Privacy Policy
Version of 24 June 2019

Privacy Policy

Version of 24 June 2019

Please note: this English text is a translation provided for your convenience. Only the German version of this document is legally binding. In the event of any discrepancy or ambiguity between the two versions, the German version shall prevail. You can read it by switching this site to German.

We are delighted that you are interested in our company. Data protection is of a particularly high priority for the management of SWINDI GmbH. Using the websites of SWINDI GmbH is generally possible without providing any personal data at all. However, if a data subject wishes to make use of particular services offered by our company through our website, processing personal data may become necessary. Where processing personal data is necessary and there is no legal basis for such processing, we generally obtain the data subject's consent.

The processing of personal data — a data subject's name, address, email address or telephone number, for example — is always carried out in accordance with the General Data Protection Regulation and in compliance with the country-specific data protection provisions applicable to SWINDI GmbH. Through this privacy policy our company wishes to inform the public about the nature, scope and purpose of the personal data we collect, use and process. This privacy policy also informs data subjects of the rights to which they are entitled.

As the controller, SWINDI GmbH has implemented numerous technical and organisational measures to ensure the most complete protection possible of the personal data processed through this website. Nevertheless, internet-based data transmissions can in principle have security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, by telephone for example.

1. Definitions

The privacy policy of SWINDI GmbH is based on the terms used by the European legislator when adopting the General Data Protection Regulation (GDPR). Our privacy policy should be easy to read and understand, both for the public and for our customers and business partners. To ensure this, we would like to explain the terms used in advance.

In this privacy policy we use, among others, the following terms:

  • a) Personal data

    Personal data means any information relating to an identified or identifiable natural person (hereinafter the „data subject“). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

  • b) Data subject

    Data subject means any identified or identifiable natural person whose personal data is processed by the controller.

  • c) Processing

    Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • d) Restriction of processing

    Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.

  • e) Profiling

    Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

  • f) Pseudonymisation

    Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

  • g) Controller or controller responsible for the processing

    Controller or controller responsible for the processing means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

  • h) Processor

    Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

  • i) Recipient

    Recipient means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

  • j) Third party

    Third party means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

  • k) Consent

    Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.

2. Name and address of the controller

The controller for the purposes of the General Data Protection Regulation, other data protection laws applicable in Member States of the European Union and other provisions related to data protection is:

SWINDI GmbH

Talstr. 16

71144 Steinenbronn

Germany

Phone: 07031 / 304 806-0

Email: info@swindi.de

Website: swindi.de

3. Cookies

The websites of SWINDI GmbH use cookies. Cookies are text files that are placed and stored on a computer system via an internet browser.

Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a character string through which websites and servers can be assigned to the specific internet browser in which the cookie was stored. This allows the websites and servers visited to distinguish the data subject's individual browser from other internet browsers that contain other cookies. A specific internet browser can be recognised and identified via the unique cookie ID.

Through the use of cookies, SWINDI GmbH can provide the users of this website with more user-friendly services that would not be possible without cookies being set.

By means of a cookie, the information and offers on our website can be optimised with the user in mind. As already mentioned, cookies allow us to recognise the users of our website. The purpose of this recognition is to make it easier for users to use our website. The user of a website that uses cookies does not, for example, have to enter their access credentials again each time they visit the site, because this is handled by the website and the cookie stored on the user's computer system. Another example is the cookie of a shopping basket in an online shop. The online shop uses a cookie to remember the items a customer has placed in the virtual shopping basket.

The data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If the data subject deactivates the setting of cookies in the internet browser used, not all functions of our website may be fully usable.

4. Collection of general data and information

Each time the website is accessed by a data subject or an automated system, the website of SWINDI GmbH collects a series of general data and information. This general data and information is stored in the server log files. The following may be collected: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrer), (4) the sub-pages accessed on our website via an accessing system, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used to avert danger in the event of attacks on our information technology systems.

When using this general data and information, SWINDI GmbH does not draw any conclusions about the data subject. Rather, this information is needed in order to (1) deliver the content of our website correctly, (2) optimise the content of our website and the advertising for it, (3) ensure the long-term functionality of our information technology systems and the technology of our website, and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack. SWINDI GmbH therefore analyses this anonymously collected data and information statistically on the one hand, and with the aim of increasing data protection and data security within our company on the other, in order ultimately to ensure an optimum level of protection for the personal data we process. The anonymous data in the server log files is stored separately from all personal data provided by a data subject.

5. Registration on our website

The data subject has the option of registering on the controller's website by providing personal data. Which personal data is transmitted to the controller in the process follows from the respective input form used for registration. The personal data entered by the data subject is collected and stored exclusively for internal use by the controller and for the controller's own purposes. The controller may arrange for the data to be passed on to one or more processors, a parcel service for example, which likewise uses the personal data exclusively for internal use attributable to the controller.

Registration on the controller's website also stores the IP address assigned by the data subject's internet service provider (ISP), together with the date and time of registration. This data is stored because it is the only way to prevent misuse of our services and because, where necessary, it makes it possible to investigate criminal offences that have been committed. To that extent, storing this data is necessary to protect the controller. This data is generally not passed on to third parties unless there is a legal obligation to do so or the disclosure serves the purpose of criminal prosecution.

The registration of the data subject, with the voluntary provision of personal data, serves to enable the controller to offer the data subject content or services which, by their nature, can only be offered to registered users. Registered persons are free to change the personal data provided at registration at any time, or to have it deleted entirely from the controller's data records.

The controller shall at any time, on request, provide each data subject with information about which personal data is stored about them. Furthermore, the controller shall correct or delete personal data at the request or indication of the data subject, provided that no statutory retention obligations conflict with this. All of the controller's employees are available to the data subject as contact persons in this respect.

6. Subscription to our newsletter

On the website of SWINDI GmbH, users are given the opportunity to subscribe to our company's newsletter. Which personal data is transmitted to the controller when the newsletter is ordered follows from the input form used for this purpose.

SWINDI GmbH informs its customers and business partners at regular intervals about the company's offers by means of a newsletter. Our company's newsletter can generally only be received by the data subject if (1) the data subject has a valid email address and (2) the data subject registers for the newsletter. For legal reasons, a confirmation email is sent using the double opt-in procedure to the email address first entered by a data subject for the newsletter. This confirmation email serves to verify that the owner of the email address, as the data subject, has authorised receipt of the newsletter.

