Privacy Information
Table of Contents
- Introduction and Contact Information of the Data Controller
- Data Collection When Visiting Our Website
- Hosting & Content Delivery Network
- Cookies
- Contact
- Comment Function
- Data Processing When Opening a Customer Account
- Use of Customer Data for Direct Marketing
- Data Processing for Order Processing
- Web Analytics Services
- Retargeting/Remarketing and Conversion Tracking
- Page Functionality
- Tools and Miscellaneous
- Rights of the Data Subject
- Duration of Storage of Personal Data
1. Introduction and Contact Information of the Data Controller
We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about how we handle your personal data when you use our website. Personal data is any information that can be used to personally identify you.
The data controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is DDP duschdichtungsprofile.de GmbH, Winzeldorfer Straße 50, 25474 Bönningstedt, Germany, Phone: +49 (0) 40 – 507 231 29, Email: info@duschdichtungsprofile.de. The data controller is the natural or legal person who decides alone or jointly with others on the purposes and means of processing personal data.
2. Data Collection When Visiting Our Website
If you only use our website for informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the page server (so-called "server log files"). When you access our website, we collect the following data that is technically required for us to display the website to you:
- Unsere besuchte Website
- Datum und Uhrzeit zum Zeitpunkt des Zugriffes
- Menge der gesendeten Daten in Byte
- Quelle/Verweis, von welchem Sie auf die Seite gelangten
- Verwendeter Browser
- Verwendetes Betriebssystem
- Verwendete IP-Adresse (ggf.: in anonymisierter Form)
Processing is carried out in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data is not shared or otherwise used. However, we reserve the right to review server log files after the fact if concrete evidence suggests unlawful use.
This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the data controller). You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser bar.
3. Hosting & Content Delivery Network
For hosting our website and displaying page content, we use a provider whose services are provided either by itself or through selected subcontractors exclusively on servers within the European Union.
All data collected on our website is processed on these servers.
We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
Cloudflare
We use a Content Delivery Network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA
This service enables us to deliver large media files such as graphics, page content or scripts more quickly via a network of regionally distributed servers. Processing is carried out to protect our legitimate interest in improving the stability and functionality of our website in accordance with Article 6(1)(f) GDPR. We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
4. Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e., small text files that are stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device longer and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the cookie settings overview of your web browser.
If cookies used by us also process personal data, processing is carried out in accordance with Article 6(1)(b) GDPR either for contract performance, in accordance with Article 6(1)(a) GDPR in the case of given consent, or in accordance with Article 6(1)(f) GDPR to protect our legitimate interests in the best possible functionality of the website and customer-friendly and effective design of the page visit.
You can set your browser so that you are informed about the setting of cookies and can decide individually about their acceptance, or you can exclude the acceptance of cookies for certain cases or generally.
Please note that if you do not accept cookies, the functionality of our website may be limited.
5. Contact
Trusted Shops
For review reminders, we use the services of the following provider: Trusted Shops SE, Subbelrather Straße 15c, 50823 Cologne, Germany.
Exclusively on the basis of your explicit consent in accordance with Article 6(1)(a) GDPR, we transmit your email address and, if applicable, other customer data to the provider so that they can contact you with a review reminder by email.
You can withdraw your consent at any time with effect for the future either to us or to the provider.
We are jointly responsible with the provider for the processing described above in accordance with Article 26 GDPR. The joint responsibility agreement can be viewed here: help.etrusted.com/hc/en/articles/4402587369105-Data-Processing-Agreement
When you contact us (e.g., via contact form or email), personal data is processed exclusively for the purpose of processing and responding to your request and only to the extent required for this.
The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Article 6(1)(f) GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Article 6(1)(b) GDPR. Your data will be deleted when it becomes clear from the circumstances that the matter in question has been finally clarified and as long as no legal retention obligations stand in the way.
