data protection
Privacy Policy Pasquariello Willers GbR
1. Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit
this website. Personal data is any data that can be used to identify you personally. For detailed information
on data protection, please refer to our privacy policy provided below this text.
Data Collection on this Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the
"Information on the Controller" section of this privacy policy.
How do we collect your data?
Your data is collected, on the one hand, by you providing it to us. This may include, for example, data that you
enter into a contact form.
Other data is collected automatically by our IT systems when you visit the website or after you have given your
consent. This mainly concerns technical data (e.g. internet browser, operating system or time of page view).
This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the website is provided without errors. Other data can be used to
analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data will
also be processed for contract offers, orders or other order inquiries.
What rights do you have regarding your data?
You have the right to obtain information free of charge at any time about the origin, recipient and purpose of
your stored personal data. You also have the right to request the rectification or erasure of this data. If you have
given consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have
the right to request the restriction of the processing of your personal data under certain circumstances.
Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this and other questions on the subject of data protection.
Analysis Tools and Third-Party Tools
When visiting this website, your surfing behavior can be statistically evaluated. This is mainly done with so-
called analysis programs.
3 / 25You can find detailed information on these analysis programs in the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
Shopify
The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32,
Ireland (hereinafter “Shopify”).
Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address
and information about the device you are using and your browser. Shopify also analyzes visitor numbers, visitor
sources, and customer behavior and creates user statistics. If you make a purchase on our website, Shopify also
collects your name, email address, shipping and billing addresses, payment data, and other data related to the
purchase (e.g., telephone number, amount of sales made, etc.). For analyses, Shopify stores cookies in your
browser.
For details, please refer to Shopify's privacy policy:
https://www.shopify.de/legal/datenschutz.
The use of Shopify is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in presenting our
website as reliably as possible. If corresponding consent has been requested, processing is carried out
exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes
the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within
the meaning of the TDDDG. Consent can be revoked at any time. If your data is required for the fulfillment of a
contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6
para. 1 lit. b GDPR. Furthermore, we process your data, if it is necessary for the fulfillment of a legal obligation,
on the basis of Art. 6 para. 1 lit. c GDPR. Data processing can also be carried out on the basis of our legitimate
interest according to Art. 6 para. 1 lit. f GDPR. Information about the respective legal bases applicable in each
individual case can be found in the following paragraphs of this privacy policy.
3. General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal
data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data are data with which you can be
personally identified. This privacy policy explains what data we collect and what we use it for. It also explains
how and for what purpose this happens.
We point out that data transmission over the Internet (e.g. when communicating by e-mail) can have security
gaps. A complete protection of data against access by third parties is not possible.
Information on the Controller
The controller for data processing on this website is:
Pasquariello Willers GbR
4 / 25Telephone: +498941435636
E-mail: info@roccosweinlager.de
The controller is the natural or legal person who alone or jointly with others determines the purposes and means
of processing personal data (e.g., names, e-mail addresses, etc.).
Storage Period
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain
with us until the purpose for data processing ceases to apply. If you assert a legitimate request for erasure or
revoke consent to data processing, your data will be deleted, unless we have other legally permissible reasons
for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will
take place after these reasons cease to exist.
General Information on the Legal Bases for Data Processing on this Website
If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a
GDPR or Art. 9 para. 2 lit. a GDPR, provided that special categories of data according to Art. 9 para. 1 GDPR
are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing
is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or
to access information on your terminal device (e.g. via device fingerprinting), data processing is additionally
carried out on the basis of § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data is necessary
for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on
the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data, if it is necessary for the fulfillment of
a legal obligation, on the basis of Art. 6 para. 1 lit. c GDPR. Data processing can also be carried out on the basis
of our legitimate interest according to Art. 6 para. 1 lit. f GDPR. Information about the respective legal bases
applicable in each individual case can be found in the following paragraphs of this privacy policy.
Recipients of Personal Data
In the course of our business activities, we work with various external bodies. In some cases, it is necessary to
transfer personal data to these external bodies. We only transfer personal data to external bodies if this is
necessary for the fulfillment of a contract, if we are legally obliged to do so (e.g. transfer of data to tax
authorities), if we have a legitimate interest according to Art. 6 para. 1 lit. f GDPR in the transfer, or if another
legal basis permits the data transfer. When using processors, we only transfer personal data of our customers
on the basis of a valid contract for order processing. In the case of joint processing, a contract for joint
processing is concluded.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can revoke consent already
given at any time. The legality of the data processing carried out until the revocation remains unaffected by the
revocation.
Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)
5 / 25WHERE DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT
TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING
FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE
PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN
THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL
DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE
PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING
SERVES THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO
ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE
THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU
FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT
IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL
SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION
PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to Complain to the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have a right to lodge a complaint with a supervisory
authority, in particular in the Member State of their habitual residence, their place of work or the place of the
alleged infringement. The right to lodge a complaint exists irrespective of other administrative or judicial
remedies.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a
contract handed over to you or to a third party in a common, machine-readable format. If you request the direct
transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Information, Rectification, and Erasure
Within the framework of the applicable legal provisions, you have the right to free information at any time about
your stored personal data, its origin and recipient, and the purpose of the data processing and, if applicable, a
right to rectification or erasure of this data. For this and other questions on the subject of personal data, you can
contact us at any time.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any
time for this. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the
duration of the examination, you have the right to request the restriction of the processing of your personal
data.
If the processing of your personal data was/is unlawful, you can request the restriction of data processing
instead of erasure.
If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have
the right to request the restriction of the processing of your personal data instead of erasure.
6 / 25If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balance must be struck between your
interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to
request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, these data – apart from their storage – may only be
processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the
rights of another natural or legal person or for reasons of important public interest of the European Union or a
Member State.
SSL or TLS Encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content,
such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection
by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your
browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted Payment Transactions on this Website
If, after the conclusion of a paid contract, there is an obligation to transmit your payment data (e.g. account
number for direct debit authorization) to us, this data is required for payment processing.
Payment transactions via the common payment methods (Visa/MasterCard, direct debit) are carried out
exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that
the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
With encrypted communication, your payment data that you transmit to us cannot be read by third parties.
4. Data Collection on this Website
Cookies
Our internet pages use so-called "cookies". Cookies are small data packets and do not cause any damage to
your end device. They are stored either temporarily for the duration of a session (session cookies) or
permanently (persistent cookies) on your end device. Session cookies are automatically deleted after your visit.
Persistent cookies remain stored on your end device until you delete them yourself or an automatic deletion is
carried out by your web browser.
Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies).
Third-party cookies enable the integration of certain services from third-party companies within websites (e.g.
cookies for processing payment services).
Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would
not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to
evaluate user behavior or for advertising purposes.
7 / 25Cookies that are required for carrying out the electronic communication process, for providing certain
functions desired by you (e.g., for the shopping cart function) or for optimizing the website (e.g., cookies for
measuring web audience) (necessary cookies) are stored on
stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified.
