Free shipping in Germany, Austria & Switzerland for orders over €50

Free shipping in DE, AT & CH for orders over €50

Privacy policy

Preamble

With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also briefly referred to as "data") we process for which purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and especially on our websites, in mobile applications, as well as within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offer").

The terms used are not gender-specific.

Status: November 25, 2025

Table of Contents

Controller

Timon Grau & Melchior Grau
Grau GmbH
Siemensstraße 35b
25462 Rellingen

Email address: support@grau.art

Imprint: www.grau.art/pages/impressum

Contact Data Protection Officer

Torsten Oestmann
Siemensstraße 35b
25462 Rellingen

Phone: +49 4101 370-0
Email: datenschutz@grau.art

Overview of Processing

The following overview summarizes the types of data processed and the purposes of their processing and refers to the affected persons.

Types of processed data

  • Master data.
  • Payment data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta-, Communication and procedural data.
  • Contact information (Facebook).
  • Event data (Facebook).
  • Log data.
  • Creditworthiness data.

Categories of affected persons

  • Service recipients and clients.
  • Interested parties.
  • Communication partners.
  • Users.
  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and fulfillment of contractual obligations.
  • Communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement.
  • Tracking.
  • Office and organizational procedures.
  • Remarketing.
  • Conversion measurement.
  • Click tracking.
  • Audience formation.
  • Affiliate tracking.
  • A/B tests.
  • Organizational and administrative procedures.
  • Feedback.
  • Heatmaps.
  • Marketing.
  • Profiles with user-related information.
  • Cross-device tracking.
  • Provision of our online offer and user-friendliness.
  • Assessment of creditworthiness and credit rating.
  • Information technology infrastructure.
  • Public relations.
  • Business processes and economic procedures.

Automated individual decisions

  • Creditworthiness report.

Relevant legal bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. If more specific legal bases are relevant in individual cases, we will inform you of these in the privacy policy.

  • Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) - The data subject has given consent to the processing of personal data relating to them for one or more specific purposes.
  • Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) - The processing is necessary for the performance of a contract to which the data subject is party or for the implementation of pre-contractual measures taken at the request of the data subject.
  • Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) - The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes in particular the Act on the Protection of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains special provisions on the right to information, the right to deletion, the right to object, the processing of special categories of personal data, processing for other purposes and transmission as well as automated decision-making in individual cases including profiling. Furthermore, state data protection laws of the individual federal states may apply.

Note on the applicability of the GDPR and Swiss DPA: These Privacy notices serve both to provide information in accordance with the Swiss DSG as well as the General Data Protection Regulation (GDPR). For this reason, please note that due to the broader geographical application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss DSG "processing" of "personal data", "overriding interest" and "particularly sensitive personal data", the terms used in the GDPR "processing" of "personal data", as well as "legitimate interest" and "special categories of data" are used. However, the legal meaning of the terms is still determined according to the Swiss DSG within the scope of the Swiss DSG.

Security Measures

We take appropriate technical and organizational measures in accordance with legal requirements, considering the state of the art, implementation costs, the nature, scope, circumstances, and purposes of the processing, as well as the varying probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.

The measures include in particular securing the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access concerning them, input, transmission, ensuring availability, and their separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data risks. Moreover, we consider the protection of personal data already in the development or selection of hardware, software, and procedures according to the principle of data protection by design and by default.

Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users' data transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator for users that their data is transmitted securely and encrypted.

Transfer of Personal Data

As part of our processing of personal data, it may happen that such data is transferred to other entities, companies, legally independent organizational units, or persons or disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.

International Data Transfers

Data processing in third countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) transmit or this occurs within the scope of using third-party services or the disclosure or transmission of data to other persons, entities, or companies (which becomes apparent from the postal address of the respective provider or if the privacy policy explicitly refers to data transfer to third countries), this always takes place in accordance with legal requirements.

For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated 10.07.2023. Additionally, we have concluded standard contractual clauses with the respective providers that comply with the requirements of the EU Commission and establish contractual obligations to protect your data.

This dual protection ensures comprehensive protection of your data: The DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should changes occur within the framework of the DPF, the standard contractual clauses act as a reliable fallback option. This ensures that your data remains adequately protected even in the event of political or legal changes.

For the individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information about the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).

For data transfers to other third countries, appropriate security measures apply, in particular standard contractual clauses, explicit consents, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

General information on data storage and deletion

We delete personal data that we process in accordance with legal provisions as soon as the underlying consents are revoked or no further legal bases for processing exist. This applies in cases where the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule exist if legal obligations or special interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons or whose storage is necessary for legal prosecution or the protection of the rights of other natural or legal persons must be appropriately archived.

Our privacy notices contain additional information about the retention and deletion of data that specifically applies to certain processing procedures.

In cases of multiple indications regarding the retention period or deletion deadlines of a date, the longest period always applies. Data that is no longer needed for the originally intended purpose but is retained due to legal requirements or other reasons is processed exclusively for the reasons that justify its retention.

Retention and deletion of data: The following general periods apply to retention and archiving under German law:

  • 10 years - retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets as well as the work instructions and other organizational documents required for their understanding (§ 147 para. 1 no. 1 in conjunction with para. 3 AO, § 14b para. 1 UStG, § 257 para. 1 no. 1 in conjunction with para. 4 HGB).
  • 8 years - accounting vouchers, such as invoices and cost receipts (§ 147 para. 1 no. 4 and 4a in conjunction with para. 3 sentence 1 AO as well as § 257 para. 1 no. 4 in conjunction with para. 4 HGB).
  • 6 years - other business documents: received commercial or business letters, copies of sent commercial or business letters, other documents insofar as they are relevant for taxation, e.g., hourly wage slips, operational accounting sheets, calculation documents, price labels, but also payroll accounting documents insofar as they are not already accounting vouchers and cash register slips (§ 147 para. 1 no. 2, 3, 5 in conjunction with para. 3 AO, § 257 para. 1 no. 2 and 3 in conjunction with para. 4 HGB).
  • 3 years - data required to consider potential warranty and compensation claims or similar contractual claims and rights, as well as to process related inquiries, based on previous business experiences and usual industry practices, are stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).

Rights of the data subjects

Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you which is based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such advertising; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you are being processed and to access such data as well as further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: You have the right, in accordance with legal requirements, to demand the completion of data concerning you or the correction of incorrect data concerning you.
  • Right to erasure and restriction of processing: You have the right, according to legal provisions, to demand that data concerning you be deleted without delay, or alternatively, according to legal provisions, to demand a restriction of the processing of the data.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, or to request the transfer of those data to another controller, according to legal requirements.
  • Complaint to supervisory authority: In accordance with legal provisions and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member state in which you usually reside, the supervisory authority of your workplace or the place of the alleged violation, to file a complaint if you believe that the processing of your personal data violates the GDPR.

Business Services

We process data of our contractual and business partners, e.g. customers and prospects (collectively referred to as "contract partners"), within the framework of contractual and comparable legal relationships as well as related measures and with regard to communication with the contract partners (or pre-contractually), for example to answer inquiries.

We use this data to fulfill our contractual obligations. This particularly includes the duties to provide the agreed services, any update obligations, and remedies for warranty and other service disruptions. Furthermore, we use the data to safeguard our rights and for the purposes of administrative tasks associated with these obligations as well as corporate organization. In addition, we process the data based on our legitimate interests both in proper and economically sound business management and in security measures to protect our contract partners and our business operations from abuse, endangerment of their data, secrets, information, and rights (e.g., involving telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or financial authorities). Under applicable law, we only disclose contract partner data to third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contract partners are informed about further forms of processing, for example for marketing purposes, within this privacy policy.

