Data protection

 

DATA PROTECTION DECLARATION

1) Introduction and contact details of the person responsible

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data refers to all data that can be used to identify you personally.

1.2 The responsible party for data processing on this website in accordance with the General Data Protection Regulation (GDPR) is XXOO Pets Family GmbH, Turmstraße 8, 4020 Linz, Austria, Email: support@xxoopetsfamily.de. The entity responsible for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

2) Data collection when visiting our website

2.1 When using our website for informational purposes only, meaning if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the web server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/reference from which you arrived at the page
  • Browser used
  • Used Operating System
  • Used IP address (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. There is no transfer or other use of the data. However, we reserve the right to review the server log files retrospectively should there be concrete indications of unlawful use.

2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser's address bar.

3) Hosting & Content-Delivery-Network

Shopify

"For hosting our website and displaying the page content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ('Shopify')"

Data is also transmitted to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

All data collected on our website is processed on the provider's servers. We have entered into a data processing agreement with the provider that ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

"In the case of data transfer to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission."

4) Cookies

"To make visiting our website attractive and to enable the use of certain functions, we use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called 'session cookies'), while others remain on your device for a longer period and allow the storage of page settings (so-called 'persistent cookies'). In the latter case, you can find the storage duration in the overview of the cookie settings of your web browser."

If individual cookies used by us also process personal data, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the case of granted consent, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the site visit.

You can configure your browser to be informed about the setting of cookies and to decide individually on their acceptance or to exclude the acceptance of cookies for specific cases or in general.

Please note that if cookies are not accepted, the functionality of our website may be limited.

5) Contact

5.1 Shopify Inbox

This website uses the live chat system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

The processing of personal data transmitted via chat is carried out either in accordance with Art. 6 para. 1 lit. b GDPR, as it is necessary for the initiation or execution of the contract, or in accordance with Art. 6 para. 1 lit. f GDPR due to our legitimate interest in effectively supporting our website visitors.
The data you have provided will be deleted, subject to any conflicting legal retention periods, once the matter in question has been conclusively clarified.

Additionally, for the purpose of creating pseudonymized usage profiles, further information may be collected and evaluated using cookies, which, however, do not serve to identify you personally and are not merged with other datasets. If this information has a personal reference, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the statistical analysis of user behavior for optimization purposes.

"The setting of cookies can be prevented by appropriate browser settings. However, the functionality of our website may be limited in this case."
"You can object to the collection and storage of data for the purpose of creating a pseudonymized user profile at any time with effect for the future."

Data is also transmitted to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

"We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties."

"In the case of data transfer to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission."

5.2 Judge.me

"For review reminders, we use the services of the following provider: Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom"

"Exclusively based on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, we will transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder via email."

You can revoke your consent at any time with effect for the future towards us or the provider.

"We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties."

"In the case of data transmission to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission."

5.3 Trusted Shops

"For review reminders, we use the services of the following provider: Trusted Shops AG, Subbelrather Str. 15c, 50823 Cologne, Germany"

"Exclusively based on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, we will transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder via email."

You can revoke your consent at any time with effect for the future towards us or the provider.

"We are jointly responsible with the provider for the processing described above in accordance with Art. 26 GDPR. The contract on joint responsibility can be viewed here:" https://help.etrusted.com/hc/de/articles/4402587369105-Vertrag-%C3%BCber-die-gemeinsame-Verantwortlichkeit-nach-DSGVO

5.4 In the context of contacting us (e.g. via contact form or email), personal data will be processed – solely for the purpose of handling and responding to your request and only to the extent necessary for that purpose.

The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 para. 1 lit. f GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no legal retention obligations to the contrary.

6) Comment function

As part of the comment function on this website, in addition to your comment, information about the time of creation of the comment and the commentator name you have chosen will be stored and published on this website. Furthermore, your IP address will be logged and stored. This storage of the IP address is done for security reasons and in case the affected person violates the rights of third parties or posts illegal content through a submitted comment. We need your email address to contact you in case a third party should contest your published content as illegal.

