data protection

Privacy Policy

1) Introduction and contact details of the responsible party

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data includes all data that can be used to identify you personally.

1.2 The responsible party for data processing on this website in accordance with the General Data Protection Regulation (GDPR) is Bertrand Dahi, Alte Eisenacher Str. 25, 99834 Gerstungen, Germany, Tel.: +4915792557024, Email: kontakt@eichenhain.com. The entity responsible for processing personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

2) Data collection when visiting our website

2.1 When you use our website for informational purposes only, meaning you do not register or otherwise provide us with information, we only collect data that your browser transmits to the server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/reference from which you arrived at the page.
  • Used Browser
  • Operating System Used
  • Used IP address (if applicable: in anonymized form)

The processing is carried out in accordance with Article 6(1)(f) of the GDPR based on our legitimate interest in improving the stability and functionality of our website. There will be no transfer or other use of the data. However, we reserve the right to review the server log files retrospectively if there are concrete indications of unlawful use.

2.2 This website uses security measures to protect the transmission of personal data and other confidential content.z.B. Orders or inquiries to the responsible party are secured with SSL or TLS encryption. You can recognize a secure connection by the string "https://" and the lock symbol in your browser's address bar.

3) Hosting & Content Delivery Network

For hosting our website and displaying the page content, we use a provider that delivers its services either directly or through selected subcontractors exclusively on servers within the European Union.

All data collected on our website is processed on these servers.

We have entered into a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

4) Cookies

To make your visit to our website attractive and to enable the use of certain features, we use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device for a longer period and allow the storage of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of the cookie settings of your web browser.

If individual cookies used by us also process personal data, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the case of granted consent, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the site visit.

You can configure your browser to be informed about the setting of cookies and decide individually on their acceptance, or you can exclude the acceptance of cookies for specific cases or in general.

Please note that if cookies are not accepted, the functionality of our website may be limited.

5) Contact Us

5.1 Own review reminder

We will use your email address solely based on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR to send you a one-time reminder to leave a review of your order. You can revoke your consent at any time by sending a message to the data processing controller.

5.2 ShopVote

For review reminders, we use the services of the following provider: Blickreif GmbH, Schulstraße 46, 80634 Munich, Germany.

Exclusively based on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, we will transmit your email address and possibly other customer data to the provider so that they can contact you via email with a review reminder.

You can revoke your consent at any time with effect for the future towards us or the provider.

We have entered into a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

5.3 WhatsApp Business

You have the option to contact us via the messaging service WhatsApp of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For this purpose, we use the so-called "Business Version" of WhatsApp.

If you contact us via WhatsApp regarding a specific transaction (for example, an order you have placed), we will store and use the mobile phone number you use on WhatsApp, as well as – if provided – your first and last name in accordance with Art. 6 para. 1 lit. b of the GDPR to process and respond to your request. Based on the same legal basis, we may ask you via WhatsApp to provide additional information (order number, customer number, address, or email address) in order to assign your inquiry to a specific transaction.

Use our WhatsApp contact for general inquiries (such as about our range of services, availability, or our online presence). We will store and use the mobile number you use on WhatsApp, as well as your first and last name if provided, in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in efficiently and promptly providing the requested information.

Your data will only be used to respond to your inquiry via WhatsApp. There will be no sharing with third parties.

Please note that WhatsApp Business gains access to the address book of the mobile device we use for this purpose and automatically transmits phone numbers stored in the address book to a server of the parent company Meta Platforms Inc. in the USA. For the operation of our WhatsApp Business account, we use a mobile device that only contains the WhatsApp contact details of users who have contacted us via WhatsApp.

This ensures that every person whose WhatsApp contact details are stored in our address book has already consented to the transmission of their WhatsApp phone number from the address books of their chat contacts upon first use of the app on their device by accepting the WhatsApp terms of use in accordance with Art. 6 para. 1 lit. a GDPR. The transmission of data from users who do not use WhatsApp and/or have not contacted us via WhatsApp is therefore excluded.

The purpose and scope of data collection and the further processing and use of data by WhatsApp, as well as your related rights and options for protecting your privacy, can be found in WhatsApp's privacy policy: https://www.whatsapp.com/legal/?eea=1#privacy-policy

We have entered into a data processing agreement with the provider that protects the data of our website visitors and prohibits sharing with third parties.

As part of the aforementioned processes, data transfers to servers of Meta Platforms Inc. in the USA may occur.