The website operator has a legitimate interest in the storage of necessary cookies for the
technically error-free and optimized provision of its services. If consent for the
storage of cookies and comparable recognition technologies has been requested, processing takes place
exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1
TDDDG); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and
only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally
and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated,
the functionality of this website may be limited.
Which cookies and services are used on this website can be found in this
privacy policy.
GDPR Legal Cookie by Shopify
Our website uses GDPR Legal Cookie by Shopify to obtain your consent for the storage of certain
cookies on your device or for the use of certain technologies and to document this
in compliance with data protection regulations. The provider of this technology is beeclever GmbH, Friedrich-
Mohr-Straße 1, 56070 Koblenz (hereinafter "beeclever").
When you enter our website, a connection is established to the servers of the provider beeclever.
In this way, the provider beeclever receives personal data, such as the
browser used, the IP address and a timestamp. A cookie is then stored in your
browser in order to be able to assign the given consents or their revocation to you. The data collected in this way
is stored until you request us to delete it, delete the cookie yourself or
the purpose for data storage no longer applies. Mandatory legal retention periods remain
unaffected. You can find details under:
https://apps.shopify.com/gdpr-legal-cookie.
The use of GDPR Legal Cookie by Shopify takes place in order to obtain the legally required consents
for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.
Use of Artificial Intelligence (AI) to answer customer inquiries
We use AI-powered software to process and answer customer inquiries. The AI used by us analyzes the content of your message to autonomously or partially autonomously generate a suitable answer or a suggested answer. In this context, our AI processes all content of your message, including names, email addresses, communication content or technical information (e.g., IP addresses, device information).
The use of the AI software employed is based on Art. 6 para. 1 lit. f GDPR. We
have a legitimate interest in the most efficient customer communication possible using
modern technical solutions.
We use the following AI applications:
ChatGPT
We use ChatGPT for our customer communication. The provider is OpenAI, 3180 18th St, San
Francisco, CA 94110, USA,
8 / 25https://openai.com. So if you contact us, your inquiries including metadata can be transferred to
the ChatGPT servers and processed there to generate a suitable answer.
We have set ChatGPT so that the data we transmit to ChatGPT is not used to
train the ChatGPT algorithm.
Further information can be found here:
https://openai.com/policies/privacy-policy.
Inquiry by e-mail, telephone or fax
If you contact us by e-mail, telephone or fax, your inquiry including all personal data resulting from it (name, inquiry) will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, insofar as your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be revoked at any time.
The data you send us via contact inquiries will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions - in particular legal retention periods - remain unaffected.
Registration on this website
You can register on this website to use additional functions on the site. We use the data entered for this purpose only for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration.
For important changes, for example, to the scope of the offer or to technically necessary changes, we use the e-mail address provided during registration to inform you in this way.
The processing of the data entered during registration is carried out for the purpose of carrying out the user relationship established by the registration and, if applicable, for initiating further contracts (Art. 6 para. 1 lit. b GDPR).
The data collected during registration will be stored by us as long as you are registered on this website and will then be deleted. Legal retention periods remain unaffected.
Registration with Facebook Connect
Instead of direct registration on this website, you can register with Facebook Connect.
The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the collected data is also transferred to the USA and other third countries.
If you choose to register with Facebook Connect and click on the "Login with
Facebook" / "Connect with Facebook" button, you will be automatically redirected to the Facebook platform.
There you can log in with your user data. This will link your
9 / 25Facebook profile to this website or our services. Through this link, we gain access to your data stored on Facebook. These are mainly:
Facebook name
Facebook profile and cover picture
Facebook cover picture
E-mail address stored on Facebook
Facebook ID
Facebook friend lists
Facebook Likes
Birthday
Gender
Country
Language
This data is used to set up, provide and personalize your account.
Registration with Facebook Connect and the associated data processing operations are based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time with effect for the future.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing carried out by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been laid down in an agreement on joint processing. The wording of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook tool and for the data protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g., requests for information) with regard to data processed on Facebook can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://de-de.facebook.com/help/566994660333381 and
https://www.facebook.com/policy.php.
Further information can be found in the Facebook Terms of Use and the Facebook
Privacy Policy. These can be found at:
https://de-de.facebook.com/about/privacy/ and
https://de-de.facebook.com/legal/terms/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452.
Registration with Google
10 / 25Instead of registering directly on this website, you can register with Google. The provider of this service is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
To register with Google, you only need to enter your Google name and password. Google will identify you and confirm your identity to our website.
If you log in with Google, we may be able to use certain information from your account to complete your profile with us. You decide whether and which information this is within your Google security settings, which you can find here:
https://myaccount.google.com/security and
https://myaccount.google.com/permissions.
The data processing associated with Google registration is based on our legitimate interest in enabling our users to have the simplest possible registration process (Art. 6 (1) lit. f GDPR). Since the use of the registration function is voluntary and users can decide for themselves about the respective access options, no overriding rights of the data subjects are apparent.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
5. Social Media
Elements of the social network Facebook are integrated on this website. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. However, according to Facebook, the collected data is also transferred to the USA and other third countries.
An overview of the Facebook social media elements can be found here:
https://developers.facebook.com/docs/plugins/?locale=de_DE.
When the social media element is active, a direct connection is established between your device and the Facebook server. Facebook thereby receives the information that you have visited this website with your IP address. If you click the Facebook "Like" button while logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to associate your visit to this website with your user account. We point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Facebook. Further information can be found in Facebook's privacy policy at:
https://de-de.facebook.com/privacy/explanation.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and §
25 para. 1 TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing carried out by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been laid down in an agreement on joint processing. The wording of the agreement can be found at:
11 / 25The obligations we jointly undertake have been laid down in an agreement on joint processing. You can find the wording of the agreement at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for implementing the tool on our website in a data protection-compliant manner. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g., requests for information) regarding data processed on Facebook can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://de-de.facebook.com/help/566994660333381 and
https://www.facebook.com/policy.php.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452.
Functions of the Instagram service are integrated on this website. These functions are
offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and the
Instagram server. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. We point out that, as the provider of the pages, we have no
information on the content of the data transmitted and its use by Instagram.
The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and §
25 para. 1 TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to
Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand
Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing
responsible (Art. 26 GDPR). The joint responsibility is limited exclusively
to the collection of data and its transfer to Facebook or Instagram. The processing after the transfer
processing by Facebook or Instagram is not part of the joint responsibility.
The obligations incumbent on us jointly have been set out in a joint processing agreement.
processing agreement. The wording of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing
the data protection information when using the Facebook or Instagram tool and for the
data protection compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook and Instagram products. Data subject rights
(e.g. requests for information) regarding data processed by Facebook or Instagram can be asserted directly with Facebook. If you assert your data subject rights with us, we are obliged to forward them to Facebook.
obliged to forward them to Facebook.
12 / 25The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://privacycenter.instagram.com/policy/ and
https://de-de.facebook.com/help/566994660333381.
