Privacy Policy

1. Privacy at a glance

General

The following notes provide a simple overview of what happens to your personal information when you visit this website. Personal data is any data that personally identifies you. Detailed information on data protection can be found in our Privacy Policy.

Data collection on this website

Who is responsible for data collection on this website?

The data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.

How do we collect your data?

On the one hand, your data is collected when you communicate it to us. This can be, for. E.g. data that you enter in a contact form.

Other data are automatically recorded by our IT systems when you visit the website. This is mainly technical data (e.g. internet browser, operating system or time of the page was viewed). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure that the website is provided without errors. Other data can be used to analyze your user behavior.

What rights do you have regarding your data?

At any time you have the right to obtain free information about the origin, recipient and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. For this purpose as well as for further questions about data protection you can contact us at any time at the address given in the imprint. Furthermore, you have a right of appeal to the competent supervisory authority.

In addition, you have the right to request the restriction of the processing of your personal data in certain circumstances. Details can be found in the privacy policy under "Right to restriction of processing".

Analysis tools and third-party tools

When visiting this website, your surfing behavior can be statistically evaluated. This happens above all with cookies and with so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior can not be traced back to you.

You can object to this analysis or prevent it by not using certain tools. Detailed information about these tools and their possibilities of appeal can be found in the following privacy policy.

2. Hosting and Content Delivery Networks (CDN)

External hosting

This website is hosted by an external service provider (hoster). The personal information collected on this website is stored on the servers of the host. These may include, but are not limited to, IP addresses, contact requests, metadata and communications, contract information, contact information, names, web page access, and other data generated through a web site.

The use of the hoster is for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para 1 lit. f DSGVO).

Our Hoster will only process your data to the extent necessary to fulfill its performance obligations and to follow our instructions with respect to such data.

3. General information and mandatory information

Privacy Policy

The operators of this website take the protection of your personal data very seriously. We treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy policy.

If you use this website, various personal data will be collected. Personal data is data with which you can be personally identified. This data protection declaration explains what data we collect and what we use it for. It also explains how and for what purpose this happens.

We point out that data transmission over the Internet (e.g. when communicating by e-mail) can have security gaps. A complete protection of the data against access by third parties is not possible.

Note on the responsible body

The responsible body for data processing on this website is:

MK Esthetics-Med GmbH
Str. 99a
82008 Unterhaching

Phone: +49 (0) 89 665 476 880
Email: mk@esthetics-med.de

The responsible body is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).

Revocation of your consent to data processing

Many data processing operations are only possible with your express consent. You can revoke consent that you have already given at any time. An informal message by e-mail to us is sufficient. The legality of the data processing that took place up until the revocation remains unaffected by the revocation.

Right to object to data collection in special cases and direct mail (Art. 21 DSGVO)

IF DATA PROCESSING IS BASED ON ART. 6 ABS. 1 LIT. E OR F DSGVO, YOU HAVE THE RIGHT, AT ANY TIME, TO CONTRADICTIVE TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS OBTAINED FROM YOUR SPECIFIC SITUATION; THIS APPLIES ALSO TO A PROFILING BASED ON THESE PROVISIONS. THE RELEVANT LEGAL BASIS ON WHICH A PROCESS IS BASED IS PERMITTED BY THIS PRIVACY POLICY. IF YOU CLAIM ANY DISPUTE, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE MAY PROVIDE IMPERATIVE REASONABLE REASONS FOR PROCESSING THAT PREVENT ITS INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING OF THE FORMATION, EXERCISE OR DEFENSE OF LEGAL ATTRIBUTIONS ( OPPOSITION ACCORDING TO ART 21 ABS 1 DSGVO).

IF YOUR PERSONAL DATA IS PROCESSED TO OPERATE DIRECT ADVERTISING, YOU HAVE THE RIGHT TO INTRODUCE ANY CONTESTING AGAINST THE PROCESSING OF YOU OF PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING; THIS IS ALSO FOR PROFILING, IF IT IS RELATED TO SUCH DIRECT ADVERTISING. IF YOU CONTEST, YOUR PERSONAL DATA IS THEN NOT USED FOR THE PURPOSES OF DIRECT ADVERTISING (CONTRARY TO ARTICLE 21 EXT. 2 DSGVO).

Right of appeal to the competent supervisory authority

In the case of violations of the GDPR, the persons concerned have a right of appeal to a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right of appeal is without prejudice to any other administrative or judicial remedies.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another person responsible, this will only be done to the extent that it is technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security purposes and to protect the transmission of confidential content, such as orders or requests you send to us as a site operator. An encrypted connection is indicated by the browser's address bar changing from "http: //" to "https: //" and the lock icon in your browser bar.

If SSL or TLS encryption is activated, the data that you transmit to us cannot be read by third parties.

Encrypted payments on this website

If there is an obligation to provide us with your payment data (e.g. account number for direct debit authorization) after the conclusion of a fee-based contract, this data is required for payment processing.

Payment transactions using common means of payment (Visa/MasterCard, direct debit) are only made via encrypted SSL or TLS connections. You can recognize an encrypted connection in your browser's address line when it changes from "http://" to "https://" and the lock icon in your browser line is visible.

In the case of encrypted communication, any payment details you submit to us cannot be read by third parties.