When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the computer system used by the data subject at the time of registration, together with the date and time of registration. Collecting this data is necessary in order to be able to trace any (possible) misuse of a data subject's email address at a later point in time, and it therefore serves the legal protection of the controller.

The personal data collected in the course of registering for the newsletter is used exclusively to send our newsletter. Furthermore, newsletter subscribers may be informed by email where this is necessary for the operation of the newsletter service or a related registration, as might be the case with changes to the newsletter offering or to the technical circumstances. The personal data collected in the course of the newsletter service is not passed on to third parties. The data subject may cancel the subscription to our newsletter at any time. The consent to the storage of personal data which the data subject has given us for sending the newsletter may be withdrawn at any time. For the purpose of withdrawing consent, a corresponding link can be found in every newsletter. It is also possible to unsubscribe from the newsletter at any time directly on the controller's website, or to notify the controller of this in another way.

7. Newsletter tracking

The newsletters of SWINDI GmbH contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in emails sent in HTML format in order to enable log file recording and log file analysis. This makes it possible to carry out a statistical evaluation of the success or failure of online marketing campaigns. On the basis of the embedded tracking pixel, SWINDI GmbH can recognise whether and when an email was opened by a data subject, and which links contained in the email were followed by the data subject.

Personal data collected via the tracking pixels contained in the newsletters is stored and evaluated by the controller in order to optimise the sending of newsletters and to tailor the content of future newsletters even better to the interests of the data subject. This personal data is not passed on to third parties. Data subjects are entitled at any time to withdraw the separate declaration of consent given for this purpose via the double opt-in procedure. Following withdrawal, this personal data is deleted by the controller. SWINDI GmbH automatically interprets unsubscribing from the newsletter as a withdrawal.

8. Contact option via the website

Owing to statutory requirements, the website of SWINDI GmbH contains information that enables quick electronic contact with our company as well as direct communication with us, which also includes a general address for so-called electronic mail (email address). If a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject is stored automatically. Such personal data transmitted on a voluntary basis by a data subject to the controller is stored for the purposes of processing the enquiry or contacting the data subject. This personal data is not passed on to third parties.

9. Comment function in the blog on the website

SWINDI GmbH offers users the opportunity to leave individual comments on particular blog posts in a blog located on the controller's website. A blog is a portal maintained on a website, usually publicly viewable, in which one or more persons, known as bloggers or web bloggers, can post articles or write down thoughts in so-called blog posts. Blog posts can generally be commented on by third parties.

If a data subject leaves a comment in the blog published on this website, then in addition to the comments left by the data subject, information about the time the comment was entered and about the user name (pseudonym) chosen by the data subject is also stored and published. Furthermore, the IP address assigned by the data subject's internet service provider (ISP) is logged. The IP address is stored for security reasons and in case the data subject infringes the rights of third parties or posts unlawful content through a comment. Storing this personal data is therefore in the controller's own interest, so that the controller could exculpate itself in the event of an infringement of rights. This collected personal data is not passed on to third parties unless such disclosure is required by law or serves the controller's legal defence.

10. Subscription to comments in the blog on the website

Comments made in the blog of SWINDI GmbH can generally be subscribed to by third parties. In particular, a commenter has the option of subscribing to the comments following their own comment on a particular blog post.

If a data subject decides to take up the option of subscribing to comments, the controller sends an automatic confirmation email in order to verify, using the double opt-in procedure, that the owner of the email address given really did choose this option. The option of subscribing to comments can be ended at any time.

11. Routine erasure and blocking of personal data

The controller processes and stores the data subject's personal data only for the period necessary to achieve the purpose of storage, or where this has been provided for by the European legislator or another legislator in laws or regulations to which the controller is subject.

If the purpose of storage no longer applies, or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data is routinely blocked or erased in accordance with the statutory provisions.

12. Rights of the data subject

  • a) Right of confirmation

    Every data subject has the right granted by the European legislator to obtain from the controller confirmation as to whether or not personal data concerning them is being processed. If a data subject wishes to make use of this right of confirmation, they may contact an employee of the controller at any time.

  • b) Right of access

    Every person affected by the processing of personal data has the right granted by the European legislator to obtain from the controller, free of charge and at any time, information about the personal data stored about them and a copy of that information. The European legislator has furthermore granted the data subject access to the following information:

    • the purposes of the processing
    • the categories of personal data being processed
    • the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations
    • where possible, the envisaged period for which the personal data will be stored or, if this is not possible, the criteria used to determine that period
    • the existence of the right to request rectification or erasure of personal data concerning them, or restriction of processing by the controller, or to object to such processing
    • the existence of the right to lodge a complaint with a supervisory authority
    • where the personal data are not collected from the data subject: any available information as to their source
    • the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR and — at least in those cases — meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject

    The data subject also has a right to obtain information as to whether personal data have been transferred to a third country or to an international organisation. Where that is the case, the data subject has the right to be informed of the appropriate safeguards relating to the transfer.

    If a data subject wishes to make use of this right of access, they may contact an employee of the controller at any time.

  • c) Right to rectification

    Every person affected by the processing of personal data has the right granted by the European legislator to obtain the rectification without undue delay of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

    If a data subject wishes to make use of this right to rectification, they may contact an employee of the controller at any time.

  • d) Right to erasure (right to be forgotten)

    Every person affected by the processing of personal data has the right granted by the European legislator to obtain from the controller the erasure of personal data concerning them without undue delay, where one of the following grounds applies and insofar as the processing is not necessary:

    • The personal data were collected or otherwise processed for purposes for which they are no longer necessary.
    • The data subject withdraws the consent on which the processing was based pursuant to point (a) of Article 6(1) GDPR or point (a) of Article 9(2) GDPR, and there is no other legal ground for the processing.
    • The data subject objects to the processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) GDPR.
    • The personal data have been unlawfully processed.
    • The personal data must be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject.
    • The personal data have been collected in relation to the offer of information society services referred to in Article 8(1) GDPR.