Further information on this can be found in Instagram's privacy policy:
https://privacycenter.instagram.com/policy/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:
European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider under the following link:
https://www.dataprivacyframework.gov/participant/4452.
6. Analysis tools and advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow
Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other
technologies on our website. Google Tag Manager itself does not create user profiles,
does not store cookies and does not perform independent analyses. It is only used to
manage and play out the tools integrated via it. However, Google Tag Manager collects
your IP address, which can also be transmitted to Google's parent company in the United States.
can be transmitted.
The Google Tag Manager is used on the basis of Art. 6 para. 1 lit. f GDPR. The
website operator has a legitimate interest in the quick and uncomplicated integration and
management of various tools on its website. If a corresponding consent has been requested,
the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1
TDDDG, insofar as the consent includes the storage of cookies or access to information in the
user's end device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be
revoked at any time.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:
European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider under the following link:
https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland
Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors.
The website operator receives various usage data, such as page views, dwell time,
operating systems used and origin of the user. This data is aggregated in a user ID
and assigned to the respective end device of the website visitor.
13 / 25Furthermore, with Google Analytics we can record, among other things, your mouse and scroll movements and clicks.
record. Google Analytics also uses various modeling approaches to supplement the collected
data sets and uses machine learning technologies for data analysis.
Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior
user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the USA and stored there.
information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there.
The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and §
25 para. 1 TDDDG. Consent can be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:
European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider under the following link:
https://www.dataprivacyframework.gov/participant/5780.
IP anonymization
Google Analytics IP anonymization is activated. This means that your IP address will be shortened by Google within
of member states of the European Union or in other contracting states of the Agreement on the
European Economic Area before being transmitted to the USA. Only in exceptional cases will the
full IP address is transmitted to a Google server in the USA and shortened there. On behalf of the
operator of this website, Google will use this information to evaluate your use of the website,
to compile reports on website activities and to provide other services related to website use and internet use to the website operator.
to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
merged with other data from Google.
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available under the following link:
following link:
https://tools.google.com/dlpage/gaoptout?hl=de.
More information on how Google Analytics handles user data can be found in the
Google's privacy policy:
https://support.google.com/analytics/answer/6004245?hl=de.
Google Signals
We use Google Signals. When you visit our website, Google Analytics collects, among other things, your
location, search history and YouTube history as well as demographic data (visitor data). This data
can be used for personalized advertising with the help of Google Signals. If you have a
Google account, the visitor data from Google Signals will be linked to your Google account
and used for personalized advertising messages. The data is also used to create
anonymized statistics on the user behavior of our users.
Google Analytics E-commerce Measurement
14 / 25This website uses the "e-commerce measurement" function of Google Analytics. With the help of e-commerce
measurement, the website operator can analyze the purchasing behavior of website visitors to improve their
online marketing campaigns. Information such as orders placed, average order values, shipping costs and the time from viewing to purchasing a product are recorded.
average order values, shipping costs and the time from viewing to purchasing
a product are recorded. This data can be aggregated by Google under a transaction ID
that is assigned to the respective user or their device.
Hotjar
This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit
Street, St Julians STJ 1000, Malta, Europe (Website:
https://www.hotjar.com).
Hotjar is a tool for analyzing your user behavior on this website. With Hotjar, we can, among other things,
record your mouse and scroll movements and clicks. Hotjar can also determine how long you
remained with the mouse pointer at a certain position. From this information, Hotjar creates
so-called heatmaps, which can be used to determine which areas of the website are preferred by website visitors.
preferred by the website visitor.
Furthermore, we can determine how long you remained on a page and when you left it.
You left. We can also determine at which point you stopped entering information into a contact form
have broken off (so-called conversion funnels).
In addition, direct feedback from website visitors can be obtained with Hotjar. This
function serves to improve the website operator's web offerings.
Hotjar uses technologies that enable the recognition of the user for the purpose of analyzing the
user behavior (e.g. cookies or use of device fingerprinting).
If consent has been obtained, the aforementioned service is used exclusively on the
basis of Art. 6 para. 1 lit. a GDPR and § 25 TDDDG. Consent can be revoked at any time. If
no consent has been obtained, this service is used on the basis of Art. 6 para. 1
lit. f GDPR; the website operator has a legitimate interest in analyzing user behavior in order to
optimize both its website and its advertising.
Disabling Hotjar
If you wish to deactivate data collection by Hotjar, click on the following link and follow the instructions there:
the instructions there:
https://www.hotjar.com/policies/do-not-track/
Please note that Hotjar must be deactivated separately for each browser and each end device.
must be deactivated separately.
Further information about Hotjar and the data collected can be found in the privacy policy
of Hotjar under the following link:
https://www.hotjar.com/privacy
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program of Google
Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads allows us to display advertisements in the Google search engine or on third-party websites
15 / 25when the user enters certain search terms in Google (keyword targeting). Furthermore,
targeted advertisements can be displayed based on user data available to Google (e.g.
location data and interests) (audience targeting). As website operators,
we can quantitatively evaluate this data by, for example, analyzing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.
led to the display of our advertisements and how many advertisements led to corresponding clicks.
led to corresponding clicks.
The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a DSGVO and §
25 para. 1 TDDDG. Consent can be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://policies.google.com/privacy/frameworks and
https://business.safety.google/controllerterms/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:
European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider under the following link:
https://www.dataprivacyframework.gov/participant/5780.
Google Ads Remarketing
This website uses the functions of Google Ads Remarketing. The provider is Google Ireland Limited
("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With Google Ads Remarketing, we can assign people who interact with our online offering to
specific target groups in order to then display interest-based advertising in the Google
advertising network (remarketing or retargeting).
Furthermore, the advertising target groups created with Google Ads Remarketing can be linked with the
cross-device functions of Google. In this way,
interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and browsing behavior on one end device (e.g. mobile phone) can also be displayed on another of your end devices (e.g. tablet or PC).
browsing behavior on one end device (e.g. mobile phone) can also be displayed on another of your
end devices (e.g. tablet or PC).
If you have a Google account, you can object to personalized advertising under the following
link:
https://adssettings.google.com/anonymous?hl=de.
The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a DSGVO and §
25 para. 1 TDDDG. Consent can be revoked at any time.
Further information and the data protection provisions can be found in Google's privacy policy
at:
https://policies.google.com/technologies/ads?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:
European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider under the following link:
https://www.dataprivacyframework.gov/participant/5780.
16 / 25Target group formation with customer matching
For target group formation, we use, among other things, Google Ads Remarketing's customer matching.
Here, we transfer certain customer data (e.g. email addresses) from our customer lists to
Google. If the customers concerned are Google users and logged into their Google account, they will be shown relevant advertising messages within the Google network (e.g. on YouTube, Gmail or in the search engine).
appropriate advertising messages within the Google network (e.g. on YouTube, Gmail or in the
search engine).