Information, cancellation and rectification

Within the scope of the applicable legal provisions, you have the right to free information about your stored personal data, their origin and recipient and the purpose of the data processing and, if necessary, a right to rectification or deletion of this data. For further information on personal data, please contact us at any time at the address given in the imprint.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time at the address given in the imprint. The right to restrict processing exists in the following cases:

  • If you deny the accuracy of your personal information stored with us, we usually need time to verify this. For the duration of the audit you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data is unlawful, you may request the restriction of data processing instead of deletion.
  • If we no longer need your personal information, but you need it to exercise, defend or enforce legal claims, you have the right to demand that your personal information be restricted instead of being deleted.
  • If you have filed an objection under Art. 21 para. 1 DSGVO, a balance must be made between your interests and ours. As long as it is not clear whose interests prevail, you have the right to demand the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data may be - except for their storage - only with your consent or for the assertion, exercise or defense of legal claims or to protect the rights of another natural or legal person or for reasons of important public interest the European Union or a Member State.

Klarna

In order to be able to offer you Klarna's payment options, we will transmit personal data, such as contact details and order data, to Klarna. Klarna can thus assess whether you can use the payment options offered by Klarna and adapt the payment options to your needs.  

You can find general information for Klarna right here, Your personal details will be processed by Klarna in accordance with the applicable data protection regulations and as specified in Klarnas Privacy Policy treated. 

 

4. Data collection on this website

Cookies

Our Internet pages use so-called "cookies". Cookies are small text files and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or your web browser automatically resolves them.

In some cases, third-party cookies can also be stored on your device when you enter our site (third-party cookies). These enable us or you to use certain services of the third-party company (e.g. cookies for processing payment services).

Cookies have different functions. Numerous cookies are technically necessary because certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies are used to evaluate user behavior or to display advertising.

Cookies that are required to carry out the electronic communication process or to provide certain functions that you wish to use (eg shopping cart function) are processed on the basis of Art. 6 para. 1 lit. f DSGVO saved. The website operator has a legitimate interest in the storage of cookies for the technically correct and optimized provision of its services. If a corresponding consent has been requested (eg consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent is revocable at any time.

You can set your browser to always inform you about established cookies, to decide case by case if you accept the cookies or generally exclude them as well as to activate the automatic delete of cookies when the browser is closed. However, the deactivation or rejection of cookies may restrict the functionality of our web offer.

Insofar as cookies from third-party companies or for analysis purposes are used, we will inform you of this separately in the context of this data protection declaration and, if necessary, ask for consent.

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • - Operating system used
  • - Referrer URL
  • - Host name of the accessing computer
  • - Time of the server request
  • IP address

These data will not be combined with data from other sources.

The collection of this data is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the technically error-free presentation and the optimization of his website - for this purpose, the server log files must be recorded.

Contact

Should you send us questions via the contact form, we will collect the data entered on the form, including the contact details you provide, to answer your question and any follow-up questions. We do not share this information without your permission.

The processing of this data is based on Art. 6 para. 1 lit. b DSGVO, if your request is related to the performance of a contract or is required to carry out pre-contractual action. In all other cases, the processing is based on our legitimate interest in the effective processing of requests addressed to us (Art. 6 para. 1 lit. f DSGVO) or your consent (Art. 6 para. 1 lit. a DSGVO), if these was queried.

The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.

Inquiry by e-mail, telephone or fax

If you contact us by e-mail, telephone or fax, your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We will not share this information without your consent.

The processing of this data is based on Art. 6 para. 1 lit. b DSGVO, if your request is related to the performance of a contract or is required to carry out pre-contractual action. In all other cases, the processing is based on your consent (Article 6 para. 1 lit. a DSGVO) and / or on our legitimate interests (Art. 6 para. 1 lit. f DSGVO), as we have a legitimate interest in the effective Processing of requests addressed to us.

The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.

5. Social Media

Social media plugins with Shariff

This website uses plug-ins from social media (e.g. Facebook, Twitter, Instagram, Pinterest, XING, LinkedIn, Tumblr).

The plugins can usually be identified by the respective social media logos. To ensure the privacy of this website, we only use these plugins together with the so-called "Shariff" solution. This application prevents the plugins integrated into this website from transferring data to the respective provider when the page is first entered.

A direct connection to the provider's server is only established when you activate the respective plug-in by clicking the associated button (consent). As soon as you activate the plugin, the respective provider receives the information that you have visited this website with your IP address. If you are logged into your respective social media account (e.g. Facebook) at the same time, the respective provider can assign your visit to this website to your user account.

The activation of the plugin constitutes a consent within the meaning of Art. 6 para. 1 lit. a DSGVO. You can revoke this consent at any time with effect for the future.

Facebook plugins (like & share button)

On this website plugins of the social network Facebook are integrated. Provider of this service is the Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the collected data will also be transferred to the US and other third countries.

You can recognize the Facebook plugins by the Facebook logo or the "Like-Button" ("Like") on this website. An overview of the Facebook plugins can be found here: https://developers.facebook.com/docs/plugins/?locale=de_DE.

When you visit this website, the plugin establishes a direct connection between your browser and the Facebook server. Facebook receives the information that you have visited this website with your IP address. If you click the Facebook "Like" button while you are logged into your Facebook account, you can link the content of this website to your Facebook profile. This enables Facebook to associate your visit to this website with your user account. We would like to point out that, as the provider of the website, we have no knowledge of the content of the data transmitted or how it is used by Facebook. For more information, see Facebook's privacy policy at: https://de-de.facebook.com/privacy/explanation.