    Where one of the grounds set out above applies and a data subject wishes to arrange for the erasure of personal data stored by SWINDI GmbH, they may contact an employee of the controller at any time. The employee of SWINDI GmbH will arrange for the erasure request to be complied with without undue delay.

    Where the personal data have been made public by SWINDI GmbH and our company as controller is obliged pursuant to Article 17(1) GDPR to erase the personal data, SWINDI GmbH shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers processing the published personal data that the data subject has requested the erasure by those other controllers of any links to, or copies or replications of, that personal data, insofar as the processing is not necessary. The employee of SWINDI GmbH will arrange what is necessary in each individual case.

  • e) Right to restriction of processing

    Every person affected by the processing of personal data has the right granted by the European legislator to obtain from the controller restriction of processing where one of the following applies:

    • The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data.
    • The processing is unlawful, the data subject opposes the erasure of the personal data and requests the restriction of their use instead.
    • The controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims.
    • The data subject has objected to processing pursuant to Article 21(1) GDPR pending the verification whether the legitimate grounds of the controller override those of the data subject.

    Where one of the conditions set out above is met and a data subject wishes to request the restriction of personal data stored by SWINDI GmbH, they may contact an employee of the controller at any time. The employee of SWINDI GmbH will arrange for the restriction of processing.

  • f) Right to data portability

    Every person affected by the processing of personal data has the right granted by the European legislator to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format. They also have the right to transmit that data to another controller without hindrance from the controller to which the personal data were provided, where the processing is based on consent pursuant to point (a) of Article 6(1) GDPR or point (a) of Article 9(2) GDPR, or on a contract pursuant to point (b) of Article 6(1) GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

    Furthermore, in exercising their right to data portability pursuant to Article 20(1) GDPR, the data subject has the right to have the personal data transmitted directly from one controller to another, where technically feasible and where doing so does not adversely affect the rights and freedoms of others.

    To assert the right to data portability, the data subject may contact an employee of SWINDI GmbH at any time.

  • g) Right to object

    Every person affected by the processing of personal data has the right granted by the European legislator to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them which is based on point (e) or (f) of Article 6(1) GDPR. This also applies to profiling based on those provisions.

    In the event of an objection, SWINDI GmbH shall no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims.

    Where SWINDI GmbH processes personal data for direct marketing purposes, the data subject has the right to object at any time to the processing of the personal data for such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If the data subject objects to SWINDI GmbH processing for direct marketing purposes, SWINDI GmbH will no longer process the personal data for those purposes.

    In addition, the data subject has the right, on grounds relating to their particular situation, to object to the processing of personal data concerning them which is carried out at SWINDI GmbH for scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) GDPR, unless such processing is necessary for the performance of a task carried out for reasons of public interest.

    To exercise the right to object, the data subject may contact any employee of SWINDI GmbH directly, or any other employee. The data subject is also free, in the context of the use of information society services and notwithstanding Directive 2002/58/EC, to exercise their right to object by automated means using technical specifications.

  • h) Automated individual decision-making, including profiling

    Every person affected by the processing of personal data has the right granted by the European legislator not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning them or similarly significantly affects them, provided that the decision (1) is not necessary for entering into, or performance of, a contract between the data subject and the controller, or (2) is not authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, or (3) is not based on the data subject's explicit consent.

    If the decision (1) is necessary for entering into, or performance of, a contract between the data subject and the controller, or (2) is based on the data subject's explicit consent, SWINDI GmbH shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision.

    If the data subject wishes to assert rights concerning automated decisions, they may contact an employee of the controller at any time.

  • i) Right to withdraw consent under data protection law

    Every person affected by the processing of personal data has the right granted by the European legislator to withdraw consent to the processing of personal data at any time.

    If the data subject wishes to assert their right to withdraw consent, they may contact an employee of the controller at any time.

13. Data protection provisions concerning the use of affilinet

The controller has integrated components of the company affilinet on this website. affilinet is a German affiliate network offering affiliate marketing.

Affiliate marketing is an internet-based form of distribution that enables commercial operators of websites, so-called merchants or advertisers, to display advertising — usually remunerated through click or sale commissions — on third-party websites, that is, with distribution partners also known as affiliates or publishers. The merchant makes an advertising medium available through the affiliate network, that is, an advertising banner or other suitable means of internet advertising, which an affiliate then embeds on their own websites or promotes through other channels such as keyword advertising or email marketing.

The operating company of affilinet is affilinet GmbH, Sapporobogen 6-8, 80637 Munich, Germany.

affilinet sets a cookie on the data subject's information technology system. What cookies are has already been explained above. affilinet's tracking cookie does not store any personal data. Only the identification number of the affiliate — that is, the partner referring the potential customer — and the reference number of the visitor to a website and of the advertising medium clicked on are stored. The purpose of storing this data is the handling of commission payments between a merchant and the affiliate, which are settled through the affiliate network, that is, affilinet.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent affilinet from setting a cookie on the data subject's information technology system. In addition, cookies already set by affilinet can be deleted at any time via an internet browser or other software programs.

affilinet's applicable data protection provisions can be found at https://www.affili.net/de/footeritem/datenschutz.

14. Data protection provisions concerning the use of Facebook

The controller has integrated components of the company Facebook on this website. Facebook is a social network.

A social network is a social meeting place operated on the internet, an online community that generally allows users to communicate with one another and to interact in virtual space. A social network can serve as a platform for exchanging opinions and experiences, or it allows the internet community to provide personal or company-related information. Facebook allows users of the social network, among other things, to create private profiles, upload photos and network via friend requests.

The operating company of Facebook is Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. If a data subject lives outside the USA or Canada, the controller responsible for processing personal data is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Each time one of the individual pages of this website operated by the controller is accessed and on which a Facebook component (Facebook plug-in) has been integrated, the internet browser on the data subject's information technology system is automatically prompted by the respective Facebook component to download a representation of the corresponding Facebook component from Facebook. A complete overview of all Facebook plug-ins can be found at https://developers.facebook.com/docs/plugins/?locale=de_DE. In the course of this technical procedure, Facebook learns which specific sub-page of our website the data subject is visiting.