The legal basis for the storage of your data is Article 6(1)(b) and (f) of the GDPR. We reserve the right to delete comments if they are challenged as unlawful by third parties.

7) Data processing when opening a customer account

According to Art. 6 para. 1 lit. b GDPR, personal data will continue to be collected and processed to the extent necessary when you provide us with this information when opening a customer account. The data required for account opening can be found in the input mask of the corresponding form on our website.

"Deletion of your customer account is possible at any time and can be done by sending a message to the above-mentioned address of the responsible party. After deletion of your customer account, your data will be deleted, provided that all contracts concluded in this regard have been fully settled, no legal retention periods are opposed, and we have no legitimate interest in further storage."

8) Use of customer data for direct marketing

8.1 Registration for our email newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing additional data is voluntary and will be used to address you personally. For the newsletter dispatch, we use the so-called double opt-in procedure, which ensures that you only receive the newsletter after you have explicitly confirmed your consent to receive the newsletter by clicking on a verification link sent to the specified email address.

By activating the confirmation link, you grant us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR. In this context, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any potential misuse of your email address at a later time. The data we collect during the newsletter registration will be used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the designated link in the newsletter or by sending a corresponding message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data in a manner that is legally permitted and of which we inform you in this statement.

8.2 Brevo

The dispatch of our email newsletters is carried out by this provider: Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany.

"Based on our legitimate interest in effective and user-friendly newsletter marketing, we will pass on the data you provided during the newsletter registration in accordance with Art. 6 para. 1 lit. f GDPR to this provider, so that they can take over the newsletter dispatch on our behalf."

Subject to your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the provider also conducts a statistical success evaluation of newsletter campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the content of the newsletter. Device information (e.g. time of access, IP address, browser type, and operating system) is also collected and evaluated, but not merged with other data sets.
You can revoke your consent to newsletter tracking at any time with effect for the future.

"We have concluded a data processing agreement with the provider that protects the data of our site visitors and prohibits the transfer to third parties."

8.3 Claviyo

The dispatch of our email newsletters is carried out by this provider: Klaviyo, Inc., 125 Summer St., Ste 600, Boston, MA 02110, USA

"Based on our legitimate interest in effective and user-friendly newsletter marketing, we will pass on the data you provided during the newsletter registration in accordance with Art. 6 para. 1 lit. f GDPR to this provider, so that they can take over the newsletter dispatch on our behalf."

Subject to your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the provider also conducts a statistical success evaluation of newsletter campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the content of the newsletter. Device information (e.g. time of access, IP address, browser type, and operating system) is also collected and evaluated, but not merged with other data sets.

You can revoke your consent to newsletter tracking at any time with effect for the future.

"We have concluded a data processing agreement with the provider that protects the data of our site visitors and prohibits the transfer to third parties."

"For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission."

8.4 Shopping cart reminders via email

In the event of canceling your purchase with us before completing the order, you have the option to be reminded of the contents of your virtual shopping cart via email once.

The only mandatory information for sending this reminder is your email address. Providing additional data is voluntary and may be used to address you personally. For sending emails, we use the so-called Double Opt-in procedure, which ensures that you will only receive a notification once you have explicitly confirmed your consent by clicking on a verification link sent to the specified email address.

By activating the confirmation link, you grant us your consent to use your personal data in accordance with Art. 6 para. 1 lit. a GDPR for the purpose of sending a shopping cart reminder. In this context, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any potential misuse of your email address at a later time. The data we collect during your registration for our email notification service will be used strictly for the intended purpose.

You can unsubscribe from the cart reminders at any time by sending a corresponding message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly deleted from our designated distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data in a manner that is legally permitted and of which we inform you in this statement.

9) Data processing for order processing

9.1 "As far as necessary for the processing of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR."