6. Comment Function
In the comment function on this website, in addition to your comment, information about the time the comment was created and the commenter name you chose is stored and published on this website. Furthermore, your IP address is logged and stored. This storage of the IP address is for security reasons and in case the affected person violates the rights of third parties or posts unlawful content through a submitted comment. We need your email address to contact you if a third party objects to your published content as unlawful.
The legal bases for storing your data are Articles 6(1)(b) and (f) GDPR. We reserve the right to delete comments if they are objected to by third parties as unlawful.
7. Data Processing When Opening a Customer Account
In accordance with Article 6(1)(b) GDPR, personal data is further collected and processed to the extent required if you provide it to us when opening a customer account. You can see which data is required for account creation from the input form of the corresponding form on our website.
You can delete your customer account at any time and this can be done by sending a message to the above address of the data controller. After deletion of your customer account, your data will be deleted provided that all contracts concluded through it have been completely processed, no legal retention periods stand in the way, and we do not have a legitimate interest in further storage.
8. Use of Customer Data for Direct Marketing
Registration for Our Email Newsletter
When you register for our email newsletter, we send you regular information about our offers. The only mandatory information for sending the newsletter is your email address. Providing additional data is voluntary and will be used to address you personally. For newsletter dispatch, we use the so-called double opt-in procedure, which ensures that you only receive newsletters after you have explicitly confirmed your consent to receiving the newsletter by clicking on a verification link sent to the email address provided.
By activating the confirmation link, you give us your consent to use your personal data in accordance with Article 6(1)(a) GDPR. We store your IP address as recorded by your Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your email address at a later date. The data we collect when you register for the newsletter is used strictly for the stated purpose.
You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a corresponding message to the data controller mentioned at the beginning. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list, unless you have explicitly consented to further use of your data or we reserve the right to further use your data that is legally permitted and about which we inform you in this statement.
9. Data Processing for Order Processing
To the extent necessary for contract processing for delivery and payment purposes, the personal data we collect is passed on in accordance with Article 6(1)(b) GDPR to the commissioned transport company and the commissioned credit institution.
To the extent that we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we process the contact data you provided when placing your order in order to inform you personally within the scope of our legal information obligations in accordance with Article 6(1)(c) GDPR. Your contact data is used strictly for the stated purpose for communications regarding updates owed by us and is only processed by us to the extent necessary for the respective communication.
To process your order, we also work with the following service provider(s) who assist us in whole or in part in the performance of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.
Shopware
For order processing, we use the following provider: shopware AG, Ebbinghoff 10, 48624 Schöppingen
Name, address and, if applicable, other personal data are passed on to the provider exclusively for the purpose of processing the online order in accordance with Article 6(1)(b) GDPR. The transfer of your data is only made to the extent that it is actually necessary for processing the order.
Use of Payment Service Providers (Payment Services)
Apple Pay
If you choose the "Apple Pay" payment method from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing is carried out via the "Apple Pay" function of your device running iOS, watchOS or macOS by debiting a payment card stored in "Apple Pay". Apple Pay uses security features integrated into your device's hardware and software to protect your transactions. To authorize a payment, you must enter a code previously set by you and verify using the "Face ID" or "Touch ID" function of your device.
For the purpose of payment processing, the information you provided during the ordering process, together with information about your order, is transmitted to Apple in encrypted form. Apple then encrypts this data again with a developer-specific key before the data is transmitted to the payment service provider of the payment card stored in Apple Pay to carry out the payment. The encryption ensures that only the website through which the purchase was made can access the payment data. After payment is made, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the payment was successful.
If personal data is processed in the transmissions described, processing is carried out exclusively for the purpose of payment processing in accordance with Article 6(1)(b) GDPR.
Apple retains anonymized transaction data, including the approximate purchase amount, approximate date and time, and whether the transaction was completed successfully. Through anonymization, a personal reference is completely excluded. Apple uses the anonymized data to improve "Apple Pay" and other Apple products and services.
