Privacy policy
Privacy Policy
1. Overview of Data Protection
General Information
The following information provides an overview of how your personal data is handled when you visit our website. Personal data refers to any information that can personally identify you. Detailed information on data protection is provided in the privacy policy below.
Data Collection on This Website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find the operator's contact details in the section titled "Notice Regarding the Responsible Party" in this privacy policy.
How do we collect your data?
Your data is collected when you provide it to us directly, for example, by filling out a contact form.
Other data is collected automatically or after your consent when you visit the website. This includes technical data (e.g., your web browser, operating system, or the time of access). This data is collected automatically as soon as you access the website.
What do we use your data for?
Some of the data is collected to ensure the website functions without errors. Other data may be used to analyze your user behavior. If the website allows for contracts to be entered into or initiated, any data you provide will also be processed for purposes related to contract offers, orders, or other inquiries.
What rights do you have regarding your data?
You have the right to request information about the origin, recipients, and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of this data.
If you have consented to data processing, you may revoke this consent at any time with future effect. In certain circumstances, you also have the right to request that the processing of your personal data be restricted. Furthermore, you have the right to file a complaint with the relevant supervisory authority.
For questions or further information about data protection, you can contact us at any time.
2. Hosting
Service Provider
The service provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter referred to as “Shopify”).
Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address, information about your device, and your browser. Shopify also analyzes visitor numbers, sources of website traffic, customer behavior, and generates user statistics. If you make a purchase on our website, Shopify collects your name, email address, delivery and billing addresses, payment details, and other data related to the purchase (e.g., phone number, transaction amounts, etc.). Shopify uses cookies in your browser for analysis purposes.
For further details, please refer to Shopify’s privacy policy: [https://www.shopify.de/legal/datenschutz](https://www.shopify.de/legal/datenschutz).
The use of Shopify is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in ensuring the most reliable presentation of our website. If specific consent has been obtained, the processing is carried out exclusively based on Article 6(1)(a) of the GDPR and § 25(1) of the TTDSG (German Telecommunications and Telemedia Data Protection Act), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) as defined by the TTDSG. Consent can be revoked at any time.
3. General Information and Mandatory Disclosures
Legal Basis for Data Processing
If you have provided consent for data processing, we process your personal data based on Article 6(1)(a) GDPR or, if special categories of data (as defined in Article 9(1) GDPR) are processed, based on Article 9(2)(a) GDPR. If you have explicitly consented to the transfer of personal data to third countries, the data processing is also carried out under Article 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., device fingerprinting), the data processing is additionally based on § 25(1) TTDSG (German Telecommunications and Telemedia Data Protection Act). Consent can be withdrawn at any time.
If your data is necessary for the performance of a contract or for pre-contractual measures, we process it under Article 6(1)(b) GDPR. Furthermore, we process your data if it is required for compliance with a legal obligation under Article 6(1)(c) GDPR. Data processing may also be based on our legitimate interests under Article 6(1)(f) GDPR. The specific legal basis for processing is outlined in the respective sections of this privacy policy.
Recipients of Personal Data
In the course of our business activities, we work with various external parties. This may involve the transfer of personal data to such external entities. We only share personal data with external parties when it is necessary for fulfilling a contract, when we are legally obligated to do so (e.g., sharing data with tax authorities), when we have a legitimate interest in sharing the data under Article 6(1)(f) GDPR, or when another legal basis permits the data transfer.
When working with data processors, we only share customer personal data based on a valid data processing agreement. For joint processing activities, we establish a joint processing agreement.
Withdrawal of Consent to Data Processing
Many data processing activities require your explicit consent. You can revoke any previously given consent at any time. The legality of data processing carried out prior to the withdrawal remains unaffected.
Right to Object to Data Collection in Special Cases and to Direct Marketing (Article 21 GDPR)
RIGHT TO OBJECT DUE TO YOUR PARTICULAR SITUATION
IF DATA PROCESSING IS CARRIED OUT BASED ON ARTICLE 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION. THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE LEGAL BASIS FOR PROCESSING CAN BE FOUND IN THIS PRIVACY POLICY.
IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ARTICLE 21(1) GDPR).
RIGHT TO OBJECT TO DIRECT MARKETING
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO SUCH PROCESSING AT ANY TIME, INCLUDING PROFILING TO THE EXTENT THAT IT RELATES TO DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ARTICLE 21(2) GDPR).
Right to Lodge a Complaint with a Supervisory Authority
If you believe there has been a violation of GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or the location of the alleged infringement. This right is without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract, in a commonly used, machine-readable format. You also have the right to request the direct transfer of this data to another responsible party, provided this is technically feasible.
Right to Access, Rectification, and Deletion
Under applicable legal provisions, you have the right to request, at any time and free of charge, information about your stored personal data, its origin, recipients, and the purpose of data processing. You also have the right to request rectification or deletion of this data. For such inquiries and further questions on the subject of personal data, you can contact us at any time.
Right to Restrict Processing
You have the right to request the restriction of the processing of your personal data. You can exercise this right by contacting us. This right applies in the following cases:
1. Dispute of Data Accuracy: If you dispute the accuracy of your personal data stored by us, we generally require time to verify your claim. During this verification period, you have the right to request the restriction of processing your personal data.
2. Unlawful Processing: If your personal data is or has been processed unlawfully, you may request restriction of its processing instead of deletion.
3. Data No Longer Needed: If we no longer need your personal data but you require it for the establishment, exercise, or defense of legal claims, you can request restriction of processing.
4. Pending Objection Resolution: If you have filed an objection under Article 21(1) GDPR, a balancing of your and our interests is necessary. While this is under review, you have the right to request the restriction of processing your personal data.
If the processing of your personal data is restricted, this data—aside from storage—may only be processed with your consent or for establishing, exercising, or defending legal claims, for protecting the rights of another natural or legal person, or for reasons of significant public interest in the EU or a member state.
SSL or TLS Encryption
For security and the protection of confidential content (e.g., orders or inquiries you send to us), this site uses SSL or TLS encryption. You can recognize an encrypted connection by the browser’s address bar switching from "http://" to "https://" and the lock symbol in the browser’s address bar. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Objection to Advertising Emails
The use of contact details published under the imprint obligation for sending unsolicited advertising and informational materials is hereby prohibited. We expressly reserve the right to take legal action in the event of the unsolicited receipt of advertising materials, such as spam emails.
4. Data Collection on This Website
Cookies
Our websites use “cookies.” Cookies are small data packets that do not harm your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted after your visit. Persistent cookies remain stored until you delete them or your browser performs an automatic deletion.
Cookies may be set by us (first-party cookies) or by third parties (third-party cookies). Third-party cookies allow the integration of services from third parties (e.g., payment processing services).
Cookies serve various purposes. Many cookies are technically necessary as certain website functions would not work without them (e.g., the shopping cart or video display functions). Other cookies are used to analyze user behavior or for advertising purposes.
Cookies required for electronic communication, certain desired functions (e.g., shopping cart), or website optimization (e.g., audience measurement) are stored based on Article 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically error-free and optimized provision of its services. If consent to store cookies or similar recognition technologies was requested, the processing is based exclusively on that consent (Article 6(1)(a) GDPR and § 25(1) TTDSG). Consent may be withdrawn at any time.
You can configure your browser to notify you about cookie usage, allow cookies only in specific cases, exclude cookies for certain cases or entirely, and enable automatic deletion of cookies when the browser is closed. Deactivating cookies may limit the functionality of this website.
The specific cookies and services used on this website are listed in this privacy policy.
Contact Form
If you submit inquiries to us via a contact form, your details from the form, including the contact information you provide, will be stored to process your inquiry and for follow-up questions. We do not share this data without your consent.
Data processing for inquiries is based on Article 6(1)(b) GDPR if your request relates to a contract or pre-contractual measures. In all other cases, the processing is based on our legitimate interest in effectively handling inquiries (Article 6(1)(f) GDPR) or your consent (Article 6(1)(a) GDPR), if requested. Consent may be withdrawn at any time.