We inform the contract partners which data are necessary for the aforementioned purposes before or during data collection, e.g., in online forms, by special marking (e.g., colors) or symbols (e.g., asterisks or similar), or personally.

We delete the data after the expiry of statutory warranty and comparable obligations, i.e., generally after four years, unless the data are stored in a customer account, e.g., as long as they must be retained for legal reasons (usually ten years for tax purposes). Data disclosed to us within the scope of an order by the contract partner are deleted according to the specifications and generally after the end of the order.

  • Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); contract data (e.g., subject matter of the contract, duration, customer category); usage data (e.g., page views and duration, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
  • Data subjects: Service recipients and clients; prospects. Business and contract partners.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; security measures; communication; office and organizational procedures; organization and Administrative procedures. Business processes and economic procedures.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing procedures, processes and services:

  • Online shop, order forms, e-commerce and service fulfillment: We process our customers' data in order to enable them to select, purchase, or order the chosen products, goods as well as related services, as well as their payment and provision, or delivery, or execution. If necessary for the execution of an order, we use service providers, especially postal, freight forwarding and shipping companies, to carry out the delivery or execution to our customers. For processing payment transactions, we use the services of banks and payment service providers. The required information is marked as such within the order or comparable purchase process and includes the information needed for delivery or provision and billing as well as contact information in order to be able to hold any necessary consultations; Legal bases: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).

Providers and services used within the scope of business activities

Within the scope of our business activities, we use additional services, platforms, interfaces or plug-ins from third-party providers (briefly "services") in compliance with legal requirements. Their use is based on our interests in the proper, lawful and economical management of our business operations and our internal organization.

  • Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or phone numbers); content data (e.g., textual or pictorial messages and posts as well as information concerning them, such as authorship details or time of creation); contract data (e.g., subject matter of the contract, duration, customer category). Meta, communication and procedural data (e.g., IP addresses, time stamps, identification numbers, involved persons).
  • Affected persons: Service recipients and clients; interested parties. Business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures. Business processes and economic procedures.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing procedures, processes and services:

  • Klar Insights: Enables the analysis of sales data to gain business insights and optimize decisions. Provides functions for monitoring performance indicators, detecting trends and creating reports. Supports in the Segmentation of customer data and identification of growth opportunities. Furthermore, it includes the collection of order and usage data as well as the preparation of this data in the data warehouse for website optimization. The analysis platform enables the analysis and improvement of the reach and success of marketing measures. For this purpose, a JavaScript snippet was implemented that is only loaded after the website visitor has given consent. It collects activity data, cookies, IP addresses, referrers, requests, and the user agent. If no user consent is given, the data is collected anonymously, i.e., without collecting personal or personally identifiable data, and in groups, i.e., by randomly assigning the collected data to groups of users. Therefore, it is not possible for us to draw conclusions about individual users; legal basis: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); To generally object to the use of Klar, please use this link: https://1581092576.grau.art/donottrack/me. This will set a cookie named "do_not_track" from the domain "grau.art." Please do not delete this, as otherwise it cannot be guaranteed that you will not be tracked by Klar; Service provider: Klar Insights GmbH, Marktstr. 18, 80802 Munich, Germany; Website: https://www.getklar.com/. Privacy Policy: https://www.getklar.com/data-protection.
  • Sendcloud: All-in-one shipping platform for e-commerce companies that combines multiple carriers and shipping methods in one interface, automates shipping labels, tracks shipments, and simplifies returns management; Service provider: Sendcloud GmbH, Fürstenrieder Str. 70, 80686 Munich, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.sendcloud.com/. Privacy Policy: https://www.sendcloud.com/privacy-policy/.

Payment Methods

Within the framework of contractual and other legal relationships, due to legal obligations or otherwise based on our legitimate interests, we offer the affected persons efficient and secure payment options and use, in addition to banks and credit institutions, other service providers (collectively "payment service providers").

The data processed by the payment service providers include master data, such as name and address, banking data, such as account numbers or credit card numbers, passwords, TANs, and check digits, as well as contract, amount, and recipient-related information. The information is required to carry out the transactions. However, the entered data is only processed and stored by the payment service providers. That is, we do not receive any account or credit card-related information, but only information confirming or denying the payment. Under certain circumstances, the data is transmitted by the payment service providers to credit agencies. This transmission is intended for identity and creditworthiness verification. For this, we refer to the terms and conditions and the privacy notices of the payment service providers.

The terms and conditions and privacy notices of the respective payment service providers, which are available within the respective websites or transaction applications, apply to the payment transactions. are available. We also refer to these for further information and for asserting rights of withdrawal, information, and other rights of the data subjects.

  • Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contract data (e.g., subject of the contract, duration, customer category); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); meta, communication and procedure data (e.g., IP addresses, timestamps, identification numbers, involved persons). Contact data (e.g., postal and email addresses or telephone numbers).
  • Data subjects: Service recipients and clients; business and contract partners. Interested parties.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations. Business processes and economic procedures.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further notes on processing procedures, methods, and services:

  • American Express: Payment services (technical connection of online payment methods); Service provider: American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.americanexpress.com/de/. Privacy policy: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
  • Apple Pay: Payment services (technical connection of online payment methods); Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.apple.com/de/apple-pay/. Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
  • Google Pay: Payment services (technical connection of online payment methods); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://pay.google.com/intl/de_de/about/. Privacy policy: https://policies.google.com/privacy.
  • Mastercard: Payment services (technical connection of online payment methods); Service provider: Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.mastercard.de/de-de.html. Privacy policy: https://www.mastercard.de/de-de/datenschutz.html.
  • PayPal: Payment services (technical integration of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); Service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.paypal.com/de. Privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full.
  • Shopify Payments: Payment services (technical integration of online payment methods). Payments are processed via Shopify Payments, Shopify's integrated payment platform. It enables customers to use various supported payment methods depending on the region. Payment processing is based on the Shopify Payments terms of use, which are displayed to the customer during the payment process. Further information is available at https://www.shopify.com/de/payments; Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.shopify.de. Privacy policy: https://www.shopify.de/legal/datenschutz.
  • Stripe: Payment services (technical integration of online payment methods); Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://stripe.com; Privacy policy: https://stripe.com/de/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
  • Visa: Payment services (technical integration of online payment methods); Service provider: Visa Europe Services Inc., London branch, 1 Sheldon Square, London W2 6TT, GB; Legal bases: Performance of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); Website: https://www.visa.de. Privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

Credit Check

If we advance payments or assume comparable economic risks (e.g. when ordering on account), we reserve the right, to protect legitimate interests, to conduct an identity and Creditworthiness information for the purpose of assessing credit risk based on mathematical-statistical methods from specialized service providers (credit reporting agencies) is to be obtained.

The information received from the credit reporting agencies about the statistical probability of a payment default is processed by us within the framework of an appropriate discretionary decision regarding the establishment, execution, and termination of the contractual relationship. We reserve the right, in the event of a negative result of the creditworthiness check, to refuse payment on account or any other advance payment.

The decision whether we provide advance payment is made solely on the basis of an automated individual decision in accordance with legal requirements, which our software makes based on the information from the credit reporting agency.

If we obtain explicit consent from contractual partners, the legal basis for the creditworthiness information and the transmission of the customer's data to the credit reporting agencies is the consent. If no consent is obtained, the creditworthiness information is based on our legitimate interests in the default security of our payment claims.

  • Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); contract data (e.g., subject matter of the contract, duration, customer category). Creditworthiness data (e.g., received credit score, estimated probability of default, risk classification based on this, historical payment behavior).
  • Data subjects: Service recipients and clients; prospective customers. Business and contractual partners.
  • Purposes of processing: Assessment of creditworthiness and credit rating.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Automated individual decisions: Creditworthiness information (decision based on a creditworthiness check).

Provision of the online offer and web hosting

We process user data in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.

  • Types of data processed: Usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons). Log data (e.g., log files concerning logins or data retrieval or access times).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online offer and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
  • Storage and deletion: Deletion according to the information in the section "General information on Data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing procedures, methods, and services:

  • Shopify: Platform through which e-commerce services are offered and carried out. The services and related processes include in particular online shops, websites, their offers and content, community elements, purchase and payment processes, customer communication as well as analysis and marketing; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Service provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; Website: https://www.shopify.de. Privacy policy: https://www.shopify.de/legal/datenschutz.
  • Provision of online offer on rented storage space: For the provision of our online offer, we use storage space, computing capacity, and software that we rent or otherwise obtain from a corresponding server provider (also called "web host"); Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Collection of access data and log files: Access to our online offer is logged in the form of so-called "server log files." Server log files may include the address and name of the retrieved web pages and files, date and time of access, transmitted data volumes, message about successful retrieval, browser type including version, user's operating system, referrer URL (the previously visited page), and usually IP addresses and the requesting provider. Server log files can be used on the one hand for security purposes, e.g., to avoid server overload (especially in case of abusive attacks, so-called DDoS attacks), and on the other hand, to ensure server utilization and stability; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is necessary for evidentiary purposes are exempt from deletion until the final clarification of the respective incident.
  • Content delivery network: We use a "content delivery network" (CDN). A CDN is a service that helps deliver content of an online offer, especially large media files such as graphics or program scripts, faster and more securely by using regionally distributed and internet-connected servers; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Use of cookies

The term "cookies" refers to functions that store information on users' end devices and read it from them. Cookies can also be used for different purposes, such as for functionality, security, and comfort of online offers as well as for creating analyses of visitor flows. We use cookies in accordance with legal regulations. For this purpose, we obtain the users' consent in advance if required. If consent is not necessary, we rely on our legitimate interests. This applies when storing and reading of Information is essential to be able to provide expressly requested content and functions. This includes, for example, the storage of settings as well as ensuring the functionality and security of our online offering. Consent can be revoked at any time. We clearly inform about its scope and which cookies are used.

Notes on data protection legal bases: Whether we process personal data using cookies depends on consent. If consent is given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.

Storage duration: With regard to storage duration, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user leaves an online offering and closes their device (e.g., browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the device is closed. For example, the login status can be saved and preferred content direct can be displayed when the user visits a website again. Likewise, user data collected via cookies can be used for reach measurement. Unless we explicitly inform users about the type and storage duration of cookies (e.g., when obtaining consent), they should assume that these are permanent and the storage duration can be up to two years.

General notes on revocation and objection (opt-out): Users can revoke their given consents at any time and also object to processing in accordance with legal requirements, including via the privacy settings of their browser.

  • Types of data processed: Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

Further notes on processing processes, procedures, and services:

  • Processing of cookie data based on consent: We use a consent management solution whereby user consent for the use of cookies or for the procedures and providers named in the consent management solution is obtained. This procedure serves to obtain, log, manage, and revoke consents, especially concerning the use of cookies and comparable technologies that are used to store, read, and process information on users' devices. Within this procedure, user consents for the use of cookies and the associated processing of information, including the specific processing and providers named in the consent management procedure, are obtained. Users also have the option to manage and revoke their consents. The declarations of consent are stored to avoid repeated queries and to provide proof of consent according to legal requirements. The Storage takes place server-side and/or in a cookie (so-called opt-in cookie) or using comparable technologies to be able to assign the consent to a specific user or their device. If there are no specific details about the providers of consent management services, the following general information applies: The duration of the storage of the consent is up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, the details about the scope of the consent (e.g., relevant categories of cookies and/or service providers) as well as information about the browser, the system, and the device used; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
  • OneTrust: Consent management: Procedures for obtaining, logging, managing, and revoking consents, especially for the use of cookies and similar technologies for storing, reading, and processing information on users' devices as well as their processing; Service provider: OneTrust Technology Limited, 82 St John St, Farringdon, London EC1M 4JN, United Kingdom (UK); Website: https://www.onetrust.de/einwilligungsmanagement/. Privacy policy: https://www.onetrust.com/privacy/.

Blogs and publication media

We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). The data of the readers is only processed for the purposes of the publication medium to the extent necessary for its presentation and the communication between authors and readers or for security reasons. Otherwise, we refer to the information on the processing of visitors to our publication medium within the framework of these privacy notices.

  • Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or phone numbers); content data (e.g., textual or visual messages and contributions as well as information relating to them, such as authorship details or time of creation); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Feedback (e.g., collecting feedback via an online form). Provision of our online offer and user-friendliness.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Contact and inquiry management

When contacting us (e.g., by post, contact form, email, telephone, or via social media) as well as within existing user and business relationships, the details of the requesting persons are processed to the extent necessary to answer the contact inquiries and any requested measures.

  • Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or phone numbers); content data (e.g., textual or visual messages and posts as well as related information, such as authorship details or time of creation); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
  • Data subjects: Communication partners.
  • Purposes of processing: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via online form). Provision of our online offer and user-friendliness.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).

Further information on processing procedures, processes, and services:

  • Contact form: When contacting us via our contact form, by email or other communication channels, we process the personal data transmitted to us to respond to and handle the respective concern. This usually includes information such as name, contact details, and possibly other information provided to us that is necessary for appropriate processing. We use this data exclusively for the specified purpose of contact and communication; Legal bases: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Zendesk: Customer support management, ticket management, multi-channel communication, knowledge base creation, customer feedback collection and analysis, automation of support processes, reporting and analytics for performance monitoring; Service provider: Zendesk, Inc., 989 Market Street #300, San Francisco, CA 94102, USA; Legal bases: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.zendesk.de; Privacy policy: https://www.zendesk.de/company/customers-partners/privacy-policy/; Data processing agreement: https://www.zendesk.de/company/data-processing-form/. Basis for third country transfers: Data Privacy Framework (DPF).

Communication via Messenger

We use messengers for communication purposes and therefore ask you to observe the following information regarding the functionality of the messengers, encryption, the use of communication metadata, and your options to object.

You can also contact us via alternative means, e.g., by phone or email. Please use the contact options provided to you or those within contact options specified in our online offer.

In the case of end-to-end encryption of content (i.e., the content of your message and attachments), we point out that the communication content (i.e., the content of the message and attached images) is encrypted from end to end. This means that the content of the messages is not accessible, not even by the messenger providers themselves. You should always use an up-to-date version of the messengers with encryption enabled to ensure the encryption of the message content.

However, we additionally inform our communication partners that although the providers of the messengers do not view the content, they can find out that and when communication partners communicate with us, as well as technical information about the device used by the communication partners and, depending on the settings of their device, also location information (so-called metadata) is processed.

Notes on legal bases: If we ask communication partners for permission before communicating with them via messenger, the legal basis for our processing of their data is their consent. Otherwise, if we do not ask for consent and, for example, they contact us on their own initiative, we use messengers in relation to our contractual partners as a contractual measure and in the context of contract initiation, and in the case of other interested parties and communication partners based on our legitimate interests in quick and efficient communication and fulfilling the needs of our communication partners for communication via messenger. Furthermore, we point out that we do not initially transmit the contact data provided to us to the messengers without your consent.