If you do not want Facebook to be able to assign your visit to this website to your Facebook user account, please log out of your Facebook user account.

The use of Facebook plugins is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the widest possible visibility in the social media.

Twitter plugin

On this website features of the service Twitter are included. These features are offered through Twitter Inc., 1355 Market Street, 900 Suite, San Francisco, CA 94103, USA. By using Twitter and the "Re-Tweet" function, the websites you visit are linked to your Twitter account and shared with other users. This data is also transmitted to Twitter. We point out that we as the provider of the pages are not aware of the content of the transmitted data and their use by Twitter. For more information, see the privacy policy of Twitter at: https://twitter.com/de/privacy.

The use of the Twitter plugin is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the widest possible visibility in the social media.

Ihre Datenschutzeinstellungen bei Twitter können Sie in den Konto-Einstellungen unter https://twitter.com/account/settings . change

Instagram plugin

Functions of the Instagram service are integrated on this website. These functions are offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.

If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. We would like to point out that, as the provider of the website, we have no knowledge of the content of the data transmitted or how it is used by Instagram.

The storage and analysis of the data is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the greatest possible visibility in social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

For more information, see the Instagram Data Protection: https://instagram.com/about/legal/privacy/.

Tumblr plugin

This website uses buttons from the Tumblr service. The provider is Tumblr, Inc., 35 East 21st St, 10th Floor, New York, NY 10010, USA.

These buttons allow you to share a post or page on Tumblr or to follow the provider at Tumblr. When you visit one of our websites using the Tumblr button, the browser establishes a direct connection to the Tumblr servers. We have no control over the amount of data that Tumblr collects and transmits using this plugin. According to the current state, the IP address of the user as well as the URL of the respective website are transmitted.

The data are stored and analyzed on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the widest possible visibility in social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

For more information, visit the Tumblr Privacy Policy at: https://www.tumblr.com/privacy/de.

LinkedIn plugin

This website uses functions of the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.

Every time a page of this website that contains LinkedIn functions is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited this website with your IP address. If you click the "Recommend" button from LinkedIn and are logged into your LinkedIn account, LinkedIn is able to assign your visit to this website to you and your user account. We would like to point out that, as the provider of the website, we have no knowledge of the content of the transmitted data or its use by LinkedIn.

The use of the LinkedIn plug-in is based on Art. 6 Para. 1 lit.f GDPR. The website operator has a legitimate interest in the widest possible visibility in social media.

For more information, see LinkedIn's Privacy Statement at: https://www.linkedin.com/legal/privacy-policy.

XING plugin

This website uses functions of the XING network. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.

Each time you visit one of our sites that contains XING features, it will connect to XING servers. A storage of personal data is not done to our knowledge. In particular, no IP addresses are stored or the usage behavior is evaluated.

The data are stored and analyzed on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the widest possible visibility in social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

For more information on the Privacy Policy and the XING Share Button, please visit the XING Privacy Statement at: https://www.xing.com/app/share?op=data_protection.

Pinterest Plugin

On this website we use social plugins from the social network Pinterest, which is operated by Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103-490, USA ("Pinterest").

If you call up a page that contains such a plugin, your browser establishes a direct connection to the Pinterest servers. The plugin transmits log data to the Pinterest server in the USA. This log data may include your IP address, the address of the websites visited that also contain Pinterest functions, the type and settings of the browser, the date and time of the request, how you use Pinterest and cookies.

The storage and analysis of the data is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the greatest possible visibility in social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

Further information on the purpose, scope and further processing and use of the data by Pinterest as well as your rights in this regard and options for protecting your privacy can be found in Pinterest's data protection information: https://policy.pinterest.com/de/privacy-policy.

6. Analysis tools and advertising

Google Analytics

This website uses functions of the web analytics service Google Analytics. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses so-called "cookies". These are text files that are stored on your computer and that allow an analysis of the use of the website by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

The storage of Google Analytics cookies and the use of this analysis tool are based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested (eg consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent is revocable at any time.

Browser Plugin

You can prevent these cookies being stored by selecting the appropriate settings in your browser. However, we wish to point out that doing so may mean you will not be able to enjoy the full functionality of this website. You can also prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

Objection to data collection

You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this site: disable Google Analytics.

For more information about how Google Analytics handles user data, see Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.

Storage time

Data stored by Google at user and event level that are linked to cookies, user IDs (e.g. user ID) or advertising IDs (e.g. DoubleClick cookies, Android advertising ID) are anonymized after 26 months or deleted. You can find details on this under the following link: https://support.google.com/analytics/answer/7667196?hl=de

Hotjar

This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Center, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (website: https://www.hotjar.com).

Hotjar is a tool for analyzing your user behavior on this website. With Hotjar we can record your mouse and scroll movements and clicks. Hotjar can also determine how long you have remained at a specific point with the mouse pointer. From this information, Hotjar creates so-called heatmaps, which can be used to determine which website areas are preferred by website visitors.

We can also determine how long you have stayed on a page and when you left it. We can also determine at which point you have canceled your entries in a contact form (so-called conversion funnels).

Hotjar can also be used to obtain direct feedback from website visitors. This function serves to improve the website operator's website.

Hotjar uses cookies. Cookies are small text files that are stored on your computer and saved by your browser. They serve to make our offer more user-friendly, more effective and safer. These cookies can be used to determine whether this website was visited with a specific device or whether the Hotjar functions have been deactivated for the browser in question. Hotjar cookies remain on your device until you delete them.

