Privacy Policy

Privacy policy

Unless otherwise stated below, the provision of your personal information is neither required by law nor by contract, nor required to conclude a contract. You are not required to provide the data. A non-provisioning has no consequences. This applies only insofar as no other indication is given in the subsequent processing operations.
"Personal data" is all information that relates to an identified or identifiable natural person.

Server log files

You can visit our website without giving any personal information. 

Every time you access our website, usage data is transmitted to us or our web host / IT service provider by your Internet browser and stored in log data (so-called server log files). This stored data includes, for example, the name of the page called up, the date and time of the call, the IP address, the amount of data transferred and the requesting provider.
The processing takes place on the basis of Art. 6 Paragraph 1 lit. f GDPR from our overriding legitimate interest in ensuring trouble-free operation of our website and improving our offer. 
Your data may be transferred to third countries outside the European Union for which the EU Commission has issued an adequacy decision.

Contact

Controller
Please contact us if you wish. The data controller is: Ute Helmreich, Alter Markt 13, 25335 Elmshorn, Germany, +49 4121 7015079, info@dudea-latexshop.de

Unsolicited contact of the customer by email
If you initiate business contact with us via e-mail, we will only collect your personal data (name, e-mail address, message text) to the extent that you have provided. The data processing serves to process and answer your contact request.
If the establishment of contact serves to carry out pre-contractual measures (e.g. advice on purchase interests, preparation of offers) or relates to a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.
If contact is made for other reasons, this data processing takes place on the basis of Article 6 Paragraph 1 Letter f GDPR from our overriding legitimate interest in processing and answering your request. In this case, you have the right, for reasons arising from your particular situation, to do so at any time in accordance with Art. 6 Para. 1 lit. to object to processing based on the GDPR relating to your personal data.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.

Collection and processing when using the contact form
When you use the contact form, we only collect your personal data (name, email address, message text) to the extent that you have provided. The data processing serves the purpose of establishing contact.
If the establishment of contact serves to carry out pre-contractual measures (e.g. advice on purchase interests, preparation of offers) or relates to a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.
If contact is made for other reasons, this data processing takes place on the basis of Article 6 Paragraph 1 Letter f GDPR from our overriding legitimate interest in processing and answering your request. In this case, you have the right, for reasons arising from your particular situation, to do so at any time in accordance with Art. 6 Para. 1 lit. to object to processing based on the GDPR relating to your personal data.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.

Collection and processing when sending images via upload
We provide an upload function for image files on our website. It is thus possible to send images to us using encrypted data transmission. With the transmission of your images, we may only collect your personal data (image of an identifiable person) to the extent provided by you. The purpose of data processing is to create personalized products. The image sent serves as a template for the product and is used for this (e.g. t-shirt print). The processing takes place on the basis of Article 6 Paragraph 1 lit. b GDPR and is necessary for the fulfillment of a contract with you.
Your data may be shared with service providers that we use for order processing. It will not be shared with any other third parties.
We only use the image you send us as part of the provision of services. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.

Collection and processing when sending images by email 
You have the option of sending us pictures by e-mail in connection with ordering a personalized product.
With the transmission of your images, we may only collect your personal data (image of an identifiable person) to the extent provided by you. The purpose of data processing is to create personalized products. The image sent serves as a template for the product and is used for this (e.g. t-shirt print). The processing takes place on the basis of Article 6 Paragraph 1 lit. b GDPR and is necessary for the fulfillment of a contract with you.
Your data will not be passed on. 
We only use the image you send us as part of the provision of services. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.

Customer account orders      

Account
When opening a customer account, we collect your personal data in the scope indicated there. The purpose of data processing is to improve your shopping experience and simplify order processing. The processing takes place on the basis of Art. 6 para. 1 lit. a DSGVO with your consent. You may revoke your consent at any time by notifying us without affecting the legality of the processing based on the consent to revocation. Your customer account will be deleted afterwards.