Revocation, objection, and deletion: You can revoke given consent at any time and object to communication with us via messenger at any time. In the case of communication via messenger, we delete the messages according to our general deletion policies (i.e., for example, as described above, after the end of contractual relationships, in the context of archiving requirements, etc.) and otherwise as soon as we can assume that any inquiries from communication partners have been answered, when no reference to a previous conversation is to be expected and no legal retention obligations oppose the deletion.

Reservation of reference to other communication channels: To ensure your security, we ask for your understanding that for certain reasons we may not be able to answer inquiries via messenger. This concerns situations where contract details must be treated particularly confidentially or a response via messenger does not meet formal requirements. In these cases, we recommend that you use more appropriate communication channels.

  • Types of data processed: Contact data (e.g., postal and email addresses or telephone numbers). Content data (e.g., textual or pictorial messages and contributions as well as information concerning them, such as authorship details or time of creation).
  • Data subjects: Communication partners.
  • Purposes of processing: Communication.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Chatbots and Chat Functions

We offer online chats and chatbot functions as communication options (collectively referred to as "chat services"). A chat is an online conversation conducted with some degree of immediacy. A chatbot is software that answers users' questions or informs them via messages. If you use our chat functions, we may process your personal data.

If you use our chat services within an online platform, your identification number within the respective platform will also be stored. We may also collect information about which users interact with our chat services and when. Furthermore, we store the content of your conversations via the chat services and log registration and consent processes in order to be able to demonstrate them in accordance with legal requirements.

We inform users that the respective platform provider can find out if and when users communicate with our chat services, as well as collect technical information about the user's device and, depending on the settings of their device, also location information (so-called metadata) for the purposes of optimizing the respective services and security purposes. Also, the metadata of communication via chat services (i.e., for example, the information about who communicated with whom) could be used by the respective platform providers according to their terms, to which we refer for further information, for marketing purposes or to display user-tailored advertising.

If users agree to receive information from a chatbot with regular messages, they always have the option to unsubscribe from the information for the future. The chatbot informs users how and with which terms they can unsubscribe from the messages. By unsubscribing from the chatbot messages, the user's data will be deleted from the directory of message recipients.

We use the aforementioned information to operate our chat services, e.g., to address users personally, to answer their inquiries, to transmit any requested content, and also to improve our chat services (e.g., to "teach" chatbots answers to frequently asked questions or to identify unanswered inquiries).

Notes on legal bases: We use the chat services based on consent if we have previously obtained permission from users to process their data within the scope of our chat services (this applies to cases where users are asked for consent, e.g., so that a chatbot can regularly send them messages). If we use chat services to answer users' inquiries about our services or our company, this is done for contractual and pre-contractual communication. Otherwise, we use chat services based on our legitimate interests in optimizing the chat services, their economic efficiency, and enhancing the positive user experience.

Revocation, objection, and deletion: You can revoke any given consent at any time or object to the processing of your data within the scope of our chat services.

  • Types of data processed: Contact data (e.g., postal and email addresses or telephone numbers); content data (e.g., textual or pictorial messages and contributions as well as information related to them, such as details about the Authorship or time of creation). Usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions).
  • Data subjects: Communication partners.
  • Purposes of processing: Communication.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Newsletter and electronic notifications

We send newsletters, emails, and other electronic notifications (hereinafter "newsletter") exclusively with the consent of the recipients or based on a legal basis. If the contents of the newsletter are mentioned during registration, these contents are decisive for the users' consent. For registration to our newsletter, usually providing your email address is sufficient. However, to offer you a personalized service, we may ask you to provide your name for personal address in the newsletter or additional information if necessary for the purpose of the newsletter.

Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them in order to be able to prove a previously given consent. The processing of this data is limited to the purpose of potentially defending against claims. An individual deletion request is possible at any time, provided that the previous existence of consent is simultaneously confirmed. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist (so-called "blocklist").

The logging of the registration process is based on our legitimate interests for the purpose of proving its proper procedure. If we commission a service provider to send emails, this is done based on our legitimate interests in an efficient and secure mailing system.

Contents:

Information about us, our services, campaigns, and offers.

  • Types of data processed: Master data (e.g., full name, residential address, contact information, customer number, etc.); contact data (e.g., postal and email addresses or phone numbers); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons). Usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g., via email or postal mail).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Right to object (opt-out): You can cancel the receipt of our newsletter at any time, i.e., revoke your consent or object to further receipt. A link to unsubscribe from the newsletter can be found either at the end of each newsletter or you can otherwise use the contact options given above, preferably email, for this purpose.

Further information on processing procedures, methods, and services:

  • Measurement of open and click rates: The newsletters contain a so-called "web beacon," i.e., a pixel-sized file that is retrieved from our or, if we use a dispatch service provider, their server when the newsletter is opened. During this retrieval, both technical information, such as details about the browser and your system, as well as your IP address and the time of retrieval are initially collected. This information is used to technically improve our newsletter based on the technical data or the target groups and their reading behavior based on their access locations (which can be determined using the IP address) or access times. This analysis also includes determining whether and when the newsletters are opened and which links are clicked. The information is assigned to the individual newsletter recipients and stored in their profiles until deletion. The evaluations serve to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users. The measurement of open and click rates as well as the storage of the measurement results in the users' profiles and their further processing are based on the users' consent. A separate revocation of the success measurement is unfortunately not possible; in this case, the entire newsletter subscription must be canceled or objected to. In this case, the stored profile information will be deleted; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
  • Klaviyo: Email and SMS marketing platform; Service provider: Klaviyo, 225 Franklin St., Boston, Massachusetts 02110, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.klaviyo.com/; Privacy policy: https://www.klaviyo.com/legal/privacy-notice. Basis for transfers to third countries: Data Privacy Framework (DPF).

Web analysis, monitoring, and optimization

Web analysis (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offer and can include behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, for example, we can see at what times our online offer or its functions or content are most frequently used, or invite reuse. It also enables us to track which areas require optimization.

In addition to web analysis, we can also use testing procedures to test and optimize different versions of our online offer or its components.

Unless otherwise stated below, profiles, i.e., data combined for a usage process, can be created for these purposes and information can be stored and then read out in a browser or on a device. The collected information includes in particular visited websites and elements used there as well as technical information, such as the browser used, the computer system used, and details about usage times. If users agree to the collection of their location data with us or have agreed to the providers of the services we use, the processing of location data is also possible.

Furthermore, the IP addresses of the users are stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect the users. In general, no clear data of the users (such as email addresses or names) are stored within the framework of web analysis, A/B testing, and optimization, but pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective procedures.

Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
  • Persons concerned: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Reach measurement (e.g., access statistics, detection of recurring visitors); profiles with user-related information (creating user profiles); provision of our online offer and user-friendliness; tracking (e.g., interest-/behavior-based profiling, use of cookies); click tracking; A/B tests. Heatmaps (mouse movements by users, which are summarized into an overall picture).
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion". Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods can be stored on users' devices for a period of two years).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further notes on processing procedures, methods, and services:

  • Google Analytics: We use Google Analytics to measure and analyze the use of our online offer based on a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It serves to assign analysis information to an end device in order to recognize which content users have accessed within one or several usage sessions, which search terms they have used, accessed again, or interacted with our online offer. The time and duration of use are also stored, as well as the sources of users referring to our online offer and technical aspects of their end devices and browsers.
    Pseudonymous profiles of users are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides coarse geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, the IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. They are not logged, are not accessible, and are not used for further purposes. When Google Analytics collects measurement data, all IP queries are conducted on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy Policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms); Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertising: https://myadcenter.google.com/personalizationoff. More information: https://business.safety.google/adsservices/ (types of processing and processed data).
  • Google Tag Manager: We use Google Tag Manager, a software from Google, which allows us to centrally manage so-called website tags via a user interface. Tags are small code elements on our website that serve to capture and analyze visitor activities. This technology supports us in improving our website and the content offered on it. The Google Tag Manager itself does not create user profiles, does not store cookies with user profiles, and does not perform independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services that we use on our website. Nevertheless, when using Google Tag Manager, the users' IP address is transmitted to Google, which is technically necessary to implement the services we use. Cookies may also be set. However, this data processing only occurs if services are integrated via the Tag Manager. For more detailed information about these services and their data processing, we refer to the further sections of this privacy policy; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement:
    https://business.safety.google/adsprocessorterms. Basis for transfers to third countries: Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms).
  • Hotjar Observe: Software for analyzing and optimizing online offerings based on pseudonymized measurements and analyses of user behavior, which may include A/B tests (measuring the popularity and user-friendliness of different content and functions), measurement of click paths and interaction with content and functions of the online offering (so-called heatmaps and recordings); Service provider: Hotjar Ltd., 3 Lyons Range, 20 Bisazza Street, Sliema SLM 1640, Malta; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.hotjar.com; Privacy Policy: https://www.hotjar.com/legal/policies/privacy; Data deletion: The cookies used by Hotjar have varying "lifespans"; some remain valid for up to 365 days, some only during the current visit; Cookie policy: https://www.hotjar.com/legal/policies/cookie-information. Objection option (Opt-Out): https://www.hotjar.com/legal/compliance/opt-out.

Online Marketing

We process personal data for the purpose of online marketing, which can include in particular the marketing of advertising space or the display of advertising and other content (collectively referred to as "content") based on potential user interests as well as the measurement of their effectiveness.

For these purposes, so-called user profiles are created and stored in a file (the so-called "cookie") or similar procedures are used, by means of which the data relevant for displaying the aforementioned content about the user are stored. These may include, for example, viewed content, visited websites, used online networks, but also communication partners and technical information such as the browser used, the computer system used, as well as information about usage times and used functions. If users have consented to the collection of their location data, these may also be processed.

In addition, the IP addresses of the users are stored. However, we use available IP masking procedures (i.e., pseudonymization by shortening the IP address) for user protection. Generally, within the framework of the online marketing process, no clear data of the users (such as email addresses or names) are stored, but pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual user identity, but only the information stored in their profiles.

The information in the profiles is usually stored in cookies or by means of similar procedures. These cookies can later generally also be used on other websites, which use the same online marketing procedure, read out and analyzed for the purpose of displaying content as well as supplemented with other data and stored on the server of the online marketing procedure provider.

Exceptionally, it is possible to assign clear data to the profiles, mainly when users are, for example, members of a social network whose online marketing procedure we use and the network links the user profiles with the aforementioned information. Please note that users can make additional agreements with the providers, for example by consenting during registration.

We generally only gain access to aggregated information about the success of our advertisements. However, within the framework of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e., for example, to a contract conclusion with us. The conversion measurement is used solely for the success analysis of our marketing measures.

Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.

Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is the permission. Otherwise, the users' data is processed based on our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we would also like to point you to the information on the use of cookies in this privacy policy.

Notes on revocation and objection:

We refer to the privacy notices of the respective providers and the objection possibilities (so-called "opt-out") provided by the providers. If no explicit opt-out option is given, there is, on the one hand, the possibility to disable cookies in your browser settings. However, this may restrict functions of our online offer. Therefore, we additionally recommend the following opt-out options, which are offered collectively for respective regions:

a) Europe: https://www.youronlinechoices.eu.

b) Canada: https://www.youradchoices.ca/choices.

c) USA: https://www.aboutads.info/choices.

d) Cross-regionally: https://optout.aboutads.info.

  • Types of data processed: Content data (e.g., textual or pictorial messages and posts as well as related information, such as authorship details or creation time); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, involved persons); event data (Facebook) ("Event data" are information that is sent to the provider Meta, for example via Meta Pixel (whether through apps or other channels) and relates to persons or their actions. This data includes details about website visits, interactions with content and functions, app installations, and product purchases. The processing of event data is carried out with the aim of creating target groups for content and advertising messages (Custom Audiences). It is important to note that event data does not include actual content such as written comments, no login information, and no contact information such as names, email addresses, or phone numbers. "Event data" is deleted by Meta after a maximum of two years, and the audiences created from this disappear when our Meta user accounts are deleted.); Contact information (Facebook) ("Contact information" is data that clearly identifies the data subjects, such as names, email addresses, and phone numbers, which can be transmitted to Facebook, for example via Facebook Pixel or upload for matching purposes to create Custom Audiences; after matching for audience creation, the contact information is deleted); Master data (e.g., full name, residential address, contact information, customer number, etc.); Contact details (e.g., postal and email addresses or phone numbers). Contract data (e.g., contract subject, duration, customer category).
  • Data subjects: Users (e.g., website visitors, users of online services); service recipients and clients; prospects; communication partners. Business and contract partners.
  • Purposes of processing: Reach measurement (e.g., access statistics, detection of returning visitors); tracking (e.g., interest-/behavior-based profiling, use of cookies); conversion measurement (measuring the effectiveness of marketing measures); audience creation; marketing; profiles with user-related information (creating user profiles); provision of our online offer and user-friendliness; remarketing; click tracking; cross-device tracking (device-spanning processing of user data for marketing purposes); provision of contractual services and fulfillment of contractual obligations; communication. Office and organizational procedures.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion." Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods can be stored on users' devices for a period of two years).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further information on processing procedures, processes, and services:

  • Meta Pixel and audience creation (Custom Audiences): With the help of the Meta Pixel (or comparable functions, for transmitting event data or contact information via interfaces in apps), the company Meta is able, on the one hand, to determine visitors to our online offer as an audience for displaying ads (so-called "Meta Ads"). Accordingly, we use the Meta Pixel to show the Meta Ads we place only to those users on Meta platforms and within the services of partners cooperating with Meta (so-called "Audience Network" https://www.facebook.com/audiencenetwork/) who have also shown interest in our online offer or who exhibit certain characteristics (e.g., interest in certain topics or products, which become apparent from the visited websites) that we transmit to Meta (so-called "Custom Audiences"). With the help of the Meta Pixel, we also want to ensure that our Meta Ads correspond to the potential interest of users and do not appear annoying. With the help of the With Meta pixels, we can also track the effectiveness of Meta ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Meta ad (so-called "conversion measurement"); Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for transfers to third countries: Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum); Further information: Event data of users, i.e. behavioral and interest data, are processed for the purposes of targeted advertising and audience formation based on the agreement on joint responsibility ("Addendum for Controllers", https://www.facebook.com/legal/controller_addendum). The joint responsibility is limited to the collection and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, especially regarding the transfer of data to the parent company Meta Platforms, Inc. in the USA (based on the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Advanced matching for the Meta pixel: In addition to the processing of event data in connection with the use of the Meta pixel (or similar functions, e.g. in apps), contact information (personally identifiable data such as names, email addresses, and phone numbers) is also collected or transmitted to Meta within our online offering. The processing of contact information serves the creation of audiences (so-called "Custom Audiences") for displaying content and advertising information tailored to the presumed interests of users. The collection, transmission, and matching with data held by Meta do not occur in plain text but as so-called "hash values," i.e., mathematical representations of the data (this method is used, for example, when storing passwords). After matching for audience creation, the contact information is deleted; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Privacy Policy: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Data processing agreement: https://www.facebook.com/legal/terms/dataprocessing; Basis for transfers to third countries: Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum). Further information: https://www.facebook.com/legal/terms/data_security_terms.
  • Facebook Ads: Placement of ads within the Facebook platform and evaluation of ad results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/; Basis for third-country transfers: Data Privacy Framework (DPF); Right to object (Opt-Out): We refer to the privacy and advertising settings in the users' profiles on the Facebook platforms as well as Facebook's consent procedures and contact options for exercising rights of access and other data subject rights, as described in Facebook's privacy policy; Further information: Event data of users, i.e. behavioral and interest information, are processed for the purposes of targeted advertising and audience building based on the agreement on joint responsibility ("Controller Addendum", https://www.facebook.com/legal/controller_addendum). The joint responsibility is limited to the collection and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which particularly concerns the transfer of data to the parent company Meta Platforms, Inc. in the USA (based on the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
  • Google Ad Manager: We use the service "Google Ad Manager" to place ads in the Google advertising network (e.g., in search results, in videos, on websites, etc.). Google Ad Manager is characterized by displaying ads in real time based on presumed user interests. This allows us to show ads for our online offer to users who might have a potential interest in our offer or who have previously shown interest, as well as to measure the success of the ads; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Types of processing as well as processed data: https://business.safety.google/adsservices/; Data processing terms for Google advertising products: Information on the services, data processing terms between controllers and standard contractual clauses for third-country data transfers: https://business.safety.google/adscontrollerterms. where Google acts as a processor, data processing terms for Google advertising products and standard contractual clauses for Third-country data transfers: https://business.safety.google/adsprocessorterms.
  • Google Ads and conversion measurement: Online marketing procedures for the purpose of placing content and ads within the service provider's advertising network (e.g. in search results, in videos, on websites, etc.) so that they are shown to users who are presumed to be interested in the ads. Furthermore, we measure the conversion of the ads, i.e., whether users have taken the ads as an occasion to interact with them and use the advertised offers (so-called conversions). However, we only receive anonymous information and no personal information about individual users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF); Further information: Types of processing and processed data: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for third-country data transfers: https://business.safety.google/adscontrollerterms.
  • Instagram advertisements: Placement of advertisements within the Instagram platform and evaluation of the ad results; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/; Basis for third-country transfers: Data Privacy Framework (DPF); Right to object (opt-out): We refer to the privacy and advertising settings in the users' profiles on the Instagram platform as well as within Instagram's consent procedures and Instagram's contact options for exercising rights of access and other data subject rights in Instagram's privacy policy; Further information: Event data of users, i.e., behavioral and interest information, are processed for the purposes of targeted advertising and audience formation based on the agreement on joint responsibility ("Addendum for Controllers", https://www.facebook.com/legal/controller_addendum). The joint responsibility is limited to the collection by and transmission of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, especially concerning the transfer of data to the parent company Meta Platforms, Inc. in the USA.
  • Microsoft Advertising: Online marketing procedures for the purpose of placing content and Ads within the service provider's advertising network (e.g., in search results, in videos, on websites, etc.), so that they are shown to users who have a presumed interest in the ads. In addition, we measure the conversion of the ads, i.e., whether users have taken the ads as an occasion to interact with them and use the advertised offers (so-called conversion). However, we only receive anonymous information and no personal information about individual users; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://about.ads.microsoft.com/en-us; Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement; Basis for data transfers to third countries: Data Privacy Framework (DPF). Opt-out option: https://account.microsoft.com/privacy/ad-settings/.
  • Pinterest Tag: The "Pinterest Tag" is a code that is executed when visiting our online offer and records users' interactions with our online offer. The "Pinterest Tag" is particularly used for measuring campaign performance, optimizing ad delivery, and building custom and similar audiences within the Pinterest platform and Pinterest's partner network. In doing so, so-called activity data are processed, which include in particular user behavior (e.g., page views, search entries, transactions, video views), technical information (e.g., IP address, operating system, browser type, language settings, cookie data), as well as demographic information (e.g., country or city): https://policy.pinterest.com/de/ad-data-terms. We and Pinterest are jointly responsible for the collection and transmission of this data as well as for the creation of statistical reports. The corresponding joint responsibility agreement can be viewed in the "Pinterest Advertising Service Agreement – Appendix B: Pinterest Appendix for Joint Controllers": https://business.pinterest.com/de/pinterest-advertising-services-agreement/. Pinterest undertakes in particular to comply with appropriate security measures and to respect the rights of data subjects. Users can assert their rights, such as requests for information or deletion, direct against Pinterest. The rights of users remain unaffected by this agreement; Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://help.pinterest.com/en/business/article/track-conversions-with-pinterest-tag; Privacy Policy: https://policy.pinterest.com/de/privacy-policy. Opt-out option: https://help.pinterest.com/de/article/personalized-ads-on-pinterest.
  • UTM Parameters: Analysis of sources and user actions based on an extension of referring web addresses with an additional parameter, the "UTM" parameter. For example, a UTM parameter like "utm_source=platformX &utm_medium=video" can tell us that a person clicked the link on platform X within a video. The UTM parameters provide information about the source of the link, the medium used (e.g., social media, website, newsletter), the type of campaign or the content of the campaign (e.g., post, link, image, and video). Using this information, we can, for example, check our visibility on the internet or the effectiveness of our campaigns; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Facebook Conversions API: We use Facebook's "Conversions API." The Conversions API is an interface through which event data is sent from our servers direct to Facebook. The operation and data processing within the Conversions API correspond to the operation and processing when using the Facebook Pixel, which is why we refer to the privacy notices for the Facebook Pixel and audience formation; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
  • Pipedrive: Cloud-based software for organizing and optimizing our customer and partner relationships as well as managing incoming emails and information requests; Service provider: Pipedrive OÜ, Paldiski mnt 80, Tallinn 10617, Estonia; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.pipedrive.com/de; Privacy policy: https://www.pipedrive.com/en/privacy. Data processing agreement: https://www.pipedrive.com/en/terms-of-service#data-processing-contract.

Affiliate programs and affiliate links

In our online offering, we include so-called affiliate links or other references (which can include search fields, widgets, or discount codes) to the offers and services of third parties (collectively referred to as "affiliate links"). If users follow the affiliate links or subsequently use the offers, we may receive a commission or other benefits from these third parties (collectively referred to as "commission").

To track whether users have used the offers of an affiliate link we have employed, it is necessary for the respective third parties to know that users have followed an affiliate link used within our online offering. The allocation of affiliate links to the respective business transactions or other actions (e.g., purchases) serves solely the purpose of commission accounting and is deleted as soon as it is no longer necessary for that purpose.

For the purposes of the aforementioned allocation of affiliate links, the affiliate links can be supplemented with certain values that are part of the link or can be stored otherwise, e.g., in a cookie. The values can particularly include the Referrer website (referrer), the time, an online identifier of the operators of the website where the affiliate link was located, an online identifier of the respective offer, the type of link used, the type of offer, and an online identifier of the user belong.

Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for processing data is consent. Otherwise, the users' data are processed based on our legitimate interests (i.e., interest in efficient, economical, and user-friendly services). In this context, we also want to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Contract data (e.g., subject of the contract, duration, customer category); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Interested parties. Users (e.g., website visitors, users of online services).
  • Purposes of processing: Affiliate tracking.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further notes on processing procedures, methods, and services:

Presences in social networks (Social Media)

We maintain online presences within social networks and process user data in this context to communicate with users active there or to offer information about us.