If the data subject is logged in to Facebook at the same time, Facebook recognises which specific sub-page of our website the data subject is visiting each time our website is accessed by the data subject, and for the entire duration of their stay on our website. This information is collected by the Facebook component and assigned by Facebook to the data subject's respective Facebook account. If the data subject activates one of the Facebook buttons integrated on our website — the „Like“ button, for example — or if the data subject submits a comment, Facebook assigns this information to the data subject's personal Facebook user account and stores this personal data.

Facebook always receives information via the Facebook component that the data subject has visited our website whenever the data subject is logged in to Facebook at the time of accessing our website; this happens regardless of whether the data subject clicks the Facebook component or not. If the data subject does not want such information to be transmitted to Facebook, they can prevent the transmission by logging out of their Facebook account before accessing our website.

The data policy published by Facebook, available at https://de-de.facebook.com/about/privacy/, provides information about the collection, processing and use of personal data by Facebook. It also explains which settings Facebook offers to protect the data subject's privacy. In addition, various applications are available that make it possible to suppress data transmission to Facebook. Such applications can be used by the data subject to suppress data transmission to Facebook.

15. Data protection provisions concerning the use of Google AdSense

The controller has integrated Google AdSense on this website. Google AdSense is an online service through which advertising can be placed on third-party sites. Google AdSense is based on an algorithm that selects the advertisements displayed on third-party sites to match the content of the respective third-party site. Google AdSense permits interest-based targeting of the internet user, implemented by generating individual user profiles.

The operating company of the Google AdSense component is Alphabet Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of the Google AdSense component is to embed advertisements on our website. Google AdSense sets a cookie on the data subject's information technology system. What cookies are has already been explained above. Setting the cookie enables Alphabet Inc. to analyse the use of our website. Each time one of the individual pages of this website operated by the controller is accessed and on which a Google AdSense component has been integrated, the internet browser on the data subject's information technology system is automatically prompted by the respective Google AdSense component to transmit data to Alphabet Inc. for the purposes of online advertising and the settlement of commissions. In the course of this technical procedure, Alphabet Inc. gains knowledge of personal data such as the data subject's IP address, which Alphabet Inc. uses, among other things, to trace the origin of visitors and clicks and subsequently to enable commission settlements.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Alphabet Inc. from setting a cookie on the data subject's information technology system. In addition, a cookie already set by Alphabet Inc. can be deleted at any time via the internet browser or other software programs.

Google AdSense also uses so-called tracking pixels. A tracking pixel is a miniature graphic embedded in websites to enable log file recording and log file analysis, allowing a statistical evaluation to be carried out. On the basis of the embedded tracking pixel, Alphabet Inc. can recognise whether and when a website was opened by a data subject and which links were clicked by the data subject. Tracking pixels serve, among other things, to evaluate the flow of visitors to a website.

Through Google AdSense, personal data and information — which also includes the IP address and is necessary for recording and settling the advertisements displayed — is transferred to Alphabet Inc. in the United States of America. This personal data is stored and processed in the United States of America. Alphabet Inc. may pass on the personal data collected through this technical procedure to third parties.

Google AdSense is explained in more detail at https://www.google.de/intl/de/adsense/start/.

16. Data protection provisions concerning the use of Google Remarketing

The controller has integrated Google Remarketing services on this website. Google Remarketing is a feature of Google AdWords that enables a company to display advertising to internet users who have previously visited the company's website. Integrating Google Remarketing therefore allows a company to create user-related advertising and consequently to display advertisements relevant to the internet user's interests.

The operating company of the Google Remarketing services is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of Google Remarketing is the display of advertising relevant to the user's interests. Google Remarketing allows us to display advertisements through the Google advertising network or to have them displayed on other websites, tailored to the individual needs and interests of internet users.

Google Remarketing sets a cookie on the data subject's information technology system. What cookies are has already been explained above. Setting the cookie enables Google to recognise the visitor to our website when they subsequently visit websites that are also members of the Google advertising network. Each time a website is accessed on which the Google Remarketing service has been integrated, the data subject's internet browser identifies itself automatically to Google. In the course of this technical procedure, Google gains knowledge of personal data such as the user's IP address or browsing behaviour, which Google uses, among other things, to display advertising relevant to their interests.

The cookie stores personal information, such as the websites visited by the data subject. Each time our websites are visited, personal data — including the IP address of the internet connection used by the data subject — is therefore transferred to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may pass on the personal data collected through this technical procedure to third parties.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Google from setting a cookie on the data subject's information technology system. In addition, a cookie already set by Google Analytics can be deleted at any time via the internet browser or other software programs.

The data subject also has the option of objecting to interest-based advertising by Google. To do so, the data subject must open the link www.google.de/settings/ads from each of the internet browsers they use and make the desired settings there.

Further information and Google's applicable data protection provisions can be found at https://www.google.de/intl/de/policies/privacy/.

17. Data protection provisions concerning the use of Google+

The controller has integrated the Google+ button as a component on this website. Google+ is a so-called social network. A social network is a social meeting place operated on the internet, an online community that generally allows users to communicate with one another and to interact in virtual space. A social network can serve as a platform for exchanging opinions and experiences, or it allows the internet community to provide personal or company-related information. Google+ allows users of the social network, among other things, to create private profiles, upload photos and network via friend requests.

The operating company of Google+ is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

Each time one of the individual pages of this website operated by the controller is accessed and on which a Google+ button has been integrated, the internet browser on the data subject's information technology system is automatically prompted by the respective Google+ button to download a representation of the corresponding Google+ button from Google. In the course of this technical procedure, Google learns which specific sub-page of our website the data subject is visiting. More detailed information about Google+ can be found at https://developers.google.com/+/.

If the data subject is logged in to Google+ at the same time, Google recognises which specific sub-page of our website the data subject is visiting each time our website is accessed by the data subject, and for the entire duration of their stay on our website. This information is collected by the Google+ button and assigned by Google to the data subject's respective Google+ account.