Google Conversion Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon
House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, Google and we can recognize whether the user has performed certain
actions. For example, we can evaluate how often certain buttons on our website
were clicked and which products were viewed or purchased most frequently. These
Information is used to create conversion statistics. We learn the total number of users
who clicked on our ads and what actions they performed. We do not receive
information that can personally identify the user. Google itself uses cookies or similar recognition technologies for identification.
The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and §
25 Para. 1 TDDDG. Consent can be revoked at any time.
More information on Google Conversion Tracking can be found in Google's privacy policy:
https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with
European data protection standards for data processing in the USA. Every company certified under the
DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
Meta Pixel (formerly Facebook Pixel)
This website uses the visitor action pixel from Meta for conversion measurement. The provider of this
service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Meta, the collected data
is also transferred to the USA and other third countries.
This allows the behavior of website visitors to be tracked after they have been redirected to the provider's website by clicking on a Meta ad.
This allows the effectiveness of Meta ads to be evaluated for statistical and market research purposes and future
advertising measures to be optimized.
The collected data is anonymous for us as the operator of this website; we cannot draw conclusions about the identity of the users.
However, the data is stored and processed by Meta, so a connection to the respective user profile on Facebook or Instagram is possible, and Meta can use the data for its own advertising purposes, in accordance with the Meta Data Usage Policy (
https://de-de.facebook.com/about/privacy/). This allows Meta to enable the display of advertisements on Facebook or Instagram pages and other advertising channels.
This use of the data cannot be influenced by us as the website operator.
The use of this service is based on your consent pursuant to Art. 6 Para. 1 lit. a GDPR and §
17 / 2525 Para. 1 TDDDG. Consent can be revoked at any time.
We use the enhanced matching function within the Meta pixel.
Enhanced matching allows us to transmit various types of data (e.g., place of residence, federal state, postal code, hashed email addresses, names, gender, date of birth, or telephone number) of our customers and interested parties, which we collect via our website, to Meta.
This enables us to tailor our advertising campaigns on Facebook and Instagram even more precisely to people who are interested in our offers.
In addition, enhanced matching improves the attribution of website conversions and expands Custom Audiences.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR).
Joint responsibility is limited exclusively to the collection of data and its transfer to Meta.
The processing carried out by Meta after the transfer is not part of the joint responsibility. The obligations jointly incumbent upon us have been laid down in an agreement on joint processing.
The text of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Meta tool and for the data protection compliant implementation of the tool on our website.
Meta is responsible for the data security of Meta products. Data subject rights (e.g., requests for information) regarding data processed on Facebook or Instagram can be asserted directly with Meta.
If you assert data subject rights with us, we are obliged to forward them to Meta.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum and
https://de-de.facebook.com/help/566994660333381.
Further information on privacy at Meta can be found in their privacy policy:
https://de-de.facebook.com/about/privacy/.
You can also deactivate the "Custom Audiences" remarketing function in the ad settings section at
https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this,
you must be logged in to Facebook.
If you do not have a Facebook or Instagram account, you can disable usage-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance:
http://www.youronlinechoices.com/de/praferenzmanagement/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with
European data protection standards for data processing in the USA. Every company certified under the
DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452.
Meta Conversion API
We have integrated the Meta Conversion API on this website. The provider of this service is Meta
Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Meta, the data collected is also transferred to the USA and other third countries.
18 / 25The Meta Conversion API enables us to record the website visitor's interactions with our website
and transmit them to Meta to improve advertising performance on Facebook and Instagram.
In particular, the time of access, the accessed website, your IP address and user agent, and, if applicable, other specific data (e.g., purchased products, shopping cart value, and currency) are collected.
A complete overview of the data that can be collected can be found here:
https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.
The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and §
25 Para. 1 TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR).
Joint responsibility is limited exclusively to the collection of data and its transfer to Meta.
The processing carried out by Meta after the transfer is not part of the joint responsibility. The obligations jointly incumbent upon us have been laid down in an agreement on joint processing.
The text of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Meta tool and for the data protection compliant implementation of the tool on our website.
Meta is responsible for the data security of Meta products. Data subject rights (e.g., requests for information) regarding data processed on Facebook or Instagram can be asserted directly with Meta.
If you assert data subject rights with us, we are obliged to forward them to Meta.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum and
https://de-de.facebook.com/help/566994660333381.
Further information on privacy at Meta can be found in their privacy policy:
https://de-de.facebook.com/about/privacy/.
You can also deactivate the "Custom Audiences" remarketing function in the ad settings section at
https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this,
you must be logged in to Facebook.
If you do not have a Facebook or Instagram account, you can disable usage-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance:
http://www.youronlinechoices.com/de/praferenzmanagement/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with
European data protection standards for data processing in the USA. Every company certified under the
DPF undertakes to comply with these data protection standards. Further
information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452.
Order processing
We have concluded a contract for order processing (AVV) for the use of the above-mentioned service.
This is a contract required by data protection law that ensures that personal data of our website visitors is processed only according to our instructions and in compliance with the GDPR.
19 / 25ensures that it processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
7. Newsletter
Newsletter data
If you would like to receive the newsletter offered on the website, we require an e-mail address from you and information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter.
Other data is not collected or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The processing of the data entered in the newsletter registration form takes place exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR).
You can revoke the consent given for storing the data, the e-mail address and its use for sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.
The data you have provided for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after unsubscribing or when the purpose ceases to apply.
We reserve the right to delete or block e-mail addresses from our newsletter distribution list at our own discretion within the framework of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Data stored by us for other purposes remains unaffected by this.
After you unsubscribe from the newsletter distribution list, your e-mail address may be stored in a blacklist by us or the newsletter service provider, if this is necessary to prevent future mailings.
The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR).
Storage in the blacklist is not time-limited. You can object to the storage if your interests outweigh our legitimate interest.
Newsletter dispatch to existing customers
If you order goods or services from us and provide your e-mail address, this e-mail address may subsequently be used by us for sending newsletters, provided we inform you about this beforehand.
In such a case, the newsletter will only be used for direct advertising for our own similar goods or services. You can cancel the sending of this newsletter at any time. For this purpose, there is a corresponding link in every newsletter.
The legal basis for sending the newsletter in this case is Art. 6 Para. 1 lit. f GDPR in conjunction with Section 7 Para. 3 UWG.
After you unsubscribe from the newsletter distribution list, your e-mail address may be stored in a blacklist by us to prevent future mailings to you.
The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR).
Storage in the blacklist is not time-limited. You can object to the storage if your interests outweigh our legitimate interest.
20 / 258. Plugins and Tools
YouTube with extended data protection
This website integrates videos from the YouTube website. The operator of the website is Google Ireland Limited
("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit one of these websites where YouTube is embedded, a connection to the YouTube servers is established.
The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you allow YouTube to directly associate your surfing behavior with your personal profile.
You can prevent this by logging out of your YouTube account.
We use YouTube in extended data protection mode. Videos played in extended data protection mode are not used by YouTube to personalize browsing on YouTube.