You can set your browser to always inform you about established cookies, to decide case by case if you accept the cookies or generally exclude them as well as to activate the automatic delete of cookies when the browser is closed. However, the deactivation or rejection of cookies may restrict the functionality of our web offer.

The use of Hotjar and the storage of Hotjar cookies are based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

Disable Hotjar

If you would like to deactivate data collection by Hotjar, click on the following link and follow the instructions there: https://www.hotjar.com/opt-out

Please note that Hotjar must be deactivated separately for each browser or for each end device.

For more information about Hotjar and the data collected, please refer to Hotjar's privacy policy at the following link: https://www.hotjar.com/privacy

WordPress Stats

This website uses the WordPress tool Stats to statistically analyze visitor traffic. Provider is Automattic Inc., 60 29th Street #343, San Francisco, CA 94110-4929, USA.

WordPress Stats uses cookies, which are stored on your computer and allow an analysis of the use of the website. The information generated by the cookies about the use of this website is stored on servers in the USA. Your IP address will be anonymized after processing and before storage.

"WordPress Stats" cookies remain on your device until you delete them.

The storage of "WordPress Stats" cookies and the use of this analysis tool are based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the anonymized analysis of user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested (eg consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent is revocable at any time.

You can set your browser to always inform you about established cookies, to decide case by case if you accept the cookies or generally exclude them as well as to activate the automatic delete of cookies when the browser is closed. However, the deactivation or rejection of cookies may restrict the functionality of our web offer.

You may object to the collection and use of your data for the future by placing an opt-out cookie in your browser by clicking on this link: https://www.quantcast.com/opt-out/.

If you delete the cookies on your computer, you must set the opt-out cookie again.

Google Analytics Remarketing

This website uses the functions of Google Analytics Remarketing in connection with the cross-device functions of Google Ads and Google DoubleClick. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

This function makes it possible to link the advertising target groups created with Google Analytics Remarketing with the cross-device functions of Google Ads and Google DoubleClick. In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one device (e.g. mobile phone) can also be displayed on another of your devices (e.g. tablet or PC).

Once you have given your consent, Google will associate your web and app browsing history with your Google Account for this purpose. That way, any device that signs in to your Google Account can use the same personalized promotional messaging.

To support this feature, Google Analytics collects Google-authenticated IDs of users that are temporarily linked to our Google Analytics data to define and create audiences for cross-device ad promotion.

You can permanently object to cross-device remarketing / targeting by deactivating personalized advertising; follow this link: https://www.google.com/settings/ads/onweb/.

The aggregation of the recorded data in your Google account takes place exclusively on the basis of your consent, which you can give to Google or revoke (Art. 6 Para. 1 lit. a GDPR). In the case of data collection processes that are not merged in your Google account (e.g. because you do not have a Google account or have objected to the merging), the collection of data is based on Art. 6 Para. 1 lit. f GDPR. The legitimate interest arises from the fact that the website operator has an interest in the anonymised analysis of the website visitors for advertising purposes.

For more information and the Google Privacy Policy, go to: https://policies.google.com/technologies/ads?hl=de.

Google Ads and Google Conversion Tracking

This website uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

As part of Google Ads, we use so-called conversion tracking. When you click on an ad served by Google, a conversion tracking cookie is set. Cookies are small text files that the Internet browser stores on the user's computer. These cookies lose their validity after 30 days and are not used for personal identification of users. If the user visits certain pages on this website and the cookie has not expired yet, Google and we may recognize that the user clicked on the ad and was redirected to this page.

Each Google Ads customer receives a different cookie. Cookies can not be tracked through Google Ads customer sites. The information gathered using the conversion cookie is used to generate conversion statistics for Google Ads customers who have opted for conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a conversion tracking tag page. However, they do not receive any information that personally identifies users. If you do not want to participate in tracking, you can opt-out of this by easily disabling the Google Conversion Tracking cookie through its Internet browser under User Preferences. You will not be included in the conversion tracking statistics.

The storage of "conversion cookies" and the use of this tracking tool are based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested (eg consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent is revocable at any time.

For more information about Google Ads and Google Conversion Tracking, see the Google Privacy Policy: https://policies.google.com/privacy?hl=de.

You can set your browser to always inform you about established cookies, to decide case by case if you accept the cookies or generally exclude them as well as to activate the automatic delete of cookies when the browser is closed. However, the deactivation or rejection of cookies may restrict the functionality of our web offer.

Google DoubleClick

This website uses functions of Google DoubleClick. The provider is Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA, (hereinafter “DoubleClick”).

DoubleClick is used to show you interest-based advertisements across the entire Google advertising network. With the help of DoubleClick, the advertisements can be tailored to the interests of the respective viewer. For example, our advertising can be displayed in Google search results or in advertising banners connected to DoubleClick.

In order to be able to display interest-based advertising to users, DoubleClick must be able to recognize the respective viewer. For this purpose, a cookie is stored in the user's browser, behind which the websites visited by the user, clicks and various other information are stored. This information is combined into a pseudonymous user profile in order to display interest-based advertising to the user concerned.

Google DoubleClick is used in the interest of targeted advertising measures. This represents a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. If a corresponding consent was requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

You can set your browser so that it no longer stores cookies. However, this may involve a restriction on the accessible website functions. It is also pointed out that DoubleClick may also use other technologies to create user profiles. Disabling cookies therefore does not guarantee that user profiles will no longer be created.