The data you enter in the contact form remains with us until you request its deletion, withdraw your consent for storage, or the purpose for data storage no longer applies (e.g., once your inquiry has been processed). Mandatory legal provisions, especially retention periods, remain unaffected.
Inquiries via Email, Telephone, or Fax
If you contact us via email, telephone, or fax, your inquiry, including all related personal data (e.g., name, inquiry), will be stored and processed for the purpose of handling your request. We do not share this data without your consent.
Data processing is based on Article 6(1)(b) GDPR if your inquiry relates to a contract or pre-contractual measures. Otherwise, processing is based on our legitimate interest in effectively managing inquiries (Article 6(1)(f) GDPR) or your consent (Article 6(1)(a) GDPR), if provided. Consent can be withdrawn at any time.
The data sent to us via inquiries will remain with us until you request deletion, withdraw consent, or the purpose for storage ceases to exist (e.g., after processing your request). Mandatory legal obligations, particularly statutory retention periods, remain unaffected.
4.1 Use of Google Services
We use the technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google") as described below. Information about your use of our website is automatically collected by these Google technologies and usually transmitted to and stored on a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Unless stated otherwise for the individual technologies, data processing is carried out on the basis of a joint data controller agreement according to Article 26 GDPR. Further information on data processing by Google can be found in Google's privacy notices.
Service Providers Outside the EU/EEA
Our service providers may be based in or use servers located in countries outside the EU and EEA where the European Commission has determined an adequate level of data protection.
In cases where service providers or servers are based in countries without an adequacy decision, our collaboration relies on the European Commission's standard data protection clauses.
Google Analytics
For the purpose of website analysis, Google Analytics automatically collects and stores data (such as your IP address, time of visit, device and browser information, and information on your usage of our website), which is then used to create pseudonymized user profiles. Cookies may also be utilized for this purpose.
If you access our website from the EU, your IP address is stored on an EU-based server to derive location information and is then deleted immediately before traffic is forwarded to Google's servers for further processing. Data processing is based on a data processing agreement with Google.
To optimize the marketing of our website, we have activated data sharing settings for "Google Products and Services." This enables Google to access the data collected and processed by Google Analytics for improving its services. This data sharing is based on an additional agreement between data controllers. We do not influence any further processing of the data by Google.
To create and conduct tests, we also use the Google Analytics extension feature, Google Optimize.
For web analysis, the Google Signals extension in Google Analytics enables "cross-device tracking." If your internet-enabled devices are linked to your Google account and you have activated the "personalized advertising" setting in your Google account, Google can generate reports on your usage patterns (particularly cross-device user numbers), even when you switch devices. We do not process any personal data in this context; we only receive statistics created using Google Signals.
Google Ads
To display advertisements in Google search results and on third-party websites, the Google Remarketing Cookie is set when you visit our website. This cookie enables interest-based advertising through the automatic collection and processing of data (such as IP address, time of visit, device and browser information, and pages you visited), using a pseudonymous cookie ID.
Further data processing occurs only if you have enabled the "personalized advertising" setting in your Google account. If you are logged into your Google account while visiting our website, Google uses your data in combination with Google Analytics data to create and define audience lists for cross-device remarketing.
For website analysis and event tracking, we use Google Ads Conversion Tracking to measure your subsequent usage behavior after you have accessed our website through a Google Ads advertisement. Cookies may be used to collect data (such as IP address, time of visit, device and browser information, and your interactions with our website based on events defined by us, such as visiting specific pages or signing up for a newsletter). Pseudonymized user profiles can be created from this data.
4.2. Facebook Pixel, Custom Audiences, and Facebook Conversion
Within our online offering, we use the so-called "Facebook Pixel" of the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or, if you are based in the EU, by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook"). This is done based on our legitimate interests in analyzing, optimizing, and economically operating our online offering.