If the data subject activates one of the Google+ buttons integrated on our website and thereby submits a Google +1 recommendation, Google assigns this information to the data subject's personal Google+ user account and stores this personal data. Google stores the data subject's Google +1 recommendation and makes it publicly accessible in accordance with the terms the data subject has accepted in this respect. A Google +1 recommendation given by the data subject on this website is subsequently stored and processed, together with other personal data such as the name of the Google +1 account used by the data subject and the photo stored in it, in other Google services — for example the search results of the Google search engine, the data subject's Google account, or in other places such as websites or in connection with advertisements. Google is also able to link the visit to this website with other personal data stored at Google. Google further records this personal information for the purpose of improving or optimising Google's various services.

Google always receives information via the Google+ button that the data subject has visited our website whenever the data subject is logged in to Google+ at the time of accessing our website; this happens regardless of whether the data subject clicks the Google+ button or not.

If the data subject does not want personal data to be transmitted to Google, they can prevent such transmission by logging out of their Google+ account before accessing our website.

Further information and Google's applicable data protection provisions can be found at https://www.google.de/intl/de/policies/privacy/. Further information from Google on the Google +1 button can be found at https://developers.google.com/+/web/buttons-policy.

18. Data protection provisions concerning the use of Google AdWords

The controller has integrated Google AdWords on this website. Google AdWords is an internet advertising service that allows advertisers to place ads both in Google's search engine results and in the Google advertising network. Google AdWords allows an advertiser to define certain keywords in advance, by means of which an ad is displayed in Google's search engine results exclusively when the user retrieves a keyword-relevant search result with the search engine. In the Google advertising network, ads are distributed across topic-relevant websites by means of an automatic algorithm and in accordance with the keywords defined beforehand.

The operating company of the Google AdWords services is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of Google AdWords is to promote our website by displaying advertising relevant to users' interests on the websites of third-party companies and in the search engine results of the Google search engine, and to display third-party advertising on our website.

If a data subject reaches our website via a Google ad, Google places a so-called conversion cookie on the data subject's information technology system. What cookies are has already been explained above. A conversion cookie expires after thirty days and is not used to identify the data subject. The conversion cookie is used, provided it has not yet expired, to trace whether particular sub-pages — the shopping basket of an online shop system, for example — were accessed on our website. The conversion cookie allows both us and Google to trace whether a data subject who reached our website via an AdWords ad generated revenue, that is, completed or abandoned a purchase.

The data and information collected through the use of the conversion cookie is used by Google to produce visit statistics for our website. We in turn use these visit statistics to determine the total number of users referred to us by AdWords ads, that is, to determine the success or failure of the respective AdWords ad and to optimise our AdWords ads for the future. Neither our company nor other Google AdWords advertisers receive information from Google by means of which the data subject could be identified.

The conversion cookie stores personal information, such as the websites visited by the data subject. Each time our websites are visited, personal data — including the IP address of the internet connection used by the data subject — is therefore transferred to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may pass on the personal data collected through this technical procedure to third parties.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Google from setting a conversion cookie on the data subject's information technology system. In addition, a cookie already set by Google AdWords can be deleted at any time via the internet browser or other software programs.

The data subject also has the option of objecting to interest-based advertising by Google. To do so, the data subject must open the link www.google.de/settings/ads from each of the internet browsers they use and make the desired settings there.

Further information and Google's applicable data protection provisions can be found at https://www.google.de/intl/de/policies/privacy/.

19. Data protection provisions concerning the use of Instagram

The controller has integrated components of the Instagram service on this website. Instagram is a service qualifying as an audiovisual platform that allows users to share photos and videos and also to redistribute such data on other social networks.

The operating company of the Instagram services is Instagram LLC, 1 Hacker Way, Building 14 First Floor, Menlo Park, CA, USA.

Each time one of the individual pages of this website operated by the controller is accessed and on which an Instagram component (Insta button) has been integrated, the internet browser on the data subject's information technology system is automatically prompted by the respective Instagram component to download a representation of the corresponding component from Instagram. In the course of this technical procedure, Instagram learns which specific sub-page of our website the data subject is visiting.

If the data subject is logged in to Instagram at the same time, Instagram recognises which specific sub-page the data subject is visiting each time our website is accessed by the data subject, and for the entire duration of their stay on our website. This information is collected by the Instagram component and assigned by Instagram to the data subject's respective Instagram account. If the data subject activates one of the Instagram buttons integrated on our website, the data and information transmitted with it is assigned to the data subject's personal Instagram user account and stored and processed by Instagram.

Instagram always receives information via the Instagram component that the data subject has visited our website whenever the data subject is logged in to Instagram at the time of accessing our website; this happens regardless of whether the data subject clicks the Instagram component or not. If the data subject does not want such information to be transmitted to Instagram, they can prevent the transmission by logging out of their Instagram account before accessing our website.

Further information and Instagram's applicable data protection provisions can be found at https://help.instagram.com/155833707900388 and https://www.instagram.com/about/legal/privacy/.

20. Data protection provisions concerning the use of Matomo

The controller has integrated the Matomo component on this website. Matomo is an open source software tool for web analysis. Web analysis is the collection, gathering and evaluation of data about the behaviour of visitors to websites. Among other things, a web analysis tool records data about the website from which a data subject reached a website (so-called referrer), which sub-pages of the website were accessed, and how often and for how long a sub-page was viewed. Web analysis is used predominantly to optimise a website and to carry out cost-benefit analysis of internet advertising.

The software runs on the controller's server; the log files that are sensitive under data protection law are stored exclusively on this server.

The purpose of the Matomo component is to analyse visitor flows on our website. The controller uses the data and information obtained, among other things, to evaluate the use of this website in order to compile online reports showing the activities on our websites.

Matomo sets a cookie on the data subject's information technology system. What cookies are has already been explained above. Setting the cookie enables us to analyse the use of our website. Each time one of the individual pages of this website is accessed, the internet browser on the data subject's information technology system is automatically prompted by the Matomo component to transmit data to our server for the purpose of online analysis. In the course of this technical procedure, we gain knowledge of personal data such as the data subject's IP address, which serves us, among other things, to trace the origin of visitors and clicks.

The cookie stores personal information such as the time of access, the location from which access originated and the frequency of visits to our website. Each time our websites are visited, this personal data — including the IP address of the internet connection used by the data subject — is transferred to our server. This personal data is stored by us. We do not pass this personal data on to third parties.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Matomo from setting a cookie on the data subject's information technology system. In addition, a cookie already set by Matomo can be deleted at any time via an internet browser or other software programs.