We point out that user data may be processed outside the territory of the European Union. This may entail risks for users because, for example, the enforcement of user rights could be made more difficult.

Furthermore, user data within social networks are generally processed for market research and advertising purposes. For example, usage profiles may be created based on the users' usage behavior and resulting interests. These profiles may, in turn, be used to display advertisements within and outside the networks that presumably correspond to the users' interests. Therefore, cookies are generally stored on users' computers in which usage behavior and interests are saved. In addition, user profiles may also store data independent of the devices used by the users (especially if they are members of the respective platforms and logged in there).

For a detailed For the presentation of the respective processing methods and the options to object (opt-out), we refer to the privacy policies and information of the operators of the respective networks.

Also, in the case of information requests and the assertion of data subject rights, we point out that these can be most effectively asserted with the providers. Only the latter have access to the user data and can direct take appropriate measures and provide information. If you still need assistance, you can contact us.

  • Types of data processed: Contact data (e.g., postal and email addresses or phone numbers); content data (e.g., textual or pictorial messages and posts as well as related information such as authorship details or creation time); usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Communication; feedback (e.g., collecting feedback via online form). Public relations.
  • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion".
  • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

Further information on processing procedures, methods, and services:

  • Instagram: Social network that allows sharing photos and videos, commenting and liking posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for transfers to third countries: Data Privacy Framework (DPF).
  • Facebook pages: Profiles within the social network Facebook - The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transfer of data of visitors to our Facebook page ("fan page"). This includes in particular information about user behavior (e.g., viewed or interacted content, actions taken) as well as device information (e.g., IP address, operating system, browser type, language settings, cookie data). Further details can be found in the Facebook Data Policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical evaluations via the "Pages Insights" service, which provide information about how people interact with our page and its content. The basis for this is an agreement with Facebook ("Information about Pages Insights": https://www.facebook.com/legal/terms/page_controller_addendum), which includes security measures among other things. as well as the exercise of the data subjects' rights are regulated. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users can therefore direct requests for information or deletion direct to Facebook. The rights of users (in particular access, deletion, objection, complaint to a supervisory authority) remain unaffected. The joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited alone is responsible for the further processing, including any possible transfer to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
  • LinkedIn: Social network - We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data from visitors that is used to create the "Page Insights" (statistics) of our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as the actions they take. In addition, details about the devices used are collected, such as IP addresses, operating system, browser type, language settings, and cookie data, as well as information from user profiles, such as job function, country, industry, hierarchy level, company size, and employment status. Privacy information regarding the processing of user data by LinkedIn can be found in LinkedIn's privacy notices: https://www.linkedin.com/legal/privacy-policy.
    We have concluded a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum", https://legal.linkedin.com/pages-joint-controller-addendum), which in particular regulates the security measures LinkedIn must observe and in which LinkedIn has declared its willingness to fulfill the rights of data subjects (i.e., users can, for example, direct requests for information or deletion direct to LinkedIn). The rights of users (in particular the right of access, deletion, objection, and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. The joint responsibility is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, a company based in the EU. The further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, especially regarding the transfer of data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://legal.linkedin.com/dpa). Option to object (Opt-Out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
  • Pinterest: Social network, enables sharing photos, commenting, favoriting and curating posts, sending messages, subscribing to profiles; Service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.pinterest.com. Privacy Policy: https://policy.pinterest.com/de/privacy-policy.
  • TikTok: Social network, enables sharing photos and videos, commenting and favoriting posts, sending messages, subscribing to accounts; Service providers: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, United Kingdom, EC1A 9HP; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); Website: https://www.tiktok.com; Privacy Policy: https://www.tiktok.com/de/privacy-policy. Basis for third-country transfers: Standard Contractual Clauses (https://ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms).
  • Vimeo: Social network and video platform; Service provider: Vimeo Inc., Attention: Legal Department, 555 West 18th Street New York, New York 10011, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://vimeo.com. Privacy Policy: https://vimeo.com/privacy.
  • YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Privacy Policy: https://policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Option to object (Opt-Out): https://myadcenter.google.com/personalizationoff.

Plug-ins and embedded functions as well as content

We integrate functional and content elements into our online offer that are retrieved from the servers of their respective providers (hereinafter referred to as "third parties"). For example, this may be about graphics, videos or city maps (hereinafter uniformly referred to as "content").

The integration always assumes that the third-party providers of this content process the users' IP addresses, as they could not send the content to their browsers without an IP address. The IP address is therefore necessary for the display of this content or functions. We strive to use only such content whose respective providers apply the IP address solely for the delivery of the content. Third parties may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Through the "pixel tags," information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information can furthermore be stored in cookies on the users' devices and may include technical information about the browser and operating system, referring websites, visit time, and other details about the use of our online offer, but also be linked with such information from other sources.

Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is the permission granted. Otherwise, user data is processed based on our legitimate interests (i.e., interest in efficient, economical, and recipient-friendly services). In this context, we would also like to point you to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g., page views and duration of stay, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online offer and user-friendliness.
  • Storage and deletion: Deletion according to the information in the section "General information on data storage and deletion." Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods can be stored on users' devices for a period of two years).
  • Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Further notes on processing procedures, methods, and services:

  • Google Fonts (retrieved from Google server): Retrieval of fonts (and symbols) for the purpose of technically secure, maintenance-free, and efficient use of fonts and symbols with regard to timeliness and loading times, their uniform display, and consideration of possible licensing restrictions. The provider of the fonts is informed of the user's IP address so that the fonts can be made available in the user's browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is necessary for the provision of the fonts depending on the devices used and the technical environment. These data may be processed on a server of the font provider in the USA - When visiting our online offer, the users' browsers send their browser HTTP requests to the Google Fonts Web API (i.e., a software interface for retrieving fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) from Google Fonts and then the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of the website visitors, as well as the referrer URL (i.e., the website on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers, and they are not analyzed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user agent, and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so that Google can determine how often a particular font family is requested. In the Google Fonts Web API, the user agent must adapt the font generated for the respective browser type. The user agent is primarily logged and used for debugging and to generate aggregated usage statistics that measure the popularity of font families. These aggregated usage statistics are published on the "Analytics" page of Google Fonts. Finally, the referrer URL is logged so that the data can be used for production maintenance and an aggregated report on the top integrations based on the number of font requests can be generated. According to Google’s own statements, Google does not use any of the information collected by Google Fonts to create profiles of end users or to serve targeted advertisements; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://fonts.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: Data Privacy Framework (DPF). Further information: https://developers.google.com/fonts/faq/privacy?hl=de.

Changes and Updates

We ask you to regularly inform yourself about the content of our privacy policy. We adjust the privacy policy as soon as changes in the data processing we carry out make this necessary. We will inform you as soon as the changes require an action on your part (e.g., consent) or any other individual notification.

If we provide addresses and contact information of companies and organizations in this privacy policy, please note that addresses may change over time, and we ask you to verify the information before making contact.

Definitions

This section provides you with an overview of the terminology used in this privacy policy. As far as the terms are legally defined, their legal definitions apply. The following explanations are primarily intended to aid understanding.