For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

5.4 In the context of contacting us (z.B. Personal data will be processed – exclusively for the purpose of handling and responding to your request and only to the extent necessary for that purpose – via the contact form or email.

The legal basis for processing this data is our legitimate interest in addressing your concern in accordance with Art. 6 para. 1 lit. f GDPR. If your contact is aimed at a contract, then the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter in question has been conclusively resolved and provided that there are no legal retention obligations to the contrary.

6) Data processing when opening a customer account

In accordance with Article 6(1)(b) of the GDPR, personal data will continue to be collected and processed to the extent necessary when you provide us with this information during the opening of a customer account. The data required for account creation can be found in the input fields of the corresponding form on our website.

You can delete your customer account at any time by sending a message to the o.g. The address of the responsible party will be provided. After the deletion of your customer account, your data will be deleted, provided that all contracts concluded in this regard have been fully settled, no legal retention periods are opposed, and we have no legitimate interest in further storage.

7) Use of customer data for direct marketing

7.1 Registration for our email newsletter

When you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. Providing additional data is voluntary and will be used to address you personally. For the newsletter distribution, we use the so-called double opt-in procedure, which ensures that you will only receive the newsletter after you have explicitly confirmed your consent to receive it by clicking on a verification link sent to the provided email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR. In this process, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any potential misuse of your email address at a later time. The data we collect during the newsletter registration will be used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time using the designated link in the newsletter or by sending a corresponding message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly removed from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data in a manner that is legally permitted and of which we inform you in this statement.

7.2 ActiveCampaign

The shipping of our email newsletters is carried out by this provider: ActiveCampaign, LLC, 150 N. Michigan Ave Suite 1230, Chicago, IL, USA.

Based on our legitimate interest in effective and user-friendly newsletter marketing, we will share the data you provided during the newsletter registration in accordance with Art. 6 para. 1 lit. f GDPR with this provider, so that they can handle the newsletter distribution on our behalf.

Subject to your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the provider also conducts a statistical success evaluation of newsletter campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the content of the newsletter. Device information is also collected.z.B. The time of the call, IP address, browser type, and operating system are collected and evaluated, but not merged with other data sets.

You can revoke your consent to newsletter tracking at any time with effect for the future.

We have entered into a data processing agreement with the provider that protects the data of our website visitors and prohibits sharing with third parties.

For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

7.3 Product availability notification via email

For temporarily unavailable items, you can sign up to receive email notifications about product availability. We will send you an email notification once regarding the availability of the specific item you selected. The only required information for sending this notification is your email address. Providing additional data is voluntary and may be used to address you personally. For sending emails, we use the so-called double opt-in procedure, which ensures that you will only receive a notification after you have explicitly confirmed your consent by clicking on a verification link sent to the provided email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR. In this context, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any potential misuse of your email address at a later time. The data we collect during your registration for our email notification service regarding product availability will be used strictly for its intended purpose.

You can unsubscribe from the availability notifications at any time by sending a corresponding message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly removed from our designated distribution list, unless you have explicitly consented to further use of your data or we reserve the right to use your data in a manner that is legally permitted and of which we inform you in this statement.

7.4 Shopping cart reminders via email

In case you abandon your shopping with us before completing your order, you have the option to receive a one-time reminder via email about the contents of your virtual shopping cart.

The only mandatory information for sending this reminder is your email address. Providing additional data is voluntary and may be used to address you personally. For sending emails, we use the so-called Double Opt-in procedure, which ensures that you will only receive a notification once you have explicitly confirmed your consent by clicking on a verification link sent to the provided email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR for sending a shopping cart reminder. In this process, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any potential misuse of your email address at a later time. The data we collect during your registration for our email notification service will be used strictly for the intended purpose.

You can unsubscribe from the cart reminders at any time by sending a corresponding message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly removed from our designated distribution list, unless you have explicitly consented to further use of your data or we reserve any additional data usage that is legally permitted and of which we inform you in this statement.

8) Data processing for order processing

8.1 As far as necessary for the processing of the contract for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details you provided during the order to inform you personally as part of our legal information obligations in accordance with Art. 6 para. 1 lit. c GDPR. Your contact details will be used strictly for the purpose of communicating updates owed by us and will only be processed by us to the extent necessary for the respective information.

To process your order, we also work with the service provider(s) listed below, who assist us in whole or in part with the execution of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

8.2 Monta

For order processing, we use the following provider: Monta Krefeld GmbH, Märkische Straße 10, 47809 Krefeld.