The data subject also has the option of objecting to, and preventing, the collection of the data generated by Matomo relating to the use of this website. To do so, the data subject must enable "Do Not Track" in their browser.

If the opt-out cookie is set, it is possible that the controller's websites will no longer be fully usable by the data subject.

Further information and Matomo's applicable data protection provisions can be found at https://matomo.org/privacy/.

21. Data protection provisions concerning the use of Twitter

The controller has integrated components of Twitter on this website. Twitter is a multilingual, publicly accessible microblogging service on which users can publish and disseminate so-called tweets, that is, short messages limited to 280 characters. These short messages are accessible to everyone, including people who are not registered with Twitter. The tweets are also displayed to the so-called followers of the respective user. Followers are other Twitter users who follow a user's tweets. Twitter also makes it possible to reach a broad audience via hashtags, links or retweets.

The operating company of Twitter is Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA.

Each time one of the individual pages of this website operated by the controller is accessed and on which a Twitter component (Twitter button) has been integrated, the internet browser on the data subject's information technology system is automatically prompted by the respective Twitter component to download a representation of the corresponding Twitter component from Twitter. Further information about the Twitter buttons can be found at https://about.twitter.com/de/resources/buttons. In the course of this technical procedure, Twitter learns which specific sub-page of our website the data subject is visiting. The purpose of integrating the Twitter component is to allow our users to redistribute the content of this website, to make this website known in the digital world and to increase our visitor numbers.

If the data subject is logged in to Twitter at the same time, Twitter recognises which specific sub-page of our website the data subject is visiting each time our website is accessed by the data subject, and for the entire duration of their stay on our website. This information is collected by the Twitter component and assigned by Twitter to the data subject's respective Twitter account. If the data subject activates one of the Twitter buttons integrated on our website, the data and information transmitted with it is assigned to the data subject's personal Twitter user account and stored and processed by Twitter.

Twitter always receives information via the Twitter component that the data subject has visited our website whenever the data subject is logged in to Twitter at the time of accessing our website; this happens regardless of whether the data subject clicks the Twitter component or not. If the data subject does not want such information to be transmitted to Twitter, they can prevent the transmission by logging out of their Twitter account before accessing our website.

Twitter's applicable data protection provisions can be found at https://twitter.com/privacy?lang=de.

22. Data protection provisions concerning the use of DoubleClick

The controller has integrated components of DoubleClick by Google on this website. DoubleClick is a Google brand under which specialised online marketing solutions are marketed primarily to advertising agencies and publishers.

The operating company of DoubleClick by Google is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

DoubleClick by Google transfers data to the DoubleClick server with every impression as well as with clicks or other activities. Each of these data transfers triggers a cookie request to the data subject's browser. If the browser accepts this request, DoubleClick sets a cookie on the data subject's information technology system. What cookies are has already been explained above. The purpose of the cookie is to optimise and display advertising. Among other things, the cookie is used to place and display advertising relevant to the user and to produce or improve reports on advertising campaigns. The cookie also serves to avoid displaying the same advertisement more than once.

DoubleClick uses a cookie ID that is required to carry out the technical procedure. The cookie ID is needed, for example, in order to display an advertisement in a browser. DoubleClick can also use the cookie ID to record which advertisements have already been displayed in a browser in order to avoid duplicate placements. Furthermore, the cookie ID enables DoubleClick to record conversions. Conversions are recorded, for example, when a user was previously shown a DoubleClick advertisement and subsequently makes a purchase on the advertiser's website using the same internet browser.

A DoubleClick cookie contains no personal data. A DoubleClick cookie may, however, contain additional campaign identifiers. A campaign identifier serves to identify the campaigns the user has already been in contact with.

Each time one of the individual pages of this website operated by the controller is accessed and on which a DoubleClick component has been integrated, the internet browser on the data subject's information technology system is automatically prompted by the respective DoubleClick component to transmit data to Google for the purposes of online advertising and the settlement of commissions. In the course of this technical procedure, Google gains knowledge of data which also serves Google to produce commission settlements. Among other things, Google can trace that the data subject clicked certain links on our website.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Google from setting a cookie on the data subject's information technology system. In addition, cookies already set by Google can be deleted at any time via an internet browser or other software programs.

Further information and the applicable data protection provisions of DoubleClick by Google can be found at https://www.google.com/intl/de/policies/.

23. Data protection provisions concerning the use of Awin

The controller has integrated components of Awin on this website. Awin is a German affiliate network offering affiliate marketing. Affiliate marketing is an internet-based form of distribution that enables commercial operators of websites, so-called merchants or advertisers, to display advertising — usually remunerated through click or sale commissions — on third-party websites, that is, with distribution partners also known as affiliates or publishers. The merchant makes an advertising medium available through the affiliate network, that is, an advertising banner or other suitable means of internet advertising, which an affiliate then embeds on their own websites or promotes through other channels such as keyword advertising or email marketing.

The operating company of Awin is Awin AG, Eichhornstraße 3, 10785 Berlin, Germany.

Awin sets a cookie on the data subject's information technology system. What cookies are has already been explained above. Awin's tracking cookie does not store any personal data. Only the identification number of the affiliate — that is, the partner referring the potential customer — and the reference number of the visitor to a website and of the advertising medium clicked on are stored. The purpose of storing this data is the handling of commission payments between a merchant and the affiliate, which are settled through the affiliate network, that is, Awin.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Awin from setting a cookie on the data subject's information technology system. In addition, cookies already set by Awin can be deleted at any time via an internet browser or other software programs.

Awin's applicable data protection provisions can be found at http://www.Awin.com/de/ueber-Awin/datenschutz/.

24. Data protection provisions concerning the use of Belboon

The controller has integrated components of Belboon on this website. Belboon is a German affiliate network offering affiliate marketing. Affiliate marketing is an internet-based form of distribution that enables commercial operators of websites, so-called merchants or advertisers, to display advertising — usually remunerated through click or sale commissions — on third-party websites, that is, with distribution partners also known as affiliates or publishers. The merchant makes an advertising medium available through the affiliate network, that is, an advertising banner or other suitable means of internet advertising, which an affiliate then embeds on their own websites or promotes through other channels such as keyword advertising or email marketing.