When you use Apple Pay on your iPhone or Apple Watch to complete a purchase you made through Safari on your Mac, your Mac and authorization device communicate via an encrypted channel on Apple's servers. Apple does not process or store any of this information in a format that can identify you. You can disable the ability to use Apple Pay on your Mac in your iPhone settings. Go to "Wallet & Apple Pay" and turn off "Allow Payments on Mac."
Further information on data protection at Apple Pay can be found at support.apple.com/en-us/HT203027.
Klarna
One or more online payment methods from the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden
If you select a payment method from the provider where you make advance payment (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order is transmitted to the provider in accordance with Article 6(1)(b) GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this.
If you select a payment method where the provider makes advance payment (such as invoice or installment purchase or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, if applicable, data for an alternative payment method).
To protect our legitimate interest in determining the creditworthiness of our customers, this data is forwarded to the provider by us in accordance with Article 6(1)(f) GDPR for the purpose of a credit check. The provider checks on the basis of the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment method you selected can be granted in view of payment and/or receivables default risks.
In making decisions within the scope of application review, in addition to provider-internal criteria, in accordance with Article 6(1)(f) GDPR, identity and creditworthiness information from the following credit reporting agencies may also be included:
cdn.klarna.com/1.0/shared/content/legal/terms/0/en/credit_rating_agencies
The credit report may contain probability values (so-called score values). Insofar as score values flow into the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, but not exclusively, flows into the calculation of score values.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may continue to be entitled to process your personal data to the extent that this is required for contract-compliant payment processing.
Mollie
One or more online payment methods from the following provider are available on this website: Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands
If you select a payment method from the provider where you make advance payment (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order is transmitted to the provider in accordance with Article 6(1)(b) GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this.
PayPal
One or more online payment methods from the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
If you select a payment method from the provider where you make advance payment, your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order is transmitted to the provider in accordance with Article 6(1)(b) GDPR. The transfer of your data in this case is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this.
If you select a payment method where we make advance payment, you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, if applicable, data for an alternative payment method).
To protect our legitimate interest in determining your creditworthiness in such cases, this data is forwarded to the provider by us in accordance with Article 6(1)(f) GDPR for the purpose of a credit check. The provider checks on the basis of the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment method you selected can be granted in view of payment and/or receivables default risks.
The credit report may contain probability values (so-called score values). Insofar as score values flow into the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, but not exclusively, flows into the calculation of score values.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may continue to be entitled to process your personal data to the extent that this is required for contract-compliant payment processing.
10. Web Analytics Services
Google Analytics 4
This website uses Google Analytics 4, a web analytics service from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables analysis of your use of our website.
By default, Google Analytics 4 sets cookies when you visit the website, which are stored as small text snippets on your device and collect certain information. The scope of this information also includes your IP address, which Google shortens to exclude the last digits to exclude direct personal reference.
The information is transmitted to Google servers and further processed there. This also includes possible transmissions to Google LLC with headquarters in the USA.
Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activities for us, and provide other services related to website use and internet use. The shortened IP address transmitted by your browser as part of Google Analytics is not combined with other Google data. The data collected as part of Google Analytics 4 is stored for a period of two months and then deleted.
All processing described above, in particular the setting of cookies on the device used, takes place only if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR.
Without your consent, Google Analytics 4 will not be used during your visit. You can revoke your given consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with Google that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
Further legal information on Google Analytics 4 can be found at business.safety.google/intl/en/privacy, policies.google.com/privacy and policies.google.com/technologies/partner-sites.
Demographic Features
Google Analytics 4 uses the special "demographic features" function and can create statistics that provide information about the age, gender and interests of website visitors. This is done by analyzing advertising and information from third parties. As a result, target audiences can be identified for marketing activities. However, the collected data cannot be attributed to a specific person and is deleted after storage for a period of two months.