For more information on how to object to the advertisements displayed by Google, see the following links: https://policies.google.com/technologies/ads and https://adssettings.google.com/authenticated.

Facebook Pixel

This website uses Facebook's visitor action pixel to measure conversion. This service is provided by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the data collected is also transferred to the USA and other third countries.

These allow the behavior of site visitors to be tracked after they click on a Facebook ad to reach the provider's website. This allows an analysis of the effectiveness of Facebook advertisements for statistical and market research purposes and their future optimization.

The data collected is anonymous to us as operators of this website and we cannot use it to draw any conclusions about our users' identities. However, the data are stored and processed by Facebook, which may make a connection to your Facebook profile and which may use the data for its own advertising purposes, as stipulated in the <a href="https://www.facebook.com/about/privacy/" target="_blank">Facebook privacy policy</a>. This will allow Facebook to display ads both on Facebook and on third-party sites. We have no control over how this data is used. Facebook Data Use Policy can use. As a result, Facebook can enable ads to be displayed on Facebook and outside of Facebook. This use of data can not be influenced by us as the site operator.

Facebook pixels are used on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in effective advertising measures, including social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

Check out Facebook's privacy policy to learn more about protecting your privacy: https://de-de.facebook.com/about/privacy/.

You can also use the remarketing "Custom Audiences" feature in the Ads Settings section under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen deactivate. To do this, you must be logged in to Facebook.

If you do not have a Facebook account, you can opt out of usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: <a href="http://www.youronlinechoices.com/de/praferenzmanagement/" target="_blank">http://www.youronlinechoices.com/de/praferenzmanagement/</a>. http://www.youronlinechoices.com/de/praferenzmanagement/.

Criteo

This website uses functions from Criteo. The provider is Criteo SA, 32 Rue Blanche, 75009 Paris (hereinafter "Criteo").

Criteo is used to show you interest-based advertisements within the Criteo advertising network. Your interests are determined on the basis of your previous usage behavior. In doing so, Criteo records, for example, which products you have viewed, added to the shopping cart or bought. Further details on the data collected by Criteo can be found here: https://www.criteo.com/de/privacy/how-we-use-your-data/.

In order to be able to show you interest-based advertising, we or other Criteo partners must be able to recognize you. For this purpose, a cookie is stored on your device or a comparable identifier is used that links your user behavior with a pseudonymous user profile. You can find details on this in Criteo's data protection declaration at: https://www.criteo.com/de/privacy/.

Your personal data and the Criteo cookies stored in your browser are stored for a maximum of 13 months from the date of collection.

Criteo is used in the interest of targeted advertising. This represents a legitimate interest within the meaning of Art. 6 Paragraph 1 lit. . 6 lit. a GDPR; the consent can be revoked at any time.

You can set your browser so that it no longer stores cookies. However, this may restrict the website functions that can be accessed. It should also be noted that Criteo may also use other technologies to create user profiles. Switching off cookies therefore does not guarantee that user profiles will no longer be created.

Criteo and we are jointly responsible within the meaning of Art. 26 GDPR. An agreement on joint processing has been concluded between Criteo and us, the essential content of which Criteo describes under the following link: https://www.criteo.com/de/privacy/how-we-use-your-data/.

7. Newsletter

Newsletter data

If you would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter . Further data is not collected or only collected on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

We will, therefore, process any data you enter onto the contact form only with your consent per Art. 6 (1) (a) DSGVO. You can revoke consent to the storage of your data and email address as well as their use for sending the newsletter at any time, e.g. through the "unsubscribe" link in the newsletter. The data processed before we receive your request may still be legally processed.

The data deposited with us for the purpose of obtaining the newsletter will be stored by us or the newsletter service provider until the time of your removal from the newsletter and deleted from the newsletter distribution list after the newsletter has been canceled. Data stored for other purposes with us remain unaffected.

After your entry from the newsletter distribution list, your e-mail address with us or the newsletter service provider may be stored in a blacklist to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO). The storage in the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest.

MailChimp

This website uses the services of MailChimp for sending newsletters. Provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, 5000 Suite, Atlanta, GA 30308, USA.

MailChimp is a service with which, among other things, the sending of newsletters can be organized and analyzed. If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), these will be stored on MailChimp's servers in the USA.

MailChimp is certified under the EU-US Privacy Shield. The Privacy Shield is an agreement between the European Union (EU) and the US to ensure compliance with European privacy standards in the United States.

With the help of MailChimp we can analyze our newsletter campaigns. When you open an email sent with MailChimp, a file contained in the email (so-called web beacon) connects to the MailChimp servers in the USA. In this way it can be determined whether a newsletter message has been opened and which links have been clicked. Technical information is also recorded (e.g. time of access, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. They are used exclusively for the statistical analysis of newsletter campaigns. The results of these analyzes can be used to better adapt future newsletters to the interests of the recipients.

If you do not want analysis by MailChimp, unsubscribe from the newsletter. For this purpose, we provide a link in every newsletter message. Furthermore, you can unsubscribe from the newsletter directly on the website.

Data processing is based on Art. 6 (1) (a) DSGVO. You may revoke your consent at any time by unsubscribing to the newsletter. The data processed before we receive your request may still be legally processed.

The data deposited with us for the purpose of obtaining the newsletter will be stored by us or the newsletter service provider until the time of your removal from the newsletter and deleted from the newsletter distribution list after the newsletter has been canceled. Data stored for other purposes with us remain unaffected.