Advertisements displayed in extended data protection mode are also not personalized. No cookies are set in extended data protection mode.
Instead, however, so-called local storage elements are stored in the user's browser, which, similar to cookies, contain personal data and can be used for recognition. Details on the extended data protection mode can be found here:
https://support.google.com/youtube/answer/171780.
After activating a YouTube video, further data processing operations may be triggered, over which we have no influence.
The use of YouTube is in the interest of an appealing presentation of our online offers.
This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. If corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 Para. 1 lit. a
GDPR and § 25 Para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG.
Consent can be revoked at any time.
Further information on data protection at YouTube can be found in their privacy policy at:
https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which aims to ensure compliance with
European data protection standards for data processing in the USA. Every company certified under the
DPF commits to adhering to these data protection standards. Further information can be obtained from the
provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
9. E-commerce and Payment Providers
Processing of Customer and Contract Data
We collect, process, and use personal customer and contract data for the establishment,
contentual design, and modification of our contractual relationships. We collect, process, and use personal
data about the use of this website (usage data) only to the extent necessary to enable the user to use the
service or to bill for it. The legal basis for this is Art. 6 para. 1 lit. b GDPR.
The collected customer data will be deleted after the order is completed or the business relationship ends
and any existing legal retention periods expire.
21 / 25Legal retention periods remain unaffected.
Data transfer upon conclusion of contract for online shops, merchants and goods dispatch
When you order goods from us, we pass on your personal data to the transport company responsible for
delivery and to the payment service provider commissioned with payment processing. Only such data is
disclosed as the respective service provider requires for the performance of its task. The legal basis for this
is Art. 6 Para. 1 lit. b GDPR, which permits the processing of data for the fulfilment of a contract or pre-
contractual measures. If you have given corresponding consent in accordance with Art. 6 Para. 1 lit. a
GDPR, we will pass on your e-mail address to the transport company entrusted with the delivery so that it
can inform you by e-mail about the shipping status of your order; you can revoke your consent at any time.
Payment services
We integrate payment services from third-party companies on our website. If you make a purchase from us,
your payment data (e.g., name, payment amount, bank details, credit card number) will be processed by
the payment service provider for the purpose of payment processing. The respective contractual and data
protection provisions of the respective providers apply to these transactions. The use of payment service
providers is based on Art. 6 Para. 1 lit. b GDPR (contract processing) and in the interest of a smooth,
convenient, and secure payment process (Art. 6 Para. 1 lit. f GDPR). Insofar as your consent is requested for
certain actions, Art. 6 Para. 1 lit. a GDPR is the legal basis for data processing; consent can be revoked at
any time for the future.
We use the following payment services/payment service providers on this website:
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-
2449 Luxembourg (hereinafter "PayPal").
Data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
For details, please refer to PayPal's privacy policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Apple Pay
The provider of the payment service is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple's privacy
policy can be found at:
https://www.apple.com/legal/privacy/de-ww/.
Google Pay
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy
policy can be found here:
https://policies.google.com/privacy.
Stripe
The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand
Canal Dock, Dublin, Ireland (hereinafter "Stripe").
22 / 25Data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://stripe.com/de/privacy and
https://stripe.com/de/guides/general-data-protection-regulation.
Further details can be found in Stripe's privacy policy at the following link:
https://stripe.com/de/privacy.
Klarna
The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers
various payment options (e.g., installment purchase). If you choose to pay with Klarna (Klarna checkout
solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the
Klarna checkout solution. Details on the use of Klarna cookies can be found at the following link:
https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
Further details can be found in Klarna's privacy policy at the following link:
https://www.klarna.com/de/datenschutz/.
Paydirekt
The provider of this payment service is Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main,
Germany (hereinafter "Paydirekt"). If you make a payment using Paydirekt, Paydirekt collects various
transaction data and forwards it to the bank with which you are registered for Paydirekt. In addition to the
data required for payment, Paydirekt may collect further data as part of the transaction processing, such as
the delivery address or individual items in the shopping cart. Paydirekt then authenticates the transaction
using the authentication procedure stored for this purpose at the bank. Subsequently, the payment amount is
transferred from your account to our account. Neither we nor third parties have access to your account data.
Details on payment with Paydirekt can be found in the general terms and conditions and the data protection
provisions of Paydirekt at:
https://www.paydirekt.de/agb/index.html.
Sofortüberweisung (Instant Transfer)
The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter "Sofort
GmbH"). With the "Sofortüberweisung" procedure, we receive a payment confirmation from Sofort GmbH in
real time and can immediately begin fulfilling our obligations. If you have chosen the payment method
"Sofortüberweisung," you transmit the PIN and a valid TAN to Sofort GmbH, with which it can log into your
online banking account. After logging in, Sofort GmbH automatically checks your account balance and carries
out the transfer to us using the TAN you provided. It then immediately transmits a transaction confirmation to
us. After logging in, your transactions, the credit limit of the overdraft facility, and the existence of other
accounts and their balances are also automatically checked. In addition to the PIN and TAN, the payment
data you entered and data about your person are also transmitted to Sofort GmbH. The data about your
person includes your first and last name, address, telephone number(s), e-mail address, IP address, and, if
applicable, other data required for payment processing. The transmission of this data is necessary to clearly
establish your identity and to prevent fraud attempts. Details on payment with Sofortüberweisung can be found
at the following link:
https://www.klarna.com/sofort/.
Shopify Payment
The provider of this payment service in the EU is Shopify International Limited, 2nd Floor Victoria
23 / 25Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter "Shopify Payment").
For details, please refer to Shopify Payment's privacy policy:
https://www.shopify.de/legal/datenschutz.
American Express
The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486
Frankfurt am Main, Germany (hereinafter "American Express").
American Express may transmit data to its parent company in the USA. Data transfer to the USA is based on
Binding Corporate Rules. Details can be found here:
https://www.americanexpress.com/en-cz/company/legal/privacy-centre/binding-corporate-rules/.
Further information can be found in American Express's privacy policy:
https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410
Waterloo, Belgium (hereinafter "Mastercard").
Mastercard may transfer data to its parent company in the USA. The data transfer to the USA is based on
Mastercard's Binding Corporate Rules. Details can be found here:
https://www.mastercard.de/de-de/datenschutz.html and
https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
VISA
The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London
W2 6TT, Great Britain (hereinafter "VISA").
Great Britain is considered a secure third country under data protection law. This means that Great Britain
has a level of data protection that corresponds to the level of data protection in the European Union.
VISA may transfer data to its parent company in the USA. The data transfer to the USA is based on the
standard contractual clauses of the EU Commission. Details can be found here:
https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-
zustandigkeitsfragen-fur-den-ewr.html.
Further information can be found in VISA's privacy policy:
https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
Data Protection Rocco's Wine Storage
Privacy Policy
1. Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this
website. Personal data is any data with which you can be personally identified. Detailed information on the
subject of data protection can be found in our privacy policy listed below this text.
