google Maps
We use the function for embedding GoogleMaps maps from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website.
The function enables the visual representation of geographical information and interactive maps. Google also collects, processes and uses data from visitors to the websites when they access the pages in which Google Maps maps are integrated.
Your data may also be transmitted to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google is not certified according to the TADPF. The data is transferred based, among other things, on standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in the needs-based and targeted design of the website. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
Further information on how Google collects and uses data can be found in Google's data protection information at https://www.google.com/privacypolicy.html. There you also have the opportunity to change your settings in the data protection center so that you can manage and protect your data processed by Google.
Use of YouTube
We use the function for embedding YouTube videos from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "YouTube") on our website. YouTube is a partnership with Google LLC (1600 Amphitheater Parkway, Mountain View, CA 94043, USA; “Google”) affiliated company.
The function displays videos stored on YouTube in an iFrame on the website. The “Extended data protection mode” option is activated. This means that YouTube does not store any information about website visitors. Only when you watch a video is information about it transmitted to YouTube and stored there. Your data may be transferred to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). YouTube is not certified according to the TADPF. The data is transferred based, among other things, on standard contractual clauses as appropriate guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks.
Your personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in the needs-based and targeted design of the website. You have the right to object to this processing of personal data concerning you at any time for reasons relating to your particular situation.
Further information on the collection and use of data by YouTube and Google, your rights in this regard and options for protecting your privacy can be found in YouTube's data protection information at https://www.youtube.com/t/privacy.



Rights of those affected and storage period



Duration of storage
After the contract has been fully processed, the data will initially be stored for the duration of the warranty period, then taking into account statutory retention periods, in particular tax and commercial law, and then deleted after the deadline has expired, unless you have agreed to further processing and use.

Rights of the data subject
If the legal requirements are met, you are entitled to the following rights in accordance with Articles 15 to 20 of the GDPR: right to information, to correction, to deletion, to restriction of processing, to data portability.
In addition, according to Art. 21 Para. 1 GDPR, you have the right to object to processing based on Art. 6 Para. 1 f GDPR, as well as to processing for the purpose of direct advertising.

Right to lodge a complaint with the supervisory authority
According to Art. 77 GDPR, you have the right to complain to the supervisory authority if you believe that your personal data is not being processed lawfully.

You can lodge a complaint with, among other things, the supervisory authority responsible for us, which you can reach using the following contact details:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Tel.: +49 981 1800930
Fax: +49 981 180093800
Email: poststelle@lda.bayern.de

Right to object
If the personal data processing listed here is based on our legitimate interest in accordance with Article 6 Paragraph 1 Letter f of the GDPR, you have the right to object to this processing at any time with future effect for reasons arising from your particular situation.
After an objection has been made, the processing of the data concerned will be terminated unless we can demonstrate compelling legitimate reasons for the processing that outweigh your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.

If personal data is processed for direct advertising purposes, you can object to this processing at any time by notifying us. After an objection has been made, we will stop processing the data concerned for the purpose of direct advertising.

last updated: July 13, 2023