Facebook is certified under the Privacy Shield agreement, providing a guarantee to comply with European data protection laws (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
With the help of the Facebook Pixel, Facebook can determine the visitors of our online offering as a target group for displaying ads (so-called "Facebook Ads"). Accordingly, we use the Facebook Pixel to ensure that the Facebook Ads we place are shown only to those Facebook users who have also shown an interest in our online offering or who possess certain characteristics (e.g., interests in specific topics or products based on the websites visited), which we transmit to Facebook (so-called "Custom Audiences"). The Facebook Pixel also helps us ensure that our Facebook Ads align with the potential interests of users and do not appear intrusive. Furthermore, the Facebook Pixel enables us to track the effectiveness of Facebook ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook advertisement (so-called "Conversion").
Facebook processes data within the framework of Facebook's Data Policy. General information on the display of Facebook Ads can be found in Facebook's Data Policy: https://www.facebook.com/policy.php. For specific details about the Facebook Pixel and how it works, visit Facebook’s Help section: https://www.facebook.com/business/help/651294705016616.
You can opt out of Facebook Pixel tracking and the use of your data for displaying Facebook Ads. To adjust which types of advertisements are shown to you on Facebook, you can visit the page provided by Facebook and follow the instructions for configuring usage-based advertising settings: https://www.facebook.com/settings?tab=ads. These settings apply across all devices, meaning they will be implemented on both desktop and mobile devices.
Additionally, you can opt out of cookies used for reach measurement and advertising purposes through the opt-out page of the Network Advertising Initiative (http://optout.networkadvertising.org/) as well as the U.S. website (http://www.aboutads.info/choices) or the European website (http://www.youronlinechoices.com/uk/your-ad-choices/).
5. Social Media
This website integrates features of the Instagram service. These features are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and the Instagram server, allowing Instagram to receive information about your visit to this website.
If you are logged into your Instagram account, clicking the Instagram button will allow you to link the content of this website to your Instagram profile. This enables Instagram to associate your visit to this website with your user account. Please note that, as the website provider, we have no knowledge of the content of the data transmitted or how Instagram uses it.
The use of this service is based on your consent, pursuant to Article 6(1)(a) GDPR and Section 25(1) of the Telecommunications-Telemedia Data Protection Act (TTDDG). Consent can be withdrawn at any time.
If personal data is collected on our website using the described tool and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Article 26 GDPR). This joint responsibility is limited solely to the collection of data and its transfer to Facebook or Instagram. Any subsequent processing by Facebook or Instagram is not part of this shared responsibility.
The obligations under joint responsibility have been outlined in an agreement on joint processing, which can be accessed here:
[https://www.facebook.com/legal/controller_addendum](https://www.facebook.com/legal/controller_addendum).
According to this agreement, we are responsible for providing privacy information and implementing the Facebook or Instagram tool on our website in compliance with data protection laws. Facebook is responsible for the data security of Facebook and Instagram products.
Affected individuals (e.g., for data access requests) can directly exercise their rights with Facebook or Instagram. If such rights are asserted with us, we are required to forward these requests to Facebook.
Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Details are available here:
[https://www.facebook.com/legal/EU_data_transfer_addendum](https://www.facebook.com/legal/EU_data_transfer_addendum)
[https://privacycenter.instagram.com/policy/](https://privacycenter.instagram.com/policy/)
[https://de-de.facebook.com/help/566994660333381](https://de-de.facebook.com/help/566994660333381)
Further information is available in Instagram's Privacy Policy:
[https://privacycenter.instagram.com/policy/](https://privacycenter.instagram.com/policy/).
Meta Platforms Ireland Limited is certified under the **EU-US Data Privacy Framework (DPF)**, an agreement ensuring compliance with European data protection standards in the USA. Companies certified under the DPF are committed to adhering to these standards. Further details are available at:
[https://www.dataprivacyframework.gov/participant/4452](https://www.dataprivacyframework.gov/participant/4452).
TikTok
When visiting this website, personal data is processed, including:
- Data categories processed: Information about website usage and logged interactions (e.g., clicks on specific elements).
- Purpose of processing: Analyzing user behavior, evaluating the impact of online marketing campaigns, and selecting online advertisements on other platforms through real-time bidding based on usage behavior.