Name, address, and any other personal data will be shared with the provider in accordance with Art. 6 para. 1 lit. b GDPR solely for the purpose of processing the online order. Your data will only be shared to the extent that it is actually necessary for the processing of the order.

8.3 Transfer of personal data to shipping service providers

- DHL

As a transport service provider, we use the following provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany.

We will pass on your email address and/or phone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR prior to the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your explicit consent during the ordering process. Otherwise, we will only provide the recipient's name and delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The transfer will only take place to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

The consent can be revoked at any time with effect for the future towards the responsible party mentioned above or towards the provider.

- UPS

As a transport service provider, we use the following provider: United Parcel Service Deutschland Inc. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany.

We will pass on your email address and/or phone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR prior to the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your explicit consent during the ordering process. Otherwise, we will only provide the recipient's name and delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The transfer will only take place to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.

The consent can be revoked at any time with effect for the future towards the responsible party mentioned above or towards the provider.

8.4 Use of payment service providers (payment services)

- Klarna

This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden.

When selecting a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment information provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is carried out solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider advances the payment (such as invoice or installment purchase or direct debit), you will also be asked to provide certain personal information during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, information about an alternative payment method).

In order to protect our legitimate interest in assessing the creditworthiness of our customers, we will forward this data to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks, based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment option you selected can be granted in terms of payment and/or default risk.

For the decision-making process during the application review, in addition to internal provider criteria according to Art. 6 para. 1 lit. f GDPR, identity and credit information from the following credit agencies may also be included:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.

- Mollie

This website offers one or more online payment methods from the following provider: Mollie. B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands

When selecting a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment information provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is carried out solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

- PayPal

This website offers one or more online payment methods from the following provider: PayPal (Europe) S.a.r.l. and Co., S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

When selecting a payment method from the provider that requires you to pay in advance, your payment information provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

When selecting a payment method where we advance the payment, you will also be asked to provide certain personal information (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, details for an alternative payment method) during the ordering process.

In such cases, to protect our legitimate interest in assessing your creditworthiness, we will forward this data to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider will evaluate, based on the personal data you provided as well as additional data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment option you selected can be granted in light of payment and/or default risks.

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.

- Stripe

This website offers one or more online payment methods from the following provider: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

When selecting a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment information provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the contents of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is carried out solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider advances the payment (such as invoice or installment purchase or direct debit), you will also be asked to provide certain personal information during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, information about an alternative payment method).

In order to protect our legitimate interest in assessing the creditworthiness of our customers, we will forward this data to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks, based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment option you selected can be granted in terms of payment and/or default risk.

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.

9) Online Marketing

Google AdSense

This website uses Google AdSense, a web advertising service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google AdSense uses so-called cookies, which are text files stored on your computer that enable an analysis of your use of the website. In addition, Google AdSense also uses so-called "web beacons" (small invisible graphics) to collect information, which allows for the recording, collection, and evaluation of simple actions such as visitor traffic on the website. The information generated by the cookie and/or web beacon (including your IP address) about your use of this website is usually transmitted to a Google server and stored there. This may also involve transmission to servers of Google LLC in the USA.

Google uses the information obtained in this way to evaluate your usage behavior concerning AdSense advertisements. The IP address transmitted by your browser as part of Google AdSense will not be merged with other data from Google. The information collected by Google may be transferred to third parties if required by law and/or to the extent that third parties process this data on behalf of Google.
All of the processing described above, particularly retrieving information on the device used via cookies and/or web beacons, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of Google AdSense will not take place during your visit to the site.

You can revoke your consent at any time with effect for the future by disabling this service in the "Cookie Consent Tool" provided on the website.

For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

10) Web Analytics Services

10.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which allows for an analysis of your use of our website.

By default, when visiting the website, Google Analytics 4 sets cookies, which are small text files stored on your device that collect certain information. This information includes your IP address, which is truncated by Google to exclude the last digits in order to prevent direct personal identification.

The information is transmitted to servers operated by Google and processed there. This may also involve transmissions to Google LLC based in the USA.

Google uses the information collected on our behalf to evaluate your use of the website, compile reports on website activities for us, and provide additional services related to website usage and internet usage. The IP address transmitted and truncated by your browser as part of Google Analytics will not be merged with other data from Google. The data collected through the use of Google Analytics 4 will be stored for a period of two months and then deleted.