  • A/B tests: A/B tests are used to improve the user-friendliness and performance of online offerings. In this process, users are shown different versions of a website or its elements, such as input forms, where the placement of content or the labels of navigation elements may differ. Subsequently, based on user behavior, e.g., longer time spent on the website or more frequent interaction with the elements, it can be determined which of these websites or elements better meet the users' needs.
  • Affiliate tracking: In the context of affiliate tracking, links that allow linking websites to refer users to websites with product or other offers are logged. The operators of the respective linking websites can receive a commission if users follow these so-called affiliate links and subsequently take advantage of the offers (e.g., purchase goods or use services). For this, it is necessary that providers can track whether users interested in certain offers subsequently take advantage of them due to the affiliate links. Therefore, for the functionality of affiliate links, it is necessary that they are supplemented with certain values that become part of the link or are otherwise stored, e.g., in a cookie. These values include, in particular, the originating website (referrer), the time, an online identifier of the operators of the website where the affiliate link was located, an online identifier of the respective offer, an online identifier of the user, as well as tracking-specific values such as advertising ID, partner ID, and categorizations.
  • Master data: Master data includes essential information necessary for the identification and management of contracting parties, user accounts, profiles, and similar assignments. These data can include, among other things, personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Master data forms the basis for any formal interaction between individuals and services, institutions, or systems by enabling unique assignment and communication.
  • Credit report: Automated decisions are based on automatic data processing without human intervention (e.g., in the case of automatic rejection of a purchase on account, an online credit application, or an online application process without any human involvement). Such automated decisions are only permissible under Article 22 GDPR if the data subject consents, if they are necessary for the performance of a contract, or if national laws allow these decisions.
  • Cross-device tracking: Cross-device tracking is a form of tracking where behavioral and interest information of users is collected across devices in so-called profiles by assigning users an online identifier. This allows user information to be analyzed for marketing purposes regardless of the browsers or devices used (e.g., mobile phones or desktop computers). For most providers, the online identifier is not linked to clear data such as names, postal addresses, or email addresses.
  • Heatmaps: "Heatmaps" are mouse movements of users that are compiled into an overall picture, which can be used, for example, to identify which website elements are preferred and which website elements users less prefer.
  • Content data: Content data includes information generated in the course of creating, editing, and publishing all types of content. This category of data can include texts, images, videos, audio files, and other multimedia content published on various platforms and media. Content data is not limited to the actual content but also includes metadata that provides information about the content itself, such as tags, descriptions, author information, and publication dates.
  • Click tracking: Click tracking allows monitoring users' movements within an entire online offering. Since the results of these tests are more accurate when user interaction can be tracked over a certain period (e.g., so we can find out if a user likes to return), cookies are usually stored on users' computers for these testing purposes.
  • Contact data: Contact data are essential information that enables communication with individuals or organizations. They include, among other things, phone numbers, postal addresses, and email addresses, as well as communication means such as social media handles and instant messaging identifiers.
  • Conversion measurement: Conversion measurement (also known as "visit action evaluation") is a method used to determine the effectiveness of marketing measures. Typically, a cookie is stored on users' devices within the websites where the marketing measures take place and then retrieved again on the target website. For example, this allows us to track whether the ads we placed on other websites were successful.
  • Meta, communication, and procedural data: Meta, communication, and procedural data are categories that contain information about how data is processed, transmitted, and managed. Meta-data, also known as data about data, includes information that describes the context, origin, and structure of other data. They can include details such as file size, creation date, author of a document, and change histories. Communication data capture the exchange of information between users across various channels, such as email traffic, call logs, messages on social networks, and chat histories, including the involved persons, timestamps, and transmission paths. Procedural data describe the processes and workflows within systems or organizations, including workflow documentation, logs of transactions and activities, as well as audit logs used for tracking and verifying processes.
  • Usage data: Usage data refers to information that records how users interact with digital products, services, or platforms. This data includes a Width range of information showing how users use applications, which features they prefer, how long they stay on certain pages, and the paths they navigate through an application. Usage data can also include usage frequency, timestamps of activities, IP addresses, device information, and location data. They are particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content, and improving products or services. Furthermore, usage data play a crucial role in identifying trends, preferences, and potential problem areas within digital Offers
  • Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles with user-related information: The processing of "profiles with user-related information," or simply "profiles," includes any form of automated processing of personal data consisting of using such personal data to analyze, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information concerning demographics, behavior and interests, such as interaction with websites and their content, etc.). Profiling purposes often involve the use of cookies and web beacons.
  • Log data: Log data are information about events or activities that have been recorded in a system or network. These data typically include information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system. Log data are often used for system problem analysis, security monitoring, or performance reporting.
  • Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and may include the behavior or interests of visitors in certain information, such as website content. Using reach analysis, operators of online offerings can, for example, determine at what times users visit their websites and which content interests them. This allows them to better tailor the website content to the needs of their visitors. For reach analysis purposes, pseudonymous cookies and web beacons are often used to recognize returning visitors and thus obtain more accurate analyses of the use of an online offering.
  • Remarketing: "Remarketing" or "retargeting" refers to, for example, recording for advertising purposes which products a user has shown interest in on a website in order to remind the user of these products on other websites, e.g., through advertisements.
  • Tracking: "Tracking" refers to the ability to trace user behavior across multiple online offerings. Typically, behavioral and interest information related to the used online offerings is stored in cookies or on servers of the providers of tracking technologies (so-called profiling). This information can then be used, for example, to display advertisements to users that are likely to correspond to their interests.
  • Controller: The "controller" is the natural or legal person, authority, institution, or other body which alone or jointly with others determines the purposes and means of the processing of decides personal data.
  • Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and practically includes any handling of data, such as collecting, evaluating, storing, transmitting, or deleting.
  • Contract data: Contract data are specific information relating to the formalization of an agreement between two or more parties. They document the terms under which services or products are provided, exchanged, or sold. This data category is essential for managing and fulfilling contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include start and end dates of the contract, the type of agreed services or products, price agreements, payment terms, cancellation rights, extension options, and special conditions or clauses. They serve as the legal basis for the relationship between the parties and are crucial for clarifying rights and obligations, enforcing claims, and resolving disputes.
  • Payment data: Payment data include all information necessary to process payment transactions between buyers and sellers. This data is critical for e-commerce, online banking, and any other form of financial transaction. It includes details such as credit card numbers, bank account information, payment amounts, transaction dates, verification numbers, and billing information. Payment data may also include information about payment status, chargebacks, authorizations, and fees.
  • Audience formation: Audience formation (English "Custom Audiences") refers to defining target groups for advertising purposes, e.g., displaying advertisements. For example, based on a user's interest in certain products or topics on the internet, it can be inferred that this user is interested in ads for similar products or the online shop where they viewed the products. "Lookalike Audiences" (or similar audiences) refers to showing content deemed suitable to users whose profiles or interests presumably correspond to those of the users from whom the audiences were formed. For the purpose of creating Custom Audiences and Lookalike Audiences, cookies and web beacons are typically used.

Privacy information about the Instagram contest

Within the framework of the contest on our Instagram account @grau, we process personal data exclusively for the execution of the contest.

  1. Controller
    Grau GmbH
    Siemensstraße 35b
    25462 Rellingen
    Email: support@grau.art

  2. Which data we process
    • Instagram username
    • publicly visible profile data
    • comment
    • for winners: name, address, email

  3. Purpose of processing
    • Execution of the contest
    • Determination and contact of winners
    • Shipping of the prize

  4. Legal basis
    • Art. 6 para. 1 lit. b GDPR
    • for publication: Art. 6 para. 1 lit. a GDPR

  5. Recipients
    Only shipping service providers if necessary.

  6. Storage duration
    • Deletion of participant data after the end
    • Deletion of winner data after processing

  7. Rights
    • Information, correction, deletion, restriction, objection, data portability
    Contact: datenschutz@grau.art

  8. Note on Instagram/Meta
    No connection with Instagram/Meta. Processing by Meta under its own responsibility.