After your entry from the newsletter distribution list, your e-mail address with us or the newsletter service provider may be stored in a blacklist to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO). The storage in the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest.

For details, see the Privacy Policy of MailChimp at: https://mailchimp.com/legal/terms/.

8. Plugins and Tools

YouTube with enhanced privacy

This website includes videos from YouTube. Site operator is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

We use YouTube in enhanced privacy mode. This mode, according to YouTube, means that YouTube does not store information about visitors to this site before they watch the video. However, sharing data with YouTube partners is not necessarily excluded by the enhanced privacy mode. So, regardless of whether you watch a video, YouTube connects to the Google DoubleClick network.

Once you start a YouTube video on this site, you will be connected to the servers of YouTube. It tells the YouTube server which of our pages you've visited. If you are logged in to your YouTube account, YouTube will allow you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.

In addition, after launching a video, YouTube may store various cookies on your device. With the help of these cookies, YouTube can receive information about visitors to this website. This information is used, among other things, to capture video statistics, improve user-friendliness, and prevent fraud. The cookies remain on your device until you delete them.

If necessary, after the launch of a YouTube video, additional data processing operations may be triggered that we have no control over.

The use of YouTube is in the interest of an attractive presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO. If a corresponding consent has been requested (eg consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent is revocable at any time.

For more information about privacy on YouTube, see their privacy policy at: https://policies.google.com/privacy?hl=de.

Vimeo

This website uses plugins from the video portal Vimeo. Provider is Vimeo Inc., 555 West 18th Street, NY, New York 10011, USA.

If you visit one of our pages equipped with a Vimeo plugin, a connection to the Vimeo servers will be established. The Vimeo server is informed which of our pages you have visited. In addition, Vimeo obtains your IP address. This also applies if you are not logged in to Vimeo or do not have an account with Vimeo. The information collected by Vimeo is transmitted to the Vimeo server in the USA.

If you are logged into your Vimeo account, you enable Vimeo to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your Vimeo account.

The use of Vimeo is in the interest of an attractive presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO. If a corresponding consent has been requested (eg consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent is revocable at any time.

For more information on how to handle user data, see Vimeo's privacy policy at: https://vimeo.com/privacy.

Google Web Fonts

This site uses so-called web fonts provided by Google for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into your browser cache in order to display text and fonts correctly.

For this purpose, the browser you are using must connect to the Google servers. This gives Google knowledge that this website was accessed via your IP address. Google WebFonts are used on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the uniform representation of the typeface on his website. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

If your browser does not support web fonts, a standard font will be used by your computer.

Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google's privacy policy at https://policies.google.com/privacy?hl=de.

Adobe fonts

This website uses Adobe web fonts for the uniform display of certain fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe).

When you visit this website, your browser loads the required fonts directly from Adobe in order to be able to display them correctly on your device. Your browser establishes a connection to the Adobe servers in the USA. As a result, Adobe learns that this website has been accessed via your IP address. According to Adobe, no cookies are stored when the fonts are provided.

Adobe is certified according to the EU-US Privacy Shield. The Privacy Shield is an agreement between the United States of America and the European Union that aims to ensure compliance with European data protection standards. You can find more information at: https://www.adobe.com/de/privacy/eudatatransfers.html.

The storage and analysis of the data takes place on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the uniform representation of the typeface on his website. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be withdrawn at any time.

You can find more information about Adobe Fonts at: https://www.adobe.com/de/privacy/policies/adobe-fonts.html.

You can find Adobe's privacy policy at: https://www.adobe.com/de/privacy/policy.html

Google Maps

This site uses the mapping service Google Maps via an API. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

To use Google Maps, it is necessary to save your IP address. This information is generally transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer.

The use of Google Maps is in the interest of making our website appealing and to facilitate the location of places specified by us on the website. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

Further information about handling user data, can be found in the data protection declaration of Google at https://policies.google.com/privacy?hl=de.

OpenStreetMap

We use the map service of OpenStreetMap (OSM). Provider is the Open Street Map Foundation (OSMF), 132 Maney Hill Road, Sutton Coldfield, West Midlands, B72 1JU, United Kingdom.

When you visit a website that includes OpenStreetMap, your IP address and other information about your behavior on this website will be forwarded to the OSMF. OpenStreetMap may store cookies in your browser. These are text files that are stored on your computer and that allow an analysis of the use of the website by you. You can prevent the storage of cookies by a corresponding setting of your browser software; however, we point out that in this case you may not be able to use all the functions of this website in full.

Your location can also be recorded if you do this in your device settings - e.g. B. on your mobile phone. The provider of this site has no influence on this data transfer. Details can be found in the data protection declaration of OpenStreetMap under the following link: https://wiki.osmfoundation.org/wiki/Privacy_Policy.

OpenStreetMap is used in the interest of an attractive presentation of our online offers and an easy findability of the places we have indicated on the website. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

SoundCloud

Plugins of the social network SoundCloud (SoundCloud Limited, Berners House, 47-48 Berners Street, London W1T 3NF, Great Britain) can be integrated on this website. You can recognize the SoundCloud plugins by the SoundCloud logo on the relevant pages.

When you visit this website, a direct connection is established between your browser and the SoundCloud server after activating the plug-in. SoundCloud receives the information that you have visited this website with your IP address. If you click the “Like” or “Share” button while you are logged into your SoundCloud user account, you can link and / or share the content of this website with your SoundCloud profile. This enables SoundCloud to assign your visit to this website to your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or their use by SoundCloud.