Data collection on this website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. Their contact details can be found
in the "Information on the responsible body" section of this privacy policy.
How do we collect your data?
Your data is collected, on the one hand, by you providing it to us. This can be, for example, data that you
enter into a contact form.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This
is primarily technical data (e.g., internet browser, operating system, or time of page view). This data is
collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the website is provided without errors. Other data may be used to
analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data
will also be processed for contract offers, orders, or other order inquiries.
What rights do you have regarding your data?
You have the right at any time to receive free information about the origin, recipient, and purpose of your
stored personal data. You also have the right to request the correction or deletion of this data. If you have
given consent to data processing, you can revoke this consent at any time for the future. You also have the
right, under certain circumstances, to request the restriction of the processing of your personal data. Further,
you have a right to complain to the competent supervisory authority.
For this purpose, as well as for further questions on the subject of data protection, you can contact us at any
time.
Analysis tools and third-party tools
When visiting this website, your surfing behavior can be statistically evaluated. This is mainly done with so-
called analysis programs.
3 / 18Detailed information on these analysis programs can be found in the following
data protection declaration.
2. Hosting
We host the content of our website with the following provider:
Shopify
The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32,
Ireland (hereinafter "Shopify").
Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP
address and information about the device and browser you are using. Shopify also analyzes visitor numbers,
visitor sources, and customer behavior, and creates user statistics. If you make a purchase on our website,
Shopify also collects your name, email address, delivery and billing addresses, payment data, and other data
related to the purchase (e.g., phone number, sales volume, etc.). Shopify stores cookies in your browser for
analysis purposes.
Further details can be found in Shopify's privacy policy:
https://www.shopify.de/legal/datenschutz.
The use of Shopify is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in presenting our
website as reliably as possible. If corresponding consent has been requested, processing is exclusively based
on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies
or access to information in the user's end device (e.g., device fingerprinting) within the meaning of the
TDDDG. Consent can be revoked at any time.
3. General information and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal
data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected.
Personal data is data with which you can be personally identified. This privacy policy explains what data we
collect and what we use it for. It also explains how and for what purpose this happens.
We point out that data transmission on the Internet (e.g., when communicating by e-mail) can have security
gaps. Complete protection of data from access by third parties is not possible.
Information on the responsible body
The responsible body for data processing on this website is:
Rocco Pasquariello
4 / 18Handorfer Straße 21
48157 Münster
Phone: 0251-32256028
Email: roccosweinlager@freenet.de
The responsible body is the natural or legal person who alone or jointly with others decides on the purposes
and means of processing personal data (e.g. names, email addresses, etc.).
Storage duration
Unless a more specific storage period has been mentioned within this privacy policy, personal data will remain
your personal data with us until the purpose for data processing no longer applies. If you submit a
legitimate request for erasure or withdraw consent for data processing, your data will be erased, unless we have
other legally permissible reasons for storing your personal data (e.g., retention periods under tax or commercial law); in
the latter case, erasure will occur after these reasons cease to apply.
General information on the legal basis for data processing on this
Website
If you have given your consent to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, provided that special categories of data
according to Art. 9 para. 1 GDPR are processed. In the event of explicit consent to the transfer of
personal data to third countries, data processing also takes place on the basis of Art.
49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or to access to information on
your terminal device (e.g. via device fingerprinting), data processing will also take place
on the basis of § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data is required for
the fulfillment of a contract or for the implementation of pre-contractual measures, we process your
data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if it is
necessary for compliance with a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR.
Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f
GDPR. Information on the respective legal bases applicable in individual cases will be provided in the following
paragraphs of this privacy policy.
Recipients of personal data
In the course of our business activities, we cooperate with various external bodies. In some cases,
this also requires the transfer of personal data to these external bodies.
We only pass on personal data to external bodies if this is necessary for the fulfillment of a contract,
if we are legally obliged to do so (e.g. transfer of data to tax authorities), if we have a legitimate interest
pursuant to Art. 6 para. 1 lit. f GDPR in the transfer or if another legal basis permits the transfer of data.
When using processors, we only pass on personal data of our customers on the basis of a valid
contract for order processing. In the case of joint processing, a contract for joint processing is concluded.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent that has already been given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
5 / 18Right to object to data collection in special cases and to
direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR,
YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR
SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA;
THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS.
THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT,
WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS
WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING
WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE
PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION ACCORDING TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES,
YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR
PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING;
THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT,
YOUR PERSONAL DATA WILL NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION
ACCORDING TO ART. 21 PARA. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, affected persons have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint exists irrespective of other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place if it is technically feasible.
Information, rectification and erasure
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, their origin and recipient and the purpose of the data processing and, if applicable, a right to rectification or erasure of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
If the processing of your personal data was/is unlawful, you can demand the restriction of data processing instead of erasure.
6 / 18If we no longer need your personal data, but you need it for the exercise, defense or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data – apart from its storage – may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Data collection on this website
Cookies
Our website uses so-called "cookies". Cookies are small data packets and do not cause any damage to your end device. They are stored on your end device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or an automatic deletion occurs by your web browser.
Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g. cookies for processing payment services).
Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.
Cookies that are necessary for carrying out the electronic communication process, for providing certain functions desired by you (e.g. for the shopping cart function) or for optimizing the website (e.g. cookies for measuring web audience) (necessary cookies) are stored on the basis of Art. 6 Para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent for the storage of cookies and comparable recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG); consent can be revoked at any time.
7 / 18You can configure your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.
You can find out which cookies and services are used on this website in this privacy policy.
Consent with Usercentrics
This website uses Usercentrics' consent technology to obtain your consent to the storage of certain cookies on your terminal device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Website:
https://usercentrics.com/de/ (hereinafter "Usercentrics").
When you enter our website, the following personal data is transferred to Usercentrics:
Your consent(s) or the revocation of your consent(s)
Your IP address
Information about your browser
Information about your terminal device
Time of your visit to the website
Geolocation
Furthermore, Usercentrics stores a cookie in your browser in order to be able to assign the consents given or their revocation to you. The data collected in this way is stored until you request us to delete it, delete the Usercentrics cookie yourself or the purpose for data storage ceases to apply. Mandatory legal retention periods remain unaffected.
Usercentrics is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.
GDPR Legal Cookie by Shopify
Our website uses GDPR Legal Cookie by Shopify to obtain your consent to the storage of certain cookies on your terminal device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is beeclever GmbH, Friedrich-Mohr-Straße 1, 56070 Koblenz (hereinafter "beeclever").
When you enter our website, a connection is established to the servers of the provider beeclever. In this way, the provider beeclever receives personal data, such as the browser used, the IP address and a timestamp. A cookie is then stored in your browser in order to be able to assign the consents given or their revocation to you. The data collected in this way is stored until you request us to delete it, delete the cookie yourself or the purpose for data storage ceases to apply. Mandatory legal retention periods remain unaffected. Details can be found at:
https://apps.shopify.com/gdpr-legal-cookie.