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details you provided when placing the order (name, address, email address) in order to inform you personally about upcoming updates within the legally prescribed period in accordance with our statutory information obligations pursuant to Art. 6 para. 1 lit. c GDPR via an appropriate communication channel (e.g., by post or email). Your contact details will be used strictly for the purpose of notifications regarding updates owed by us and will be processed by us only to the extent necessary for the respective information.

"To process your order, we also work with the service provider(s) listed below, who assist us in whole or in part with the execution of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information."

9.2 Track123

"For the possibility of shipment tracking, we use the service of the following provider: Shenzhen LINGXING Network Technology Co., Ltd., Nanshan District, 35-36F, Building A7, Creative City, Shenzhen, GD, 518000, China."

"According to Art. 6 para. 1 lit. f GDPR, we pass on certain customer data (email address, first and last name, as well as the address) along with the shipment number to the provider based on our legitimate interest in effective and informative customer communication, as well as in the transparent and reliable processing of shipments after the package has been dispatched, which is also in the customer's interest, so that the provider can send shipping notifications and status updates regarding delivery on our behalf or otherwise make them accessible to the customer."

The data will not be passed on to third parties by the provider and will be processed solely for the purpose stated above. After the shipment is completed, the data will be deleted by the provider.

"We have concluded a data processing agreement with the provider that protects the data of our site visitors and prohibits the transfer to third parties."

9.3 Use of payment service providers (payment services)

- Klarna

On this website, one or more online payment methods from the following provider are available: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden.

When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is solely for the purpose of processing the payment with the provider and only to the extent necessary for this.

When selecting a payment method where the provider goes into advance payment (such as invoice or installment purchase or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data for an alternative payment method).

In order to safeguard our legitimate interest in determining the creditworthiness of our customers, this data will be forwarded to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks, based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment option you selected can be granted in terms of payment and/or default risk.

"In the decision-making process during the application review, in addition to internal provider criteria according to Art. 6 para. 1 lit. f GDPR, identity and credit information from the following credit agencies may also be included:"

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical method. The calculation of the score values includes, among other things, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Paypal

On this website, one or more online payment methods from the following provider are available: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

When selecting a payment method from the provider that requires you to make an advance payment, your payment data communicated during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared with them in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is carried out solely for the purpose of processing the payment with the provider and only to the extent necessary for this.

"When selecting a payment method where we advance payment, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data for an alternative payment method) during the ordering process."

"In order to safeguard our legitimate interest in determining your creditworthiness in such cases, we will forward this data to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider will assess, based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment method you selected can be granted in terms of payment and/or default risk."

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical method. The calculation of the score values includes, among other things, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Shopify Payments

On this website, one or more online payment methods from the following provider are available: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is solely for the purpose of processing the payment with the provider and only to the extent necessary for this.
- IMMEDIATELY

"On this website, one or more online payment methods from the following provider are available: SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany"

When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is solely for the purpose of processing the payment with the provider and only to the extent necessary for this.
- Stripe

"This website offers one or more online payment methods from the following provider: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland."

When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is solely for the purpose of processing the payment with the provider and only to the extent necessary for this.

When selecting a payment method where the provider goes into advance payment (such as invoice or installment purchase or direct debit), you will also be asked during the ordering process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data for an alternative payment method).

In order to safeguard our legitimate interest in determining the creditworthiness of our customers, this data will be forwarded to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks, based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences), whether the payment option you selected can be granted in terms of payment and/or default risk.

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical method. The calculation of the score values includes, among other things, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.

10) Retargeting/ Remarketing and Conversion Tracking

Google Marketing Platform

"This website uses the online marketing tool Google Marketing Platform provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("GMP")."

GMP uses cookies to serve relevant ads to users, improve campaign performance reports, or to prevent a user from seeing the same ads multiple times. Through a cookie ID, Google tracks which ads are served in which browser and can thus prevent them from being displayed multiple times. Furthermore, GMP can use cookie IDs to capture so-called conversions related to ad requests. This is the case, for example, when a user sees a GMP ad and later visits the advertiser's website using the same browser and makes a purchase through that website. According to Google, GMP cookies do not contain any personal information.
"Due to the marketing tools used, your browser automatically establishes a direct connection with Google's server."