Collection, processing and transfer of personal data during orders

When ordering, we collect and process your personal data only to the extent necessary for the fulfillment and processing of your order and to process your requests. The provision of the data is required for the conclusion of the contract. Non-provisioning means that no contract can be concluded. The processing takes place on the basis of Art. 6 para. 1 lit. b DSGVO and is required to fulfill a contract with you. 

Your data will be passed on to, for example, shipping companies, dropshipping or fulfillment providers, payment service providers, service providers for order processing and IT service providers. In all cases, we strictly adhere to the legal requirements. The scope of data transmission is limited to a minimum.

Your data may be transferred to third countries outside the European Union for which the EU Commission has issued an adequacy decision. 
 Reviews       Advertising      

Store Information Customer Review
We use the rating tool “shopauskunft.de” from Händlerbund Management AG (Kohlgartenstraße 11 – 13, 04315 Leipzig; “Shopauskunft”) for our website.
After placing your order, we would like to ask you to rate and comment on your purchase. For this purpose, we will contact you by email using the "Legally Compliant Rating Request (RBA)" system. We will process your order data (order number/invoice number, purchase value, and shipping costs) as well as your email address. We may also use this data to verify your rating.

The processing is based on Art. 6 Abs.1 lit. a DSGVO with your consent, provided that you have expressly consented to the disclosure of your data and the receipt of the evaluation request.
You may revoke your consent at any time by using the appropriate link in the e-mail or by notifying us, without affecting the legality of the processing based on the consent to revocation.
Further information on data protection when using shop information can be found at: 
https://www.shopauskunft.de/datenschutz.
Website logo for Google customer reviews
The website logo for Google Customer Reviews of Google LLC (1600 Amphitheater Parkway, Mountain View, CA 94043, USA; “Google”) is integrated on our website.
The purpose of the integration is to display the number and results of our ratings received so far via Google and to advertise participation in this program.
Google uses cookies to display the logo on our website and to show you personalized advertisements on Google. Your IP address can be processed and transmitted to Google.
Your data may be transmitted to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus obliged to comply with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Article 6 Paragraph 1 Letter a GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation.
For more information on terms of use and data protection when using Google Customer Reviews, see https://www.google.com/shopping/customerreviews/static/tos/de/1_01_tos.html as well as under https://policies.google.com/privacy?hl=de

Using the e-mail address to receive newsletters
We use your email address to send you information and offers via newsletter, provided you have expressly consented to this. Data processing serves exclusively for the purpose of advertising. For this purpose, we process your email address and, if applicable, other data that you have voluntarily provided when registering for our newsletter.
The processing is based on Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
You can unsubscribe from the newsletter at any time by using the corresponding link in the newsletter or by notifying us. Your email address will then be removed from the mailing list. Despite being removed from the mailing list, we may continue to store your email address on a so-called blacklist to prevent you from receiving newsletter emails from us in the future. This storage is based on Art. 6 (1) (f) GDPR, which is our and your legitimate interest in preventing the further use of your email address to send you our newsletter. For reasons that arise from your particular situation, you have the right to object to this processing of your personal data at any time.

Using the e-mail address for sending direct mail
We use your e-mail address, which we obtained in connection with the sale of a good or service, for the electronic transmission of advertising for own goods or services, which are similar to those, which you already acquired with us, as far as this Use did not contradict. The provision of the e-mail address is required for the conclusion of the contract. Non-provisioning means that no contract can be concluded. The processing takes place on the basis of Art. 6 para. 1 lit. f DSGVO from our predominant legitimate interest in direct mail. You may object to this use of your e-mail address at any time by notifying us.The contact details for the exercise of the contradiction can be found in the imprint. You can also use the dedicated link in the promotional e-mail. There are no other costs than the transmission costs according to the basic tariffs.