Google Signals
As an extension to Google Analytics 4, Google Signals can be used on this website to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google can analyze your usage behavior across devices and create database models, including cross-device conversions, subject to your consent to use Google Analytics in accordance with Article 6(1)(a) GDPR. We do not receive personal data from Google, only statistics. If you want to stop cross-device analysis, you can disable the "Personalized Ads" feature in your Google account settings. Follow the instructions on this page support.google.com/My-Ad-Center-Help/answer/12155764
Further information on Google Signals can be found at the following link: support.google.com/analytics/answer/7532985
UserIDs
As an extension to Google Analytics 4, the "UserIDs" feature can be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Article 6(1)(a) GDPR, have created an account on this website, and log in to that account from different devices, your activities, including conversions, can be analyzed across devices.
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
Google Tag Manager
This website uses "Google Tag Manager", a service from the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").
Google Tag Manager provides a technical foundation for bundling various web applications, including tracking and analysis services, and managing, controlling, and conditioning them via a single user interface. Google Tag Manager itself does not store information on user devices or read it. The service also does not perform independent data analysis. However, Google Tag Manager transmits your IP address to Google when a page is accessed and it may be stored there. There is also a possibility of transmission to Google LLC servers in the USA.
This processing is only carried out if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR. Without this consent, Google Tag Manager will not be used during your visit. You can revoke your given consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
Further legal information on Google Tag Manager can be found at business.safety.google/intl/en/privacy and policies.google.com/privacy
PostHog
This website uses the web analytics service from the following provider: PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA
The service enables statistical evaluation of the use of new features and content on the website by distributing test variants to certain user groups. In the interest of improving the attractiveness of our site, we can understand which variants users prefer. The service uses cookies, i.e., small text files that are stored on your device and enable analysis of your website usage. The information collected via cookies about your website usage is usually transmitted to a server of the provider and stored and processed there.
All processing described above, in particular the setting of cookies to store and read information on the device you use to visit the website, only takes place if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR. Without your consent, the service will not be used during your website usage. You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
11. Retargeting/Remarketing and Conversion Tracking
Google Ads Conversion Tracking Without Cookies
This website uses the online advertising program "Google Ads" and as part of Google Ads the conversion tracking from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").
We use Google Ads to draw attention to our attractive offers on external websites with the help of advertising materials (so-called Google Adwords). We can determine in relation to the data from advertising campaigns how successful the individual advertising measures are. We pursue the goal of showing you advertising that is of interest to you, making our website more interesting for you, and achieving fair billing of advertising costs incurred.
This website uses Google Ads conversion tracking exclusively without the use of cookies, which means that the service never sets cookies on your device at any time.
Instead, the local storage of your browser is used to store an individual ID assigned by Google, which enables analysis of your website usage. For this purpose, certain user information is processed via the ID.
The ID is set when a user clicks on a Google Ads advertisement. When the user visits certain pages of this website, Google and we can see that the user clicked on the ad and was directed to this page. Each Google Ads customer receives a different cookie. Cookies cannot be tracked across Google Ads customer websites. The information obtained is used to create conversion statistics for Google Ads customers who have opted in for conversion tracking. Customers learn the total number of users who clicked on their ad and were directed to a page tagged with a conversion tracking tag.
However, you do not receive information that can be used to personally identify users. As part of the use of Google Ads, there may also be a transmission of personal data to Google LLC servers in the USA. Details on processing initiated by Google Ads Conversion Tracking and Google's handling of data from websites can be found here: policies.google.com/technologies/partner-sites
To the extent that the collected information has a personal reference, processing is carried out in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in the statistical evaluation of the success of our advertising campaigns.
Google's privacy policy can be found here: business.safety.google/intl/en/privacy and www.google.de/policies/privacy
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
Google Ads Conversion Tracking
This website uses the online advertising program "Google Ads" and as part of Google Ads the conversion tracking from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use Google Ads to draw attention to our attractive offers on external websites with the help of advertising materials (so-called Google Adwords). We can determine in relation to the data from advertising campaigns how successful the individual advertising measures are. We pursue the goal of showing you advertising that is of interest to you, making our website more interesting for you, and achieving fair billing of advertising costs incurred.