The operating company of Adcell is belboon GmbH, Weinmeisterstr. 12-14, 10178 Berlin.

Belboon sets a cookie on the data subject's information technology system. What cookies are has already been explained above. Belboon's tracking cookie does not store any personal data. Only the identification number of the affiliate — that is, the partner referring the potential customer — and the reference number of the visitor to a website and of the advertising medium clicked on are stored. The purpose of storing this data is the handling of commission payments between a merchant and the affiliate, which are settled through the affiliate network, that is, Belboon.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Belboon from setting a cookie on the data subject's information technology system. In addition, cookies already set by Belboon can be deleted at any time via an internet browser or other software programs.

Belboon's applicable data protection provisions can be found at https://www.belboon.com/de/ueber-uns/datenschutz/.

25. Data protection provisions concerning the use of Tradedoubler

The controller has integrated components of Tradedoubler on this website. Tradedoubler is a German affiliate network offering affiliate marketing. Affiliate marketing is an internet-based form of distribution that enables commercial operators of websites, so-called merchants or advertisers, to display advertising — usually remunerated through click or sale commissions — on third-party websites, that is, with distribution partners also known as affiliates or publishers. The merchant makes an advertising medium available through the affiliate network, that is, an advertising banner or other suitable means of internet advertising, which an affiliate then embeds on their own websites or promotes through other channels such as keyword advertising or email marketing.

The operating company of Tradedoubler is Tradedoubler GmbH, Herzog-Wilhelm-Straße 26, 80331 Munich, Germany.

Tradedoubler sets a cookie on the data subject's information technology system. What cookies are has already been explained above. Tradedoubler's tracking cookie does not store any personal data. Only the identification number of the affiliate — that is, the partner referring the potential customer — and the reference number of the visitor to a website and of the advertising medium clicked on are stored. The purpose of storing this data is the handling of commission payments between a merchant and the affiliate, which are settled through the affiliate network, that is, Tradedoubler.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Tradedoubler from setting a cookie on the data subject's information technology system. In addition, cookies already set by Tradedoubler can be deleted at any time via an internet browser or other software programs.

Tradedoubler's applicable data protection provisions can be found at http://www.tradedoubler.com/de/datenschutzrichtlinie/.

26. Data protection provisions concerning the use of Oracle Eloqua / Oracle Marketing Cloud

The controller has integrated components of Oracle Eloqua / Oracle Marketing Cloud (hereinafter „Eloqua“) on this website. Eloqua matches relevant website content with data on prospects and customers and their profiles in order to enable website operators to address prospects and customers more effectively and in a more targeted way. The purpose of Eloqua is to increase the conversion rate of prospects into customers and thereby increase a website operator's revenue.

The operating company of Eloqua is Oracle Corporation, 500 Oracle Parkway, Redwood Shores, CA 94065, USA.

Eloqua sets a cookie on the data subject's information technology system. What cookies are has already been explained above. On behalf of the controller, Eloqua will use the data and information obtained via our website to evaluate the user behaviour of the data subject who has used our website. Eloqua will also use the data to produce reports on user activity on our behalf and to provide further services to our company relating to the use of our website.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Oracle from setting a cookie on the data subject's information technology system. In addition, cookies already set by Oracle can be deleted at any time via the internet browser or other software programs.

The data subject also has the option of objecting to, and preventing, the collection of the data generated by the Eloqua cookie relating to the use of this website and the processing of that data by Oracle. To do so, the data subject must press the "Click here" button at https://www.oracle.com/marketingcloud/opt-status.html, which sets an opt-out cookie. The opt-out cookie set with the objection is placed on the information technology system used by the data subject. If the cookies on the data subject's system are deleted after an objection, the data subject must open the link again and set a new opt-out cookie.

If the opt-out cookie is set, it is possible that the controller's websites will no longer be fully usable by the data subject.

Oracle's applicable data protection provisions can be found at https://www.oracle.com/legal/privacy/index.html.

27. Data protection provisions concerning the use of Amobee

The controller has integrated components of Amobee on this website. Amobee is a technology-based advertising agency specialising in delivering advertising to mobile devices.

The operating company of Amobee is Amobee Inc., 950 Tower Lane, Suite 2000, Foster City, CA 94404, USA.

The purpose of Amobee is the delivery of advertising. Amobee sets a cookie on the data subject's information technology system. What cookies are has already been explained above. Each time one of the individual pages of this website operated by the controller is accessed and on which an Amobee component has been integrated, the internet browser on the data subject's information technology system is automatically prompted by the respective Amobee component to transmit data to Amobee. In the course of this technical procedure, Amobee gains knowledge of data which is subsequently used to create usage profiles. The usage profiles obtained in this way serve advertising activities.

As already explained above, the data subject may prevent the setting of cookies by our website at any time by means of a corresponding setting in the internet browser used, and may thereby permanently object to the setting of cookies. Such a setting in the internet browser used would also prevent Amobee from setting a cookie on the data subject's information technology system. In addition, cookies already set by Amobee can be deleted at any time via an internet browser or other software programs.

There is also the option of objecting to, and preventing, the collection of the data generated by the Amobee cookie relating to the use of this website and the processing of that data by Amobee. To do so, the data subject must press the "Click here to opt out" button at http://amobee.com/privacy/technology/, which sets an opt-out cookie. The opt-out cookie set with the objection is placed on the information technology system used by the data subject. If the cookies on the data subject's system are deleted after an objection, the data subject must open the link again and set a new opt-out cookie.

If the opt-out cookie is set, it is possible that the controller's websites will no longer be fully usable by the data subject.

Amobee's applicable data protection provisions can be found at http://amobee.com/privacy/.

28. Payment method: data protection provisions concerning PayPal as a payment method

The controller has integrated components of PayPal on this website. PayPal is an online payment service provider. Payments are processed via so-called PayPal accounts, which are virtual private or business accounts. PayPal also offers the option of processing virtual payments by credit card if a user does not hold a PayPal account. A PayPal account is managed via an email address, which is why there is no conventional account number. PayPal makes it possible to initiate online payments to third parties and to receive payments. PayPal also acts as a trustee and offers buyer protection services.