Using CleverReach
We use the service of CleverReach GmbH & Co. KG (Schafjückenweg 2, 26180 Rastede; “CleverReach”) for sending newsletters as part of a data processing agreement.
We pass on the information you provide when registering for the newsletter (e-mail address, first and last name if applicable) to CleverReach. The data processing serves the purpose of sending the newsletter and its statistical evaluation.
To evaluate newsletter campaigns, the newsletters we send contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any embedded links. Conversion tracking enables us to analyze, for example, whether a purchase was made after clicking a link in the newsletter or whether you registered on our website. In this context, we collect your personal data, such as your IP address, browser type and device, and the time of access. Usage profiles can be created from this data under a pseudonym. The collected data is not used to personally identify you. It is used solely for statistical analysis to improve our newsletter campaigns.
The processing of your personal data takes place on the basis of Art. 6 Para. 1 lit. f GDPR from our overriding legitimate interest in a targeted, promotionally effective and user-friendly newsletter system. You have the right to object to the processing of your personal data at any time for reasons that arise from your particular situation.
Further information and Cleverreach's privacy policy can be found at: https://www.cleverreach.com/de-de/datenschutz/ and https://www.cleverreach.com/de-de/newsletter-tool/newsletter-reporting/.

Using Mailchimp
We use the service of Rocket Science Group LLC (675 Ponce de Leon Ave NE, Suite 5000 Atlanta, GA 30308, USA; "Mailchimp") to send the newsletter as part of order processing.
We pass on the information you provide when registering for the newsletter (e-mail address, first and last name if applicable) to Mailchimp. The data processing serves the purpose of sending the newsletter and its statistical evaluation.
In order to evaluate newsletter campaigns, the newsletters sent contain a 1×1 pixel graphic (tracking pixel) or a tracking link. This enables us to determine whether you have opened the newsletter and whether you have clicked on any integrated links. In this context, we collect your personal data such as IP address, browser type and device and the time. User profiles can be created from this data under a pseudonym. The data collected will not be used to identify you personally. The data collected is only used for statistical evaluation to improve newsletter campaigns.
Your data is generally transferred to and stored on Mailchimp servers in the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Mailchimp is not certified under the TADPF. Data transfers are based, among other things, on standard contractual clauses as suitable safeguards for the protection of personal data, which can be viewed at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_de.
The processing of your personal data takes place on the basis of Art. 6 Para. 1 lit. f GDPR from our overriding legitimate interest in a targeted, promotionally effective and user-friendly newsletter system. You have the right to object to the processing of your personal data at any time for reasons that arise from your particular situation.
You can find more information and MailChimp's privacy policy at: https://mailchimp.com/de/legal/data-processing-addendum/ and https://www.intuit.com/privacy/statement/

Shipping service       ERP      

Forwarding the e-mail address to shipping companies for information about the shipping status
We will pass on your e-mail address as part of the contract to the transport company, if you have agreed to this explicitly in the ordering process. The purpose of the disclosure is to inform you by e-mail about the delivery status. The processing takes place on the basis of Art. 6 para. 1 lit. a DSGVO with your consent. You may revoke your consent at any time by notifying us or the carrier without affecting the legality of the processing carried out on the basis of the consent to revocation.

Use of an external ERP system
We use a merchandise management system as part of order processing for contract execution. Your personal data collected during the order process will be used for this purpose
DUDEA Latex, Alter Markt 13, 25335 Elmshorn 
transmitted.

The processing of your personal data serves the purpose of fulfilling the contract concluded with you and is carried out on the basis of Article 6 Paragraph 1 Letter b GDPR.

payment service      

Using PayPal Express
We use the PayPal Express payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the PayPal Express payment service. In order to integrate this payment service, PayPal must collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when you visit the website. Cookies can also be used for this purpose. The cookies enable your browser to be recognized.
The processing of your personal data takes place on the basis of Art. 6 Paragraph 1 lit. For reasons that arise from your particular situation, you have the right to object to this processing of your personal data at any time.
With the selection and use of PayPal Express, the data required for payment processing will be transmitted to PayPal in order to be able to fulfill the contract with you with the selected payment method. This processing takes place on the basis of Art. 6 Para. 1 lit. b GDPR. For more information on data processing when using the PayPal Express payment service, see the associated data protection declaration at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE#Updated_PS.