"We have no influence on the scope and further use of the data collected by Google through the use of this tool and therefore inform you according to our knowledge as follows: By integrating GMP, Google receives the information that you have accessed the corresponding part of our website or clicked on an advertisement from us. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, there is a possibility that the provider will learn and store your IP address. As part of the use of GMP, there may also be a transmission of personal data to the servers of Google LLC in the USA."

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

"For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission."

The privacy policy of GMP by Google can be found here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

11) Page functionalities

11.1 Facebook plugins

"Our website uses plugins from the social network of the following provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland"

These plugins enable direct interactions with content on the social network.

"To increase the protection of your data when visiting our website, the plugins are initially deactivated and integrated into the page using a so-called '2-click' or 'Shariff' solution."

This integration ensures that when a page of our website that contains such plugins is called, no connection to the provider's servers is established yet.

"Only when you activate the plugins and thereby give your consent to the data transmission in accordance with Art. 6 para. 1 lit. a GDPR, does your browser establish a direct connection to the servers of the provider. In this process, regardless of a login to an existing user profile, information about your device used (including your IP address), your browser, and your page history is transmitted to the provider and may be further processed there."

"If you are logged into an existing user profile on the provider's social network, information about interactions performed via the plugins will also be published there and shown to your contacts."
You can revoke your consent at any time by deactivating the activated plugin by clicking it again. However, the revocation does not affect the data that has already been transmitted to the provider.

Data can also be transferred to: Meta Platforms Inc., USA

"We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties."

"For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission."

11.2 Instagram plugins

"Our website uses plugins from the social network of the following provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland."

These plugins enable direct interactions with content on the social network.

"To increase the protection of your data when visiting our website, the plugins are initially deactivated and integrated into the page using a so-called '2-click' or 'Shariff' solution."

This integration ensures that when a page of our website that contains such plugins is called, no connection to the provider's servers is established yet.

"Only when you activate the plugins and thereby give your consent to the data transmission in accordance with Art. 6 para. 1 lit. a GDPR, does your browser establish a direct connection to the servers of the provider. In this process, regardless of a login to an existing user profile, information about your device used (including your IP address), your browser, and your page history is transmitted to the provider and may be further processed there."

"If you are logged into an existing user profile on the provider's social network, information about interactions performed via the plugins will also be published there and shown to your contacts."
You can revoke your consent at any time by deactivating the activated plugin by clicking it again. However, the revocation does not affect the data that has already been transmitted to the provider.

Data can also be transferred: Meta Platforms Inc., USA

"We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties."

"For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission."

11.3 Pinterest plugins

"Our website uses plugins from the social network of the following provider: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland."

These plugins enable direct interactions with content on the social network.

"To increase the protection of your data when visiting our website, the plugins are initially deactivated and integrated into the page using a so-called '2-click' or 'Shariff' solution."

This integration ensures that when a page of our website that contains such plugins is called, no connection to the provider's servers is established yet.

"Only when you activate the plugins and thereby give your consent to the data transmission in accordance with Art. 6 para. 1 lit. a GDPR, does your browser establish a direct connection to the servers of the provider. In this process, regardless of a login to an existing user profile, information about your device used (including your IP address), your browser, and your page history is transmitted to the provider and may be further processed there."

"If you are logged into an existing user profile on the provider's social network, information about interactions performed via the plugins will also be published there and shown to your contacts."
You can revoke your consent at any time by deactivating the activated plugin by clicking it again. However, the revocation does not affect the data that has already been transmitted to the provider.

Data can also be transferred to: Pinterest Inc., USA

"We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties."

"For the transmission of data to the USA, the provider relies on the standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection."

11.4 Trusted Shops Trustbadge

"On our website, graphic elements from the following provider are integrated to display external customer reviews and/or an externally awarded quality seal: Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne, Germany."