The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.

If the data subject selects „PayPal“ as the payment option during the ordering process in our online shop, the data subject's data is transmitted automatically to PayPal. By selecting this payment option, the data subject consents to the transmission of personal data required for processing the payment.

The personal data transmitted to PayPal is generally first name, surname, address, email address, IP address, telephone number, mobile telephone number or other data necessary for processing the payment. Personal data relating to the respective order is also necessary in order to perform the contract of sale.

The purpose of transmitting the data is payment processing and fraud prevention. The controller will transmit personal data to PayPal in particular where there is a legitimate interest in the transmission. The personal data exchanged between PayPal and the controller may be transmitted by PayPal to credit agencies. The purpose of this transmission is to check identity and creditworthiness.

PayPal may pass the personal data on to affiliated companies and to service providers or subcontractors, insofar as this is necessary to fulfil the contractual obligations or the data is to be processed on its behalf.

The data subject has the option of withdrawing consent to the handling of personal data from PayPal at any time. A withdrawal does not affect personal data that must necessarily be processed, used or transmitted for (contractual) payment processing.

PayPal's applicable data protection provisions can be found at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

29. Payment method: data protection provisions concerning Sofortüberweisung as a payment method

The controller has integrated components of Sofortüberweisung on this website. Sofortüberweisung is a payment service that enables cashless payment for products and services on the internet. Sofortüberweisung represents a technical procedure through which the online retailer receives confirmation of payment immediately. This enables a retailer to deliver goods, services or downloads to the customer immediately after the order.

The operating company of Sofortüberweisung is SOFORT GmbH, Fußbergstraße 1, 82131 Gauting, Germany.

If the data subject selects „Sofortüberweisung“ as the payment option during the ordering process in our online shop, the data subject's data is transmitted automatically to Sofortüberweisung. By selecting this payment option, the data subject consents to the transmission of personal data required for processing the payment.

When a purchase is processed via Sofortüberweisung, the buyer transmits their PIN and TAN to Sofort GmbH. After technically checking the account balance and retrieving further data to check whether the account is in credit, Sofortüberweisung then carries out a transfer to the online retailer. The execution of the financial transaction is then communicated automatically to the online retailer.

The personal data exchanged with Sofortüberweisung is first name, surname, address, email address, IP address, telephone number, mobile telephone number or other data necessary for processing the payment. The purpose of transmitting the data is payment processing and fraud prevention. The controller will also transmit other personal data to Sofortüberweisung where there is a legitimate interest in the transmission. The personal data exchanged between Sofortüberweisung and the controller may be transmitted by Sofortüberweisung to credit agencies. The purpose of this transmission is to check identity and creditworthiness.

Sofortüberweisung may pass the personal data on to affiliated companies and to service providers or subcontractors, insofar as this is necessary to fulfil the contractual obligations or the data is to be processed on its behalf.

The data subject has the option of withdrawing consent to the handling of personal data from Sofortüberweisung at any time. A withdrawal does not affect personal data that must necessarily be processed, used or transmitted for (contractual) payment processing.

Sofortüberweisung's applicable data protection provisions can be found at https://www.sofort.com/ger-DE/datenschutzerklaerung-sofort-gmbh/.

30. Legal basis for the processing

Article 6(1)(a) GDPR serves our company as the legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is party, as is the case for example with processing operations necessary for the supply of goods or the provision of any other service or consideration, the processing is based on Article 6(1)(b) GDPR. The same applies to processing operations necessary to carry out pre-contractual measures, for example in the case of enquiries about our products or services. If our company is subject to a legal obligation requiring the processing of personal data, for example to fulfil tax obligations, the processing is based on Article 6(1)(c) GDPR. In rare cases the processing of personal data might become necessary in order to protect the vital interests of the data subject or of another natural person. This would be the case, for example, if a visitor were injured on our premises and their name, age, health insurance details or other vital information had to be passed on to a doctor, a hospital or other third parties. The processing would then be based on Article 6(1)(d) GDPR. Finally, processing operations could be based on Article 6(1)(f) GDPR. Processing operations not covered by any of the aforementioned legal bases are based on this legal basis where the processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, provided that the interests, fundamental rights and freedoms of the data subject do not override those interests. We are permitted to carry out such processing operations in particular because they were specifically mentioned by the European legislator, which took the view that a legitimate interest could be assumed where the data subject is a client of the controller (recital 47, second sentence, GDPR).

31. Legitimate interests pursued by the controller or by a third party

Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the conduct of our business for the benefit of the well-being of all our employees and our shareholders.

32. Period for which the personal data will be stored

The criterion for the period for which personal data is stored is the respective statutory retention period. Once the period has expired, the data in question is routinely erased, provided it is no longer necessary for the performance or initiation of a contract.

33. Statutory or contractual requirements to provide the personal data; necessity for entering into a contract; obligation of the data subject to provide the personal data; possible consequences of failure to provide such data

We would point out that the provision of personal data is in part required by law (tax regulations, for example) or may also follow from contractual arrangements (details of the contracting party, for example). It may sometimes be necessary for the conclusion of a contract that a data subject provides us with personal data which must subsequently be processed by us. The data subject is, for example, obliged to provide us with personal data when our company concludes a contract with them. Failure to provide the personal data would mean that the contract with the data subject could not be concluded. Before providing personal data, the data subject must contact one of our employees. Our employee will explain to the data subject, on a case-by-case basis, whether the provision of the personal data is required by law or by contract or is necessary for the conclusion of a contract, whether there is an obligation to provide the personal data, and what the consequences of failing to provide the personal data would be.

34. Existence of automated decision-making

As a responsible company, we do not use automated decision-making or profiling.

This privacy policy was created by the privacy policy generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, which acts as Externer Datenschutzbeauftragter Neu-Ulm, in cooperation with the lawyer for IT and data protection law Christian Solmecke.

Uploads

When media (photos and videos) are uploaded, the following data is stored for guests and registered members alike:

  • IP address
  • Reverse DNS record
  • Browser identification (manufacturer, name, version, features)
  • Time of upload