Using PayPal Check Out
We use the PayPal Check-Out payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the payment service. With the selection and use of payment via PayPal, credit card via PayPal, direct debit via PayPal or "Pay later" via PayPal, the data required for payment processing is transmitted to PayPal in order to be able to fulfill the contract with you with the selected payment method. This processing takes place on the basis of Article 6 Paragraph 1 Letter b GDPR.

Cookies can be stored here, which enable your browser to be recognized. The resulting data processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in a customer-oriented offer of different payment methods. For reasons that arise from your particular situation, you have the right to object to this processing of your personal data at any time.

Credit card via PayPal, direct debit via PayPal & "Pay later" via PayPal 
For individual payment methods such as credit card via PayPal, direct debit via PayPal or "Pay later" via PayPal, PayPal reserves the right to obtain creditworthiness information on the basis of mathematical-statistical procedures using credit agencies. For this purpose, PayPal transmits the personal data required for a credit check to a credit agency and uses the information received about the statistical probability of a payment default for a balanced decision on the establishment, implementation or termination of the contractual relationship. The credit report can contain probability values ​​(score values), which are calculated on the basis of scientifically recognized mathematical-statistical methods and which, among other things, include address data. Your concerns will be considered in accordance with the statutory provisions. The data processing serves the purpose of a credit check for the initiation of a contract. The processing takes place on the basis of Art. 6 (1) (f) GDPR from our overriding legitimate interest in protection against non-payment if PayPal makes an advance payment. 
You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data based on Article 6 (1) (f) GDPR by notifying PayPal. The provision of the data is necessary for the conclusion of a contract with the payment method you require. Failure to provide this means that the contract cannot be concluded with the payment method you have chosen.

Third party providers
When paying via a third-party payment method, the data required for payment processing is transmitted to PayPal. This processing takes place on the basis of Article 6 Paragraph 1 Letter b GDPR. In order to carry out this payment method, the data may then be passed on to the respective provider by PayPal. This processing takes place on the basis of Article 6 Paragraph 1 Letter b GDPR. Examples of local third-party providers can be:

  • Apple Pay (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
  • Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)

Purchase on account via PayPal 
When paying using the payment method purchase on account, the data required for payment processing is first sent to PayPal. To carry out this payment method, the data is then sent by PayPal to Ratepay GmbH (Franklinstraße 28-29, 10587 Berlin; "Ratepay") in order to be able to fulfill the contract with you with the selected payment method. This processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR. Ratepay may carry out a credit check on the basis of mathematical-statistical procedures (probability or score values) using credit agencies according to the process already described above. The data processing serves the purpose of credit checks for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protecting against payment default when Ratepay makes advance payments. Further information on data protection and which credit agencies use Ratpay can be found at https://www.ratepay.com/legal-payment-dataprivacy/ and https://www.ratepay.com/legal-payment-creditagencies/

More information on data processing when using PayPal can be found in the associated data protection declaration https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

Use of the payment service provider Stripe

We use the payment service Stripe from Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland) on our website. The data processing serves the purpose of being able to offer you payment via the payment service. By selecting and using Stripe, the data required for payment processing is transmitted to Stripe in order to be able to fulfill the contract with you using the selected payment method. This processing takes place on the basis of Article 6 Paragraph 1 Letter b GDPR. 

Stripe reserves the right, if necessary, to obtain a credit report based on mathematical-statistical processes using credit agencies. For this purpose, Stripe transmits the personal data required for a credit check to a credit agency and uses the information received about the statistical probability of non-payment for a balanced decision on the establishment, implementation or termination of the contractual relationship. The credit report can contain probability values ​​(score values), which are calculated on the basis of scientifically recognized mathematical-statistical methods and which, among other things, include address data. Your concerns will be considered in accordance with the statutory provisions. The data processing serves the purpose of a credit check for the initiation of a contract. The processing takes place on the basis of Art. 6 (1) lit. f GDPR from our overriding legitimate interest in protection against non-payment if Stripe pays in advance. 