The conversion tracking cookie is set when a user clicks on a Google Ads ad. Cookies are small text files that are stored on your device. These cookies typically expire after 30 days and are not used for personal identification. When the user visits certain pages of this website and the cookie has not yet expired, Google and we can see that the user clicked on the ad and was directed to this page. Each Google Ads customer receives a different cookie. Cookies cannot be tracked across Google Ads customer websites. The information obtained through the conversion cookie is used to create conversion statistics for Google Ads customers who have opted in for conversion tracking. Customers learn the total number of users who clicked on their ad and were directed to a page tagged with a conversion tracking tag. However, you do not receive information that can be used to personally identify users. As part of the use of Google Ads, there may also be a transmission of personal data to Google LLC servers in the USA.
Details on processing initiated by Google Ads Conversion Tracking and Google's handling of data from websites can be found here: policies.google.com/technologies/partner-sites
All processing described above, in particular the setting of cookies to read information on the device used, is only carried out if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.
You can also permanently object to the setting of cookies by Google Ads Conversion Tracking by downloading and installing the browser plugin from Google available at the following link: support.google.com/My-Ad-Center-Help/answer/12155656
Please note that certain functions of this website may not or only be partially available if you have disabled the use of cookies. Google's privacy policy can be found here: business.safety.google/intl/en/privacy and www.google.de/policies/privacy
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
Microsoft Advertising Universal Event Tracking
This website uses conversion tracking technology from the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
For the use of Universal Event Tracking, a tag is placed on each page of our website that interacts with the conversion cookie set by Microsoft. This interaction makes user behavior on our website traceable and sends the information collected in this way to Microsoft. The purpose of this is to enable certain predefined goals such as purchases or leads to be statistically recorded and evaluated in order to design the targeting and content of our offers in a more interest-appropriate manner. The tags are never used for personal identification of users.
All processing described above, in particular the setting of cookies to read information on the device used, is only carried out if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR. Without this consent, retargeting technology will not be used during your visit.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
12. Page Functionality
YouTube
This website uses plugins to display and play videos from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
Data can also be transmitted to: Google LLC., USA
When you access a page on our website that contains such a plugin, your browser establishes a direct connection to the provider's servers at the latest when the video is played to load the content. Certain information, including your IP address, is transmitted to the provider in this process.
When playback of embedded videos via the plugin is started, the provider also uses cookies to collect information about user behavior, create playback statistics, and prevent misuse.
If you are logged into a user account with the provider during your visit, your data will be directly associated with your account when you click on a video. If you do not wish to have this assignment to your account, you must log out before clicking the play button.
All of the foregoing processing, in particular the setting of cookies to read information on the device used, takes place only if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR. The consent you have given can be revoked at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider has committed to the EU-US Data Privacy Framework, which ensures compliance with European data protection standards on the basis of an adequacy decision by the European Commission.
Trusted Shops Trustbadge
On our website, graphic elements of the following provider are embedded to display external customer reviews and/or an externally awarded quality seal: Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne, Germany
When you access a page on our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to properly load the elements. Certain browser information, including your IP address, is transmitted to the provider in this process.
To the extent that personal data is also processed, this is done in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in the optimal marketing of our offer and the appealing design of our website.
In the event of an online order with us, further processing may take place.
So, depending on your explicit consent in accordance with Article 6(1)(a) GDPR, your order information (order total, order number, products purchased if applicable) and your email address are transmitted encrypted to the provider via the Trustbadge after an order is completed to check whether there is an existing registration for the provider's services (in particular "Buyer Protection") and, if applicable, to enable a new registration.