The data are stored and analyzed on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the widest possible visibility in social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

Further information can be found in the SoundCloud data protection declaration at: https://soundcloud.com/pages/privacy.

If you do not want SoundCloud to assign your visit to this website to your SoundCloud user account, please log out of your SoundCloud user account before activating the content of the SoundCloud plug-in.

Spotify

Functions of the music service Spotify are integrated into this website. The provider is Spotify AB, Birger Jarlsgatan 61, 113 56 Stockholm in Sweden. You can recognize the Spotify plugins by the green logo on this website. You can find an overview of the Spotify plugins at: https://developer.spotify.com.

This enables a direct connection to be established between your browser and the Spotify server when you visit this website via the plugin. Spotify receives the information that you have visited this website with your IP address. If you click the Spotify button while you are logged in to your Spotify account, you can link the content of this website to your Spotify profile. This enables Spotify to associate your visit to this website with your user account.

The storage and analysis of the data is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the appealing acoustic design of his website. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

For more information, please see Spotify's privacy policy: https://www.spotify.com/de/legal/privacy-policy/.

If you do not want Spotify to be able to assign your visit to this website to your Spotify user account, please log out of your Spotify user account.

Zendesk

We use the Zendesk CRM system to process user inquiries. The provider is Zendesk, Inc, 1019 Market Street in San Francisco, CA 94103 USA.

We use Zendesk to process your inquiries quickly and efficiently.

The storage and analysis of the data takes place on the basis of Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in communication with customers and interested parties that is as uncomplicated as possible. If a corresponding consent has been requested (e.g. consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 Paragraph 1 lit. a GDPR; the consent can be revoked at any time.

As a US provider, Zendesk is Privacy Shield certified and thus undertakes to comply with EU data protection law. In addition, we have concluded a data processing agreement (DPA) with Zendesk. This ensures that Zendesk only uses the user data within the framework of EU data protection standards for processing requests and does not pass them on to third parties.

You can only send inquiries by specifying your email address and without specifying your name.

You can also send inquiries to us via our chat window. In this case, we will save your IP address in addition to your chat messages. You do not need to enter your name for the chat.

The data you enter in the contact form or in the chat will remain with us until you ask us to delete it or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions - especially retention periods - remain unaffected.

If you do not agree to our processing of your request via Zendesk, you can alternatively communicate with us by e-mail, telephone or fax.

Further information can be found in Zendesk's data protection declaration: https://www.zendesk.de/company/customers-partners/privacy-policy/.

9. Online marketing and affiliate programs

Amazon affiliate program

The operators of this website participate in the Amazon EU partner program. This website incorporates advertisements and links to the Amazon.de page through Amazon, where we can earn money by reimbursing advertising costs. Amazon uses cookies to track the origin of the orders. This enables Amazon to recognize that you have clicked the partner link on this website.

The storage and analysis of the data is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in the correct calculation of his affiliate remuneration. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a GDPR; the consent can be revoked at any time.

For more information about Amazon's data usage, please refer to the Amazon Privacy Policy: https://www.amazon.de/gp/help/customer/display.html/ref=footer_privacy?ie=UTF8&nodeId=3312401.

10. eCommerce and payment providers

Processing of data (customer and contract data)

We collect, process and use personal data only insofar as they are necessary for the establishment, content or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b DSGVO, which allows the processing of data for the performance of a contract or precontractual measures. Personal data on the use of this website (usage data), we collect, process and use only to the extent necessary to enable the user to use the service or to bill.

Collected customer data shall be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.

Data transmitted when entering into a contract with online shops, retailers, and mail order

We transmit personally identifiable data to third parties only to the extent required to fulfill the terms of your contract, for example, to companies entrusted to deliver goods to your location or banks entrusted to process your payments. Your data will not be transmitted for any other purpose unless you have given your express permission to do so. Your data will not be disclosed to third parties for advertising purposes without your express consent.

The basis for data processing is Art. 6 Paragraph 1 lit. b GDPR, which allows the processing of data to fulfill a contract or pre-contractual measures.

Data transfer at the conclusion of the contract for services and digital content

We only transfer personal data to third parties if this is necessary in the course of the contract processing, for example to the credit institution commissioned with payment processing.

A further transmission of the data is not possible or only if you have expressly agreed to the transmission. Your data will not be passed on to third parties without express consent, for example for advertising purposes.

The basis for data processing is Art. 6 Paragraph 1 lit. b GDPR, which allows the processing of data to fulfill a contract or pre-contractual measures.

Stripe

On this website we offer payment with the services of Stripe. The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter "Stripe").

If you pay via Stripe, your payment data will be forwarded to Stripe via an interface on our site to make the payment. You can find details on this in Stripe's data protection declaration at the following link: https://stripe.com/de/privacy.

The transmission of your data to Stripe is based on Art. 6 Para. 1 lit. b GDPR (contract processing) and on the basis of our legitimate interest in the use of reliable and secure payment processes (Art. 6 Para. 1 lit.

PayPal

On this website we offer payment via PayPal, among other things. The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).

If you select payment via PayPal, the payment data you provide will be supplied to PayPal based on Art. XNUMX (XNUMX) (a) (Consent) and Art. XNUMX (XNUMX) (b) DSGVO (Processing for contract purposes). You have the option to revoke your consent at any time with future effect. It does not affect the processing of data previously collected.