All of the aforementioned processes, especially the setting of cookies on the device used, will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
Without your consent, the use of Google Analytics 4 will not take place during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your right of withdrawal, please disable this service using the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with Google that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information regarding Google Analytics 4 can be found at https://business.safety.google/intl/de/privacy/, , https://policies.google.com/privacy?hl=de&gl=de and under https://policies.google.com/technologies/partner-sites

Demographic characteristics
Google Analytics 4 uses the special feature "demographic characteristics" and can generate statistics that provide insights into the age, gender, and interests of website visitors. This is done by analyzing advertising and information from third parties. As a result, target audiences for marketing activities can be identified. However, the collected data cannot be attributed to any specific individual and will be deleted after a storage period of two months.

Google Signals
As an extension to Google Analytics 4, Google Signals can be used on this website to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google, subject to your consent for the use of Google Analytics in accordance with Art. 6 para. 1 lit. a GDPR, can analyze your usage behavior across devices and create database models, including cross-device conversions. We do not receive any personal data from Google, only statistics. If you wish to stop cross-device analysis, you can disable the "Personalized Advertising" feature in your Google account settings. Please follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de For more information about Google Signals, please visit the following link: https://support.google.com/analytics/answer/7532985?hl=de

User IDs
As an extension to Google Analytics 4, the "UserIDs" feature can be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Art. 6 para. 1 lit. a GDPR, set up an account on this website, and log in to this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

10.2 Google Tag Manager

This website uses the "Google Tag Manager," a service provided by the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as "Google").

The Google Tag Manager provides a technical foundation for consolidating various web applications, including tracking and analytics services, allowing them to be calibrated, controlled, and linked to conditions through a unified user interface. The Google Tag Manager itself does not store information on user devices or read it. The service also does not perform independent data analyses. However, when a page is accessed, your IP address is transmitted to Google and may be stored there. It is also possible for this information to be transmitted to servers of Google LLC in the USA.

This processing will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of Google Tag Manager will not occur during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your revocation, please disable this service in the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

Further legal information regarding Google Tag Manager can be found at https://business.safety.google/intl/de/privacy/ and https://policies.google.com/privacy?hl=de&gl=de

10.3 Matomo

This website uses a web analytics service from the following provider: InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand, ("Matomo").

To protect the site visitors, Matomo uses a so-called "config_id" to enable various analyses of site usage within a short time frame of up to 24 hours. The "config_id" is a randomly set, time-limited hash of a limited set of settings and attributes of the visitor. The config_id or config hash is a string that is calculated for a visitor based on their operating system, browser, browser plugins, IP address, and browser language. Matomo does not use device fingerprinting and uses an anonymized IP address of the site visitor to create the "config_id."

If the processed information includes personal user data, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes. To object to the processing of your visitor data in the future, we provide a separate option to do so on our website.

Data is only transmitted to the provider if the service is not hosted on our servers. In the case of self-hosting, there is no transmission of data collected through the service to the provider.

Unless the service is hosted on our servers, we have entered into a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to New Zealand, an adequacy decision by the EU Commission applies in this case, which certifies compliance with European data protection standards for international data transfers.

10.4 Umami

This website uses a web analytics service from the following provider: Umami Software, Inc., 1362 42nd Ave., San Francisco, CA 94122, USA.

To protect site visitors, Umami uses a so-called "Distinct ID" to enable various analyses of site usage within a short time frame of up to 24 hours. The "Distinct ID" is a randomly generated, time-limited hash of a limited set of settings and attributes of the visitor, calculated based on their operating system, browser, browser plugins, previously anonymized IP address, and browser language.

The "Distinct ID" is therefore created solely based on information that cannot personally identify the visitor.

If the processed information exceptionally includes personal user data, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes. You can permanently object to the collection and storage of your visitor data for the future by notifying us in this case.

Information is only transmitted to the provider if the service is not hosted on our servers. In the case of self-hosting, no transmission of information collected through the service to the provider takes place.

Unless the service is hosted on our servers, we have entered into a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For the transmission of data to the USA, the provider relies on the standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.

11) Retargeting/Remarketing and Conversion Tracking

Google Ads Remarketing

This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

For this purpose, Google sets a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID based on the pages you visit. Further data processing only occurs if you have consented to Google linking your internet and app browsing history with your Google account and using information from your Google account to personalize ads you view on the web. If you are logged into Google during your visit to our website, Google uses your data along with Google Analytics data to create and define audience lists for cross-device remarketing. To do this, your personal data is temporarily linked by Google with Google Analytics data to form audiences. As part of using Google Ads Remarketing, there may also be a transfer of personal data to the servers of Google LLC in the USA.