In the event of a confirmed existing registration or in the event of a new registration with the provider for its services (in particular buyer protection), your order information (order total, order number, products purchased) and your email address are transmitted to the provider in accordance with the contractual agreement with the provider in accordance with Article 6(1)(b) GDPR and further processed by the provider in order to provide the services (in particular buyer protection).
We are jointly responsible with the provider for the processing described above in accordance with Article 26 GDPR. The joint responsibility agreement can be viewed here: help.etrusted.com/hc/en/articles/4402587369105-Data-Processing-Agreement
13. Tools and Miscellaneous
AccountOne
For accounting purposes, we use the service of the cloud-based accounting software from the following provider: AccountOne GmbH, Fördepromenade 4d, 24944 Flensburg, Germany
The provider processes incoming and outgoing invoices as well as, if applicable, our company's bank movements in order to automatically record invoices, match them to transactions, and create financial accounting from a semi-automated process.
To the extent that personal data is also processed, processing is carried out on the basis of our legitimate interest in efficient organization and documentation of our business processes in accordance with Article 6(1)(f) GDPR.
DATEV
For accounting purposes, we use the service of the cloud-based accounting software from the following provider: DATEV eG, Paumgartnerstr. 6-14, 90429 Nuremberg, Germany
The provider processes incoming and outgoing invoices as well as, if applicable, our company's bank movements in order to automatically record invoices, match them to transactions, and create financial accounting from a semi-automated process.
To the extent that personal data is also processed, processing is carried out on the basis of our legitimate interest in efficient organization and documentation of our business processes in accordance with Article 6(1)(f) GDPR.
14. Rights of the Data Subject
The applicable data protection law grants you the following rights as a data subject (rights of access and intervention) against the data controller with regard to the processing of your personal data, whereby reference is made to the legal basis cited for the respective exercise conditions:
- Auskunftsrecht gemäß Art. 15 DSGVO;
- Recht auf Berichtigung gemäß Art. 16 DSGVO;
- Recht auf Löschung gemäß Art. 17 DSGVO;
- Recht auf Einschränkung der Verarbeitung gemäß Art. 18 DSGVO;
- Recht auf Unterrichtung gemäß Art. 19 DSGVO;
- Recht auf Datenübertragbarkeit gemäß Art. 20 DSGVO;
- Recht auf Widerruf erteilter Einwilligungen gemäß Art. 7 Abs. 3 DSGVO;
- Recht auf Beschwerde gemäß Art. 77 DSGVO.
RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA WITHIN THE SCOPE OF AN INTEREST WEIGHING ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING FOR REASONS RESULTING FROM YOUR SPECIFIC SITUATION WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE REASONS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS, OR IF PROCESSING IS NECESSARY FOR THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO PROCESSING OF YOUR PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING. YOU CAN EXERCISE YOUR OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.
15. Duration of Storage of Personal Data
The duration of storage of personal data is determined by the respective legal basis, the processing purpose, and – if applicable – additionally by the respective legal retention period (e.g., commercial and tax retention periods).
When processing personal data on the basis of express consent in accordance with Article 6(1)(a) GDPR, the affected data will be stored until you revoke your consent.
If legal retention periods exist for data processed under Article 6(1)(b) GDPR in the context of legal transactions or similar legal acts, this data will be routinely deleted after the retention period expires, unless it is still required for contract performance or contract initiation and/or we no longer have a legitimate interest in further storage.
When processing personal data on the basis of Article 6(1)(f) GDPR, this data will be stored until you exercise your right to object in accordance with Article 21(1) GDPR, unless we can demonstrate compelling legitimate reasons for processing that outweigh your interests, rights and freedoms, or processing is necessary for the assertion, exercise or defense of legal claims.
When processing personal data for the purpose of direct marketing on the basis of Article 6(1)(f) GDPR, this data will be stored until you exercise your right to object in accordance with Article 21(2) GDPR.
Otherwise, to the extent that nothing else results from the other information in this statement regarding specific processing situations, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.