If you select payment via PayPal, the payment data you provide will be supplied to PayPal based on Art. 6 (1) (a) (Consent) and Art. 6 (1) (b) DSGVO (Processing for contract purposes). You have the option to revoke your consent at any time with future effect. It does not affect the processing of data previously collected.

Klarna

On this website we offer, among other things, payment with Klarna services. The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna").

Klarna offers various payment options (e.g. installment purchase). If you decide to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. You can read details on this in Klarna's data protection declaration under the following link: https://www.klarna.com/de/datenschutz/.

Klarna uses cookies to optimize the use of the Klarna Checkout solution. The optimization of the checkout solution constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO. Cookies are small text files that are stored on your device and cause no damage. They remain on your device until you delete them. For details on the use of Klarna cookies, please refer to the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.

The transmission of your data to Klarna is based on Art. 6 para. 1 lit. a DSGVO (consent) and Art. 6 para. 1 lit. b DSGVO (processing to fulfill a contract). You have the opportunity to revoke your consent to data processing at any time. A revocation does not affect the effectiveness of historical data processing operations.

Sofortüberweisung

On this website we offer payment by "Sofortüberweisung". The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter “Sofort GmbH”).

With the help of the "Sofortüberweisung" procedure, we receive a payment confirmation from Sofort GmbH in real time and can immediately start fulfilling our obligations.

If you have opted for the "Sofortüberweisung" payment method, send the PIN and a valid TAN to Sofort GmbH, with which they can log into your online banking account. Sofort GmbH automatically checks your account balance after logging in and carries out the transfer to us using the TAN you provided. Then she immediately sends us a transaction confirmation. After logging in, your sales, the credit line of the overdraft facility and the existence of other accounts and their holdings are also automatically checked.

In addition to the PIN and the TAN, the payment data entered by you as well as personal data will be transmitted to Sofort GmbH. The personal data are first name, surname, address, telephone number (s), e-mail address, IP address and possibly further data required for payment processing. The transmission of this data is necessary to establish your identity beyond doubt and to prevent fraud.

The transmission of your data to Sofort GmbH is based on Art. 6 para. 1 lit. a DSGVO (consent) and Art. 6 para. 1 lit. b DSGVO (processing to fulfill a contract). You have the option to revoke your consent to data processing at any time. Revocation does not affect the effectiveness of historical data processing operations.

For details on payment with Sofortüberweisung see the following links: https://www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/.

Paydirekt

On this website we offer payment via Paydirekt, among other things. The provider of this payment service is Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main, Germany (hereinafter “Paydirekt”).

If you make the payment using Paydirekt, Paydirekt collects various transaction data and forwards them to the bank with which you are registered with Paydirekt. In addition to the data required for payment, Paydirekt may collect additional data such as B. Delivery address or individual items in the shopping cart.

Paydirekt then authenticates the transaction using the authentication procedure stored with the bank. The payment amount will then be transferred from your account to our account. Neither we nor third parties have access to your account information.

For more information, see the terms and conditions and privacy policy of Paydirekt at https://www.paydirekt.de/agb/index.html.

11. Own services

Handling applicant data

We offer you the opportunity to apply to us (e.g. by email, post or via the online application form). In the following, we will inform you about the scope, purpose and use of your personal data collected during the application process. We assure you that the collection, processing and use of your data is carried out in accordance with the applicable data protection law and all other statutory provisions and that your data will be treated with strict confidentiality.

Scope and purpose of the data collection

If you send us an application, we process your related personal data (e.g. contact and communication data, application documents, notes in the context of job interviews, etc.), insofar as this is necessary to decide on the establishment of an employment relationship. The legal basis for this is § 26 BDSG-new according to German law (initiation of an employment relationship), Art. 6 Para. 1 lit. b GDPR (general contract initiation) and - if you have given your consent - Art. 6 Para. 1 lit. a GDPR. The consent can be revoked at any time. Your personal data will only be passed on to persons within our company who are involved in processing your application.

If the application is successful, the data submitted by you will be published on the basis of § 26 BDSG-new and Art. 6 para. 1 lit. b DSGVO for the purpose of carrying out the employment relationship in our data processing systems.

Retention period of the data

If we are unable to make you a job offer, reject a job offer or withdraw your application, we reserve the right to uphold the data transmitted by you based on our legitimate interests (Art. 6 Para. 1 lit. f GDPR) for up to 6 months to be kept with us from the end of the application process (rejection or withdrawal of the application). The data is then deleted and the physical application documents are destroyed. The storage serves in particular for verification purposes in the event of a legal dispute. If it can be seen that the data will be required after the 6-month period has expired (e.g. due to an impending or pending legal dispute), deletion will only take place if the purpose for further storage no longer applies.

Longer storage can also take place if you have given the appropriate consent (Art. 6 Para. 1 lit. a GDPR) or if there are legal retention obligations to prevent deletion.

Inclusion in the applicant pool

If we do not make you a job offer, you may have the opportunity to be included in our applicant pool. In the case of admission, all documents and information from the application are transferred to the applicant pool to contact you in the event of suitable vacancies.

Admission to the pool of applicants takes place exclusively on the basis of your express consent (Art. 6 Para. 1 lit. a GDPR). The submission of consent is voluntary and has no relation to the ongoing application process. The person concerned can withdraw their consent at any time. In this case, the data from the applicant pool will be irrevocably deleted, provided there are no legal reasons for storage.

The data from the applicant pool will be irrevocably deleted at the latest two years after consent has been given.