The use of GDPR Legal Cookie by Shopify takes place in order to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.
Contact form
8 / 18If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not pass on this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be revoked at any time.
The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to storage or the purpose for data storage ceases to apply (e.g. after your inquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
Use of AI on the Website
We use AI-powered services and/or applications on our website.
We use Artificial Intelligence (AI) on our website as follows:
Phone support by Safina AI
If you interact with or come into contact with elements on our website that use artificial intelligence (e.g. chatbot), your input including metadata will be processed to generate an appropriate answer or response.
The use of these AI-powered functions is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in using modern technologies on our website to improve our services and to identify new potential from interacting with our customers. If consent is required, processing is exclusively based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. You can revoke your consent at any time.
Further information on the data processing of this tool or service can be found in the relevant section of this privacy policy.
Inquiry by e-mail, telephone or fax
If you contact us by e-mail, telephone or fax, your inquiry including all personal data resulting from it (name, inquiry) will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your
consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be
withdrawn at any time.
The data you send to us via contact inquiries will remain with us until you request us to delete it, revoke your
consent to storage, or the purpose for data storage no longer applies (e.g. after your request has been
processed). Mandatory legal provisions – in particular statutory retention periods – remain unaffected.
9 / 185. Social Media
Elements of the social network Facebook are integrated into this website. The provider of this service is
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. However, according to
Facebook, the collected data is also transferred to the USA and other third countries.
An overview of the Facebook social media elements can be found here:
https://developers.facebook.com/docs/plugins/?locale=de_DE.
When the social media element is active, a direct connection is established between your device and the
Facebook server. Facebook thereby receives the information that you have visited this website with your IP
address. If you click the Facebook "Like" button while logged into your Facebook account, you can link the
content of this website to your Facebook profile. This allows Facebook to associate your visit to this website
with your user account. We point out that as the provider of the pages, we have no knowledge of the content
of the transmitted data or its use by Facebook. Further information can be found in Facebook's privacy
policy at:
https://de-de.facebook.com/privacy/explanation.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1
TDDDG. Consent can be withdrawn at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to
Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2,
Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited
exclusively to the collection of data and its transfer to Facebook. The processing carried out by Facebook
after the transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been laid
down in an agreement on joint processing. The wording of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for
providing data protection information when using the Facebook tool and for the data protection-compliant
implementation of the tool on our website. Facebook is responsible for the data security of Facebook
products. Data subject rights (e.g., requests for information) regarding data processed by Facebook can be
asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to
Facebook.
Data transfer to the USA is based on the EU Commission's standard contractual clauses.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://de-de.facebook.com/help/566994660333381 and
https://www.facebook.com/policy.php.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement
between the European Union and the USA, which aims to ensure compliance with European data protection
standards when processing data in the USA. Every company certified under the DPF undertakes to comply
with these data protection standards. Further information on this can be obtained from the provider at the
following link:
https://www.dataprivacyframework.gov/participant/4452.
10 / 18Functions of the Instagram service are integrated into this website. These functions are offered by Meta
Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and the
Instagram server. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile
by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user
account. We point out that as the provider of the pages, we have no knowledge of the content of the transmitted
data or its use by Instagram.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1
TDDDG. Consent can be withdrawn at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to
Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour,
Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is
limited exclusively to the collection of data and its transfer to Facebook or Instagram. The processing carried
out by Facebook or Instagram after the transfer is not part of the joint responsibility. The obligations incumbent
on us jointly have been laid down in an agreement on joint processing. The wording of the agreement can be
found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for
providing data protection information when using the Facebook or Instagram tool and for the data protection-
compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook
or Instagram products. Data subject rights (e.g., requests for information) regarding data processed by
Facebook or Instagram can be asserted directly with Facebook. If you assert data subject rights with us, we are
obliged to forward them to Facebook.
Data transfer to the USA is based on the EU Commission's standard contractual clauses.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://privacycenter.instagram.com/policy/ and
https://de-de.facebook.com/help/566994660333381.
Further information can be found in Instagram's privacy policy:
https://privacycenter.instagram.com/policy/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement
between the European Union and the USA, which aims to ensure compliance with European data protection
standards when processing data in the USA. Every company certified under the DPF undertakes to comply
with these data protection standards. Further information on this can be obtained from the provider at the
following link:
https://www.dataprivacyframework.gov/participant/4452.
6. Analytics tools and advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4,
Ireland.
11 / 18Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies
into our website. Google Tag Manager itself does not create user profiles, store cookies, or perform its own
analyses. It merely serves to manage and deploy the tools integrated through it. However, Google Tag Manager
collects your IP address, which can also be transferred to Google's parent company in the United States.
The use of Google Tag Manager is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate
interest in quickly and easily integrating and managing various tools on his website. If appropriate consent has
been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para.
1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device
(e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement
between the European Union and the USA, which aims to ensure compliance with European data protection
standards when processing data in the USA. Every company certified under the DPF undertakes to comply
with these data protection standards. Further information on this can be obtained from the provider at the
following link:
https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland
Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics allows the website operator to analyze the behavior of website visitors. The website operator
receives various usage data, such as page views, duration of stay, operating systems used, and the user's
origin. This data is aggregated into a user ID and assigned to the respective device of the website visitor.
Furthermore, with Google Analytics, we can record, among other things, your mouse and scroll movements and
clicks. Google Analytics also uses various modeling approaches to supplement the collected data records and
employs machine learning technologies in data analysis.
Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior
(e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is
usually transmitted to a Google server in the USA and stored there.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1
TDDDG. Consent can be withdrawn at any time.
Data transfer to the USA is based on the EU Commission's standard contractual clauses.
Details can be found here:
https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement
between the European Union and the USA, which aims to ensure compliance with European data protection
standards when processing data in the USA. Every company certified under the DPF undertakes to comply
with these data protection standards. Further information on this can be obtained from the provider at the
following link:
https://www.dataprivacyframework.gov/participant/5780.
12 / 18IP Anonymization
Google Analytics IP anonymization is activated. This means that your IP address will be truncated by Google
within member states of the European Union or in other contracting states of the Agreement on the European
Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be
transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google
will use this information to evaluate your use of the website, to compile reports on website activity and to provide
other services related to website and internet use to the website operator. The IP address transmitted by your
browser as part of Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent Google from collecting and processing your data by downloading and installing the browser
plugin available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=de.
More information on how Google Analytics handles user data can be found in Google's privacy policy:
https://support.google.com/analytics/answer/6004245?hl=de.
Google Signals
We use Google Signals. When you visit our website, Google Analytics collects, among other things, your
location, search history, and YouTube history, as well as demographic data (visitor data). This data can be used
with the help of Google Signals for personalized advertising. If you have a Google account, the visitor data from
Google Signals will be linked to your Google account and used for personalized advertising messages. The data
is also used to create anonymized statistics on the user behavior of our users.