All of the processing described above, particularly the setting of cookies to read information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, the use of retargeting technology will not take place during your visit to the site.

You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

Details about the processing initiated by Google and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

12) Page functionalities

12.1 ShopVote graphics

On our website, graphic elements from the following provider are integrated to display external customer reviews and/or an externally awarded quality seal: Blickreif GmbH, Schulstraße 46, 80634 Munich, Germany.

When you visit a page on our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to load the elements properly. In this process, certain browser information, including your IP address, is transmitted to the provider.

If personal data is also processed in this context, this is done in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the optimal marketing of our offerings and the appealing design of our online presence.

12.2 Cloudflare Turnstile

On this website, we use the CAPTCHA service of the following provider: Cloudflare, Inc., 101 Townsend St. San Francisco, CA 94107, USA.

The service checks whether an input is made by a natural person or abusively through machine and automated processing, and blocks spam, DDoS attacks, and similar automated malicious access. To ensure that an action is taken by a human and not by an automated bot, Cloudflare Turnstile collects the IP address of the device used, detection data of the browser and operating system type used, as well as the date and duration of the visit, and transmits this information for evaluation to the provider's servers.

The described processing will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

13) Tools and Miscellaneous

13.1 Lexware Office

For the completion of our accounting, we use the service of the cloud-based accounting software from the following provider: Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany.

The provider processes incoming and outgoing invoices as well as, if applicable, the bank transactions of our company in order to automatically capture invoices, match them to the transactions, and generate the financial accounting from this in a semi-automated process.

If personal data is also processed in this context, the processing is based on our legitimate interest in an efficient organization and documentation of our business processes in accordance with Art. 6 para. 1 lit. f GDPR.

13.2 Cookie Consent Tool

This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users in the form of an interactive user interface when the page is accessed, allowing users to grant consent for specific cookies and/or cookie-based applications by checking boxes. With the use of this tool, all consent-required cookies/services are only loaded if the respective user has granted the corresponding consents by checking the boxes. This ensures that such cookies are only set on the user's device if consent has been given.

The tool uses technically necessary cookies to store your cookie preferences. Personal user data is generally not processed in this context.

In individual cases, if the processing of personal data (such as the IP address) is necessary for the purpose of storing, assigning, or logging cookie settings, this will be carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a legally compliant, user-specific, and user-friendly consent management for cookies, and thus in a legally compliant design of our online presence.

Another legal basis for processing is also Article 6(1)(c) of the GDPR. As the data controller, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user consent.

As required, we have entered into a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further information about the operator and the settings options of the cookie consent tool can be found directly in the corresponding user interface on our website.

14) Rights of the Data Subject

14.1 The applicable data protection law grants you the following rights as a data subject regarding the processing of your personal data against the controller (rights of access and intervention), with reference to the respective legal basis for the conditions of exercise:

  • Right of access according to Art. 15 GDPR;
  • Right to rectification according to Art. 16 GDPR;
  • Right to erasure pursuant to Article 17 GDPR;
  • Right to restriction of processing according to Article 18 GDPR;
  • Right to information according to Art. 19 GDPR;
  • Right to data portability according to Art. 20 GDPR;
  • Right to withdraw consent given pursuant to Art. 7 para. 3 GDPR;
  • Right to lodge a complaint pursuant to Article 77 GDPR.

14.2 RIGHT OF WITHDRAWAL

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR PREVAILING LEGITIMATE INTEREST AS PART OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING PROTECTABLE REASONS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA CONCERNING SUCH MARKETING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT OF OBJECTION, WE WILL CEASE PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.

15) Duration of storage of personal data

The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing, and – where applicable – additionally by the respective statutory retention period.z.B. Commercial and tax-related retention periods.

When processing personal data based on explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the affected data will be stored until you revoke your consent.

There are legal retention periods for data processed in the context of contractual or contract-like obligations based on Article 6 (1) (b) of the GDPR. These data will be routinely deleted after the retention periods expire, provided they are no longer necessary for contract fulfillment or contract initiation and/or we have no legitimate interest in continuing to store them.

When processing personal data based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

When processing personal data for the purpose of direct marketing based on Article 6(1)(f) of the GDPR, this data will be stored until you exercise your right to object under Article 21(2) of the GDPR.

Unless otherwise stated in the additional information of this declaration regarding specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.

Status: 29.07.2025, 6:18:48 PM