You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data based on Article 6 (1) (f) GDPR by notifying Stripe. The provision of the data is necessary for the conclusion of a contract with the payment method you require. Failure to provide this means that the contract cannot be concluded with the payment method you have chosen.

All Stripe transactions are subject to the Stripe Privacy Policy. You can find it at https://stripe.com/de/privacy 

Cookie policy

Our website uses cookies. Cookies are small text files that are stored in the Internet browser or the Internet browser on the computer system of a user. When a user visits a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string that allows the browser to be uniquely identified when the website is reopened.

Cookies are stored on your computer. Therefore, you have full control over the use of cookies. By selecting the appropriate technical settings in your Internet browser, you can be notified before cookies are set and decide individually whether to accept them and prevent the storage of cookies and the transmission of the data they contain. Cookies that have already been saved can be deleted at any time. However, we would like to point out that you may then not be able to use all the functions of this website to their full extent.

Under the links below you can find out how to manage (among other things disable) cookies on the most important browsers:

Chrome: https://support.google.com/accounts/answer/61416?hl=de
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09

Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen

Safari: https://support.apple.com/de-de/guide/safari/manage-cookies-and-website-data-sfri11471/mac

Technically necessary cookies

Unless otherwise stated in the data protection declaration below, we only use these technically necessary cookies for the purpose of making our offer more user-friendly, more effective and more secure. Furthermore, cookies enable our systems to recognize your browser even after changing pages and to offer you services. Some functions of our website cannot be offered without the use of cookies. For this it is necessary that the browser is recognized even after a page change.

The use of cookies or comparable technologies is based on Section 25 Paragraph 2 TDDDG. Your personal data is processed on the basis of Article 6 Paragraph 1 Letter f of the GDPR due to our overriding legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective design of our offering.

For reasons that arise from your particular situation, you have the right to object to this processing of your personal data at any time.

Using Compliance GDPR Cookie Consent

We use the Complianz GDPR Cookie Consent plugin from iubenda srl ​​(Via San Raffaele 1, 20121 Milan, Italy; “iubenda”) on our website.

This plug-in allows you to grant consent to data processing via the website, in particular the setting of cookies, and to exercise your right to withdraw previously granted consent. The data processing serves the purpose of obtaining and documenting necessary consents for data processing and thus complying with legal obligations. Cookies may be used for this purpose. The following information, among other things, may be collected and transmitted to iubenda: a uniquely identifiable ID and consent status. This data will not be shared with any other third parties.

Data processing takes place to fulfill a legal obligation on the basis of Art. 6 Para. 1 lit. c GDPR.

Further information on data protection can be found at: https://complianz.io/de/legal-deutsch/datenschutzerklaerung-von-complianz-shopify/

Analysis       

Use of Google Analytics 4
We use the web analysis service Google Analytics from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website.
The data processing serves the purpose of analyzing this website and its visitors as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. 
The following information can be collected, among other things: IP address, date and time of page access, click path, information about the browser you use and the device you use, pages visited, referrer URL (website through which you visit our website). website), location data, purchasing activities. Your data may be linked by Google with other data, such as your search history, your personal accounts, your usage data from other devices and any other data that Google has about you.

Your IP address will first be shortened by us on our own servers. Google only receives pseudonymized data.

Google uses technologies such as cookies, web storage in the browser and tracking pixels, which enable an analysis of your use of the website. The use of cookies or similar technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Art. 6 Paragraph 1 Letter a of GDPR. 

The processing of your personal data takes place with your consent on the basis of Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation.