- Legal basis for processing: Your consent, as per Article 6(1)(a) GDPR.
Data may be transmitted to TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland ([https://www.tiktok.com](https://www.tiktok.com)). The legal basis for data transfers to TikTok is your consent, pursuant to Article 6(1)(a) GDPR, which may also involve transferring personal data to countries outside the European Union. This is done based on your explicit consent under Article 6(1)(a) and Article 49(1)(a) GDPR.
For further information or to contact TikTok Technology Limited’s Data Protection Officer, visit:
[https://www.tiktok.com/legal/privacy-policy-eea?lang=de](https://www.tiktok.com/legal/privacy-policy-eea?lang=de).
6. Newsletter Data
If you wish to receive the newsletter offered on our website, we require an email address from you, as well as information that allows us to verify that you are the owner of the provided email address and agree to receive the newsletter. No additional data is collected, or only on a voluntary basis. These data are used exclusively for sending the requested information and are not shared with third parties.
The processing of data entered into the newsletter registration form is based solely on your consent (Article 6(1)(a) GDPR). You may revoke your consent to store the data, email address, and its use for sending the newsletter at any time, for instance, via the "Unsubscribe" link in the newsletter. The legality of the data processing already carried out remains unaffected by the revocation.
The data you provide for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe or the purpose ceases to exist.
We reserve the right to delete or block email addresses from our newsletter distribution list at our discretion within the scope of our legitimate interest under Article 6(1)(f) GDPR.
Data stored by us for other purposes remain unaffected.
After unsubscribing from the newsletter distribution list, your email address may be stored in a blacklist by us or the newsletter service provider to prevent future mailings. Data from the blacklist will only be used for this purpose and will not be combined with other data. This is in both your interest and ours in complying with legal requirements for newsletter distribution (legitimate interest under Article 6(1)(f) GDPR). The storage in the blacklist is indefinite. You can object to the storage if your interests outweigh our legitimate interest.
Newsletter Distribution to Existing Customers
If you purchase goods or services from us and provide your email address, this email address may subsequently be used by us to send newsletters, provided that we inform you of this in advance. In this case, the newsletter will only contain direct advertising for similar goods or services from our offerings.
You can unsubscribe from this newsletter at any time. An unsubscribe link is included in every newsletter. The legal basis for sending the newsletter in this case is Article 6(1)(f) GDPR in conjunction with Section 7(3) of the German Unfair Competition Act (UWG).
After unsubscribing from the newsletter distribution list, your email address may be stored in a blacklist by us to prevent future mailings. Data from the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and ours in complying with legal requirements for newsletter distribution (legitimate interest under Article 6(1)(f) GDPR). The storage in the blacklist is indefinite. You can object to the storage if your interests outweigh our legitimate interest.
7. Plugins and Tools
YouTube with Enhanced Privacy Mode
This website integrates videos from the YouTube platform. The operator of YouTube is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit a page on this website that includes a YouTube video, a connection to YouTube's servers is established. The YouTube server is informed about which pages you visited. If you are logged into your YouTube account, you allow YouTube to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.
We use YouTube in enhanced privacy mode. According to YouTube, videos played in enhanced privacy mode are not used to personalize your browsing experience on YouTube. Advertisements displayed in enhanced privacy mode are also not personalized. In enhanced privacy mode, no cookies are set. However, so-called **local storage elements** are stored in the user's browser, which may contain personal data and serve similar functions to cookies for recognition purposes. You can find more details about enhanced privacy mode here:
[https://support.google.com/youtube/answer/171780](https://support.google.com/youtube/answer/171780).
Further data processing may be triggered after activating a YouTube video, over which we have no control.
The use of YouTube is in the interest of providing an appealing presentation of our online offerings. This constitutes a legitimate interest pursuant to Article 6(1)(f) GDPR. If consent is requested, processing is carried out exclusively based on Article 6(1)(a) GDPR and Section 25(1) of the German Telecommunication and Telemedia Data Protection Act (TTDSG), provided that the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) as defined by the TTDSG. Consent can be revoked at any time.