"When you access a page of our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to load the elements properly. In this process, certain browser information, including your IP address, is transmitted to the provider."

"If personal data is also processed in this context, this is done in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the optimal marketing of our offerings and the appealing design of our online presence."

In the case of an online order with us, further processing may occur.

"Depending on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, your order information (order amount, order number, possibly purchased product) as well as your email address will be transmitted encrypted to the provider via the Trustbadge after completing an order, in order to verify an existing registration for the provider's services (especially the "buyer protection") and, if necessary, to enable a new registration."

In the event of an existing registration being identified or in the case of a new registration with the provider for its services (especially buyer protection), your order information (order amount, order number, purchased product) as well as your email address will be transmitted to the provider based on the contractual agreement with the provider in accordance with Art. 6 para. 1 lit. b GDPR and will be further processed by them in order to provide the services (especially buyer protection).

"We are jointly responsible with the provider for the processing described above in accordance with Art. 26 GDPR. The contract on joint responsibility can be viewed here:" https://help.etrusted.com/hc/de/articles/4402587369105-Vertrag-%C3%BCber-die-gemeinsame-Verantwortlichkeit-nach-DSGVO

11.5 Google Maps

"This website uses an online mapping service from the following provider: Google Maps (API) by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”)."

Google Maps is a web service for displaying interactive (land) maps to visually represent geographical information. By using this service, our location will be shown to you and any travel to it will be made easier.

When accessing those subpages where the Google Maps map is embedded, information about your use of our website (such as your IP address) is transmitted to servers of Google and stored there; this may also involve transmission to the servers of Google LLC in the USA. This occurs regardless of whether Google provides a user account through which you are logged in or whether a user account exists. If you are logged into Google, your data is directly associated with your account. If you do not wish for this association with your Google profile, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates them.

The collection, storage, and evaluation are carried out in accordance with Art. 6 para. 1 lit. f GDPR based on Google's legitimate interest in displaying personalized advertising, market research, and/or the needs-based design of Google websites. You have the right to object to the creation of these user profiles, and you must contact Google to exercise this right. If you do not agree with the future transmission of your data to Google in the context of using Google Maps, there is also the option to completely disable the Google Maps web service by turning off JavaScript in your browser. Google Maps and thus the map display on this website cannot be used then.

"As far as legally required, we have obtained your consent for the processing of your data as described above in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future. To exercise your revocation, please follow the option described above for making an objection."

"For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission."

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

12) Rights of the Data Subject

12.1 The applicable data protection law grants you the following rights as a data subject regarding the processing of your personal data (rights to information and intervention), with reference to the respective conditions for exercise based on the legal basis mentioned:

  • Right of access according to Art. 15 GDPR;
  • Right to rectification pursuant to Art. 16 GDPR;
  • Right to erasure according to Art. 17 GDPR;
  • Right to restriction of processing according to Art. 18 GDPR;
  • Right to information pursuant to Art. 19 GDPR;
  • Right to data portability according to Art. 20 GDPR;
  • Right of withdrawal of granted consents according to Art. 7 para. 3 GDPR;
  • Right to lodge a complaint pursuant to Art. 77 GDPR.

12.2 RIGHT OF OBJECTION

"IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERWHELMING LEGITIMATE INTEREST AS PART OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE."

"IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING PROTECTABLE REASONS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS."

"IF YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING PURPOSES. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE."

"IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES."

13) Duration of storage of personal data

The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing, and – if applicable – additionally by the respective statutory retention period (e.g. commercial and tax retention periods).

When processing personal data based on explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the affected data will be stored until you revoke your consent.

"If there are statutory retention periods for data processed in the context of contractual or contract-like obligations based on Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the retention periods have expired, provided that it is no longer necessary for the fulfillment of the contract or the initiation of a contract and/or we have no legitimate interest in further storage."

When processing personal data based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

When processing personal data for the purpose of direct marketing based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 2 GDPR.

Unless otherwise stated in the other information of this declaration regarding specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.

Represented by the IT Law Firm