We use the advanced implementation of consent mode (Advanced Consent Mode). Even if consent is not given, user data is transmitted to Google in the form of "pings". These pings can contain the following information, among others: IP address to derive the IP country (the IP address is not logged), date and time of the page visit, URL of the pages visited, user agent, referrer URL (website from which our website was accessed) or information about the triggering of website events such as a conversion. On the basis of this information, Google models user data in order to be able to carry out a comprehensive usage analysis despite the refusal of consent.

The information generated in this way about your use of this website is usually transmitted to a Google server in the USA and stored there. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is therefore obliged to comply with European data protection principles. Both Google and US government authorities have access to your data.

For more information about Terms of Use and Privacy, please see https://policies.google.com/technologies/partner-sites and under https://policies.google.com/privacy?hl=de&gl=de.

Plug-ins and other

Use of the Google Tag Manager
We use the Google Tag Manager from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website. 
This application manages JavaScript tags and HTML tags that are used to implement tracking and analysis tools in particular. The data processing serves the purpose of the needs-based design and optimization of our website.
The Google Tag Manager itself does not save cookies nor does it process personal data. However, it enables the triggering of further tags that can collect and process personal data.
You can find more information on terms of use and data protection here.

Using Google reCAPTCHA 

We use the reCAPTCHA service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website. The query is used to distinguish between input by a human and automated, machine processing. For this purpose, your input is transmitted to Google and used there. In addition, the IP address and any other data required by Google for the reCAPTCHA service are transmitted to Google. This data is processed by Google within the European Union and may also be transmitted to Google LLC servers in the USA. For the USA, the EU Commission has issued an adequacy decision, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is therefore committed to adhering to European data protection principles.

The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Article 6 Paragraph 1 Letter a GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation.

For more information about Google reCAPTCHA and its privacy policy, please visit: https://www.google.com/recaptcha/intro/android.html and https://www.google.com/privacy.
Use of Google invisible reCAPTCHA
We use the invisible reCAPTCHA service from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website. 
This serves the purpose of differentiating the input by a person or by automated, machine processing. In the background, Google collects and analyzes usage data, which Invisible reCaptcha uses to distinguish regular users from bots. For this purpose, your input will be transmitted to Google and used there. In addition, the IP address and any other data required by Google for the Invisible reCAPTCHA service will be transmitted to Google.
This data is processed by Google within the European Union and may also be transferred to servers of Google LLC in the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself under the TADPF and has thus committed to complying with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Article 6 Paragraph 1 Letter a GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation.
For more information about Google reCAPTCHA and its privacy policy, please visit: https://www.google.com/recaptcha/intro/android.html and https://www.google.com/privacy

Using Wordfence
We use the security plugin Wordfence from Defiant Inc. (00 5th Ave Ste 4100, Seattle, WA 98104, USA “Wordfence”) on our website as part of order processing. Data processing serves in particular to protect against viruses and malware and to detect and defend against brute force and DDoS attacks. For this purpose, Wordfence uses cookies to classify website visitors as questionable or harmless. For this purpose, among other things, the IP address of the website visitor is stored on Wordfence's servers. IP addresses that are classified as harmless are placed on a white list. Questionable IP addresses, however, end up on a blacklist. For this purpose, our website establishes a permanent connection to Wordfence's servers so that Wordfence can compare its databases with the access made to our website and, if necessary, block them.
Your data will be transferred to the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Wordfence is not TADPF certified. The data transfer is based, among other things, on standard contractual clauses as suitable safeguards for the protection of personal data, which can be viewed at: https://www.wordfence.com/standard-contractual-clauses/.
The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Article 6 Paragraph 1 Letter a GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation.
Further information on the collection and use of data by Wordfence, your related rights and options for protecting your privacy can be found in Wordfence's privacy policy at https://www.wordfence.com/privacy-policy/ and https://www.wordfence.com/help/general-data-protection-regulation/#standard-contractual-clauses.
Use of YouTube
We use the function for embedding YouTube videos from Google Ireland Limited on our website (Gordon House, Barrow Street, Dublin 4, Ireland; "YouTube"). YouTube is one with Google LLC (1600 Amphitheater Parkway, Mountain View, CA) 94043, USA; “Google”) affiliate.
The function displays videos stored on YouTube in an iFrame on the website. The option "Extended data protection mode" is activated. As a result, YouTube does not store any information about visitors to the website. Only when you watch a video is information about it sent to YouTube and stored there. Your data may be transmitted to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). YouTube has certified itself according to the TADPF and is thus obliged to comply with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Article 6 Paragraph 1 Letter a GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation.
Further information on the collection and use of data by YouTube and Google, your rights in this regard and options for protecting your privacy can be found in YouTube's data protection information at https://www.youtube.com/t/privacy.