Google Analytics E-commerce Measurement
This website uses the "E-commerce measurement" function of Google Analytics. With the help of e-commerce
measurement, the website operator can analyze the purchasing behavior of website visitors to improve their
online marketing campaigns. This involves collecting information such as orders placed, average order values,
shipping costs, and the time from viewing to purchasing a product. This data can be aggregated by Google
under a transaction ID, which is assigned to the respective user or their device.
Hotjar
This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit
Street, St Julians STJ 1000, Malta, Europe (Website:
https://www.hotjar.com).
Hotjar is a tool for analyzing your user behavior on this website. With Hotjar, we can record, among other
things, your mouse and scroll movements and clicks. Hotjar can also determine how long you have remained
with the mouse pointer at a certain position. From this information, Hotjar creates so-called heatmaps, which
can be used to determine which areas of the website are preferred by website visitors.
Furthermore, we can determine how long you have remained on a page and when you left it. We can also
determine where you interrupted your entries in a contact form (so-called conversion funnels).
13 / 18In addition, Hotjar can be used to obtain direct feedback from website visitors. This function serves to improve
the website operator's web offerings.
Hotjar uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies
or the use of device fingerprinting).
Insofar as consent has been obtained, the aforementioned service is used exclusively on the basis of Art. 6
para. 1 lit. a GDPR and § 25 TDDDG. Consent can be withdrawn at any time. Insofar as no consent has been
obtained, this service is used on the basis of Art. 6 para. 1 lit. f GDPR; the website operator has a legitimate
interest in analyzing user behavior to optimize both its web offering and its advertising.
Disabling Hotjar
If you wish to disable data collection by Hotjar, click on the following link and follow the instructions there:
https://www.hotjar.com/policies/do-not-track/
Please note that Hotjar must be deactivated separately for each browser or device.
For more information about Hotjar and the data collected, please refer to the privacy policy
of Hotjar at the following link:
https://www.hotjar.com/privacy
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program of Google
Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads allows us to display advertisements in the Google search engine or on third-party websites
when the user enters specific search terms into Google (keyword targeting). Furthermore,
targeted advertisements can be displayed based on user data available to Google (e.g.,
location data and interests) (audience targeting). As website operators,
we can evaluate this data quantitatively, for example, by analyzing which search terms led to the display
of our advertisements and how many advertisements led to corresponding clicks.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and §
25 para. 1 TDDDG. Consent can be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here:
https://policies.google.com/privacy/frameworks and
https://business.safety.google/controllerterms/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which aims to ensure compliance with
European data protection standards for data processing in the USA. Every company certified under
the DPF commits to adhering to these data protection standards. Further
information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
Google Ads Remarketing
14 / 18This website uses the functions of Google Ads Remarketing. The provider is Google Ireland Limited
("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With Google Ads Remarketing, we can assign people who interact with our online offering to
certain target groups, in order to then display interest-based advertising to them in the Google
advertising network (remarketing or retargeting).
Furthermore, the advertising target groups created with Google Ads Remarketing can be linked with the
cross-device functions of Google. In this way,
interest-based, personalized advertising messages, which have been adapted to you depending on your previous usage and
browsing behavior on one device (e.g., mobile phone), can also be displayed on another of your
devices (e.g., tablet or PC).
If you have a Google account, you can object to personalized advertising at the following
link:
https://adssettings.google.com/anonymous?hl=de.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and §
25 para. 1 TDDDG. Consent can be revoked at any time.
Further information and the data protection provisions can be found in Google's privacy policy
at:
https://policies.google.com/technologies/ads?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which aims to ensure compliance with
European data protection standards for data processing in the USA. Every company certified under
the DPF commits to adhering to these data protection standards. Further
information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
Google Conversion Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon
House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, Google and we can recognize whether the user has performed certain
actions. For example, we can evaluate which buttons on our website
were clicked how often and which products were viewed or purchased particularly often. This
information is used to create conversion statistics. We learn the total number of users
who clicked on our ads and what actions they performed. We do not receive any
information that would allow us to personally identify the user. Google itself uses cookies or
comparable recognition technologies for identification.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and §
25 para. 1 TDDDG. Consent can be revoked at any time.
More information on Google Conversion Tracking can be found in Google's privacy policy
at:
https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The
DPF is an agreement between the European Union and the USA, which aims to ensure compliance with
European data protection standards for data processing in the USA. Every company certified under
the DPF commits to adhering to these data protection standards. Further
15 / 18information on this can be obtained from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
7. Newsletter
Newsletter data
If you wish to subscribe to the newsletter offered on the website, we require an e-mail address from you
as well as information that allows us to verify that you are the owner of the
e-mail address provided and that you agree to receive the newsletter. Further
data is not collected or only on a voluntary basis. We use this data exclusively for
sending the requested information and do not pass it on to third parties.
The processing of the data entered into the newsletter registration form is based exclusively on
your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent to the storage of
data, the e-mail address, and its use for sending the newsletter at any time,
for example, via the "unsubscribe" link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the revocation.
The data you have stored with us for the purpose of newsletter subscription will be stored by us until you
unsubscribe from the newsletter with us or the newsletter service provider and will be deleted after
unsubscribing from the newsletter or when the purpose ceases to apply from the newsletter distribution list. We
reserve the right to delete or block e-mail addresses from our newsletter distribution list at our discretion within the scope
of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.
Data stored with us for other purposes remains unaffected by this.
After you unsubscribe from the newsletter distribution list, your e-mail address will be stored with us or the
newsletter service provider, if necessary, in a blacklist, provided this is necessary to prevent future
mailings. The data from the blacklist will only be used for this purpose and will not be combined with
other data. This serves both your interest and our interest in
complying with legal requirements when sending newsletters (legitimate interest within the meaning of
Art. 6 para. 1 lit. f GDPR). Storage in the blacklist is not time-limited. You can object to the
storage if your interests outweigh our legitimate interest.
8. eCommerce and Payment Providers
Processing of customer and contract data
We collect, process, and use personal customer and contract data for the establishment,
content-related design, and amendment of our contractual relationships. We only collect, process, and use personal data about the
use of this website (usage data) insofar as this is
necessary to enable the user to use the service or to bill for it.
The legal basis for this is Art. 6 para. 1 lit. b GDPR.
The collected customer data will be deleted after the completion of the order or the termination of the
business relationship and the expiry of any applicable statutory retention periods.
Statutory retention periods remain unaffected.
Data transfer upon conclusion of contract for online shops, retailers, and shipping of goods
When you order goods from us, we pass on your personal data to the transport company entrusted with the delivery
and to the payment service provider entrusted with payment processing
16 / 18. Only such data is released as the respective service provider requires to fulfill its
task. The legal basis for this is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for
the performance of a contract or pre-contractual measures. If you have given corresponding
consent according to Art. 6 para. 1 lit. a GDPR, we will transfer your e-mail address to the transport company entrusted with the
delivery so that it can inform you by e-mail about the shipping status
of your order; you can revoke your consent at any time.