Integration of the Händlerbund member logo
The Händlerbund member logo (Händlerbund eV, Kohlgartenstraße 11 - 13, 04315 Leipzig) is integrated into our website. When you visit our website, the browser used on your device automatically sends information to the Händlerbund eV server. This information is temporarily stored in a so-called server log file for 7 days. The following information is recorded without your intervention and stored until it is automatically deleted:

  • IP address of the requesting computer,
  • Date and time of access,
  • Name and URL of the retrieved file,
  • Website from which access is made (referrer URL),
  • used browser and, if applicable, the operating system of your computer as well as the name of your access provider. 

The temporary storage of the IP address by the system is necessary to enable the website to be delivered. For this purpose, the IP address must be stored for the duration of the session. The data is stored in log files to ensure the functionality of the website. The data is also used to optimize the website and to ensure the security of the information technology systems. This data is not stored together with other personal data. The legal basis for data processing is Art. 6 Para. 1 Clause 1 Letter f of GDPR.

Use of Google Translate 

We use the translation service on our website via an API integration 

Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).

The data processing serves the purpose of presenting the information provided on the website in a different language. In order for the translation to be automatically displayed after you have selected a national language, the browser you are using connects to the Google servers. Cookies can be used here. Among other things, the following information can be collected and processed: IP address, URL of the page visited, date and time.
Your data may be transmitted to the USA. The EU Commission has an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus obliged to comply with European data protection principles.

The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Article 6 Paragraph 1 Letter a GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Para. 1 lit. a GDPR. You can revoke your consent at any time without affecting the lawfulness of the processing carried out based on your consent before its revocation. 

You can find more information about the collection and use of your data by Google at: https://www.google.com/policies/privacy/.
Affected rights and storage duration

Duration of storage
After completion of the contract, the data is first stored for the duration of the warranty period, then taking into account statutory, especially tax and commercial retention periods and then deleted after the deadline, unless you have consented to the further processing and use.

Rights of the person concerned
You are entitled to the following rights under Art. 15 to 20 DSGVO if the legal prerequisites are met: Right to information, to correction, to deletion, to restriction of processing, to data portability.
Furthermore, according to Art. 21 para. 1 DSGVO, you are entitled to a right of objection to the processing based on Art. 6 para. 1 f DSGVO as well as the processing for the purpose of direct mail.

Right of appeal to the supervisory authority
In accordance with Art. 77 DSGVO, you have the right to complain to the supervisory authority if you believe that the processing of your personal data is not lawful.

You can lodge a complaint with the supervisory authority responsible for us, which you can reach under the following contact details:

Independent State Center for Data Protection Schleswig-Holstein
Mailbox 71 16
24171 Kiel
Phone: + 49 431 9881200
Fax: +49 431 9881223
Email: mail@datenschutzzentrum.de

Right of objection
The personal data processing listed here is based on our legitimate interest in accordance with Art. 6 para. 1 lit. f DSGVO, you have the right for reasons that arise from your particular situation, at any time to object to these processing with effect for the future.
Following an objection, processing of the data in question will cease unless we can establish compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or if the processing is for the purposes of asserting, exercising or defending legal claims.

If the personal data processing for purposes of direct mail, you can object to this processing at any time by notifying us. After the objection, we will stop the processing of the data concerned for the purpose of direct mailing.

last update: 22.10.2024