data protection

 

Privacy Policy Pasquariello Willers GbR

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit

this website. Personal data is any data that can be used to identify you personally. For detailed information

on data protection, please refer to our privacy policy provided below this text.

Data Collection on this Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find their contact details in the

"Information on the Controller" section of this privacy policy.

How do we collect your data?

Your data is collected, on the one hand, by you providing it to us. This may include, for example, data that you

enter into a contact form.

Other data is collected automatically by our IT systems when you visit the website or after you have given your

consent. This mainly concerns technical data (e.g. internet browser, operating system or time of page view).

This data is collected automatically as soon as you enter this website.

What do we use your data for?

Some of the data is collected to ensure the website is provided without errors. Other data can be used to

analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data will

also be processed for contract offers, orders or other order inquiries.

What rights do you have regarding your data?

You have the right to obtain information free of charge at any time about the origin, recipient and purpose of

your stored personal data. You also have the right to request the rectification or erasure of this data. If you have

given consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have

the right to request the restriction of the processing of your personal data under certain circumstances.

Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time regarding this and other questions on the subject of data protection.

Analysis Tools and Third-Party Tools

When visiting this website, your surfing behavior can be statistically evaluated. This is mainly done with so-

called analysis programs.

3 / 25You can find detailed information on these analysis programs in the following privacy policy.

2. Hosting

We host the content of our website with the following provider:

Shopify

The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32,

Ireland (hereinafter “Shopify”).

Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address

and information about the device you are using and your browser. Shopify also analyzes visitor numbers, visitor

sources, and customer behavior and creates user statistics. If you make a purchase on our website, Shopify also

collects your name, email address, shipping and billing addresses, payment data, and other data related to the

purchase (e.g., telephone number, amount of sales made, etc.). For analyses, Shopify stores cookies in your

browser.

For details, please refer to Shopify's privacy policy:

https://www.shopify.de/legal/datenschutz.

The use of Shopify is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in presenting our

website as reliably as possible. If corresponding consent has been requested, processing is carried out

exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes

the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within

the meaning of the TDDDG. Consent can be revoked at any time. If your data is required for the fulfillment of a

contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6

para. 1 lit. b GDPR. Furthermore, we process your data, if it is necessary for the fulfillment of a legal obligation,

on the basis of Art. 6 para. 1 lit. c GDPR. Data processing can also be carried out on the basis of our legitimate

interest according to Art. 6 para. 1 lit. f GDPR. Information about the respective legal bases applicable in each

individual case can be found in the following paragraphs of this privacy policy.

3. General Information and Mandatory Disclosures

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal

data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data are collected. Personal data are data with which you can be

personally identified. This privacy policy explains what data we collect and what we use it for. It also explains

how and for what purpose this happens.

We point out that data transmission over the Internet (e.g. when communicating by e-mail) can have security

gaps. A complete protection of data against access by third parties is not possible.

Information on the Controller

The controller for data processing on this website is:

Pasquariello Willers GbR

4 / 25Telephone: +498941435636

E-mail: info@roccosweinlager.de

The controller is the natural or legal person who alone or jointly with others determines the purposes and means

of processing personal data (e.g., names, e-mail addresses, etc.).

Storage Period

Unless a more specific storage period has been stated within this privacy policy, your personal data will remain

with us until the purpose for data processing ceases to apply. If you assert a legitimate request for erasure or

revoke consent to data processing, your data will be deleted, unless we have other legally permissible reasons

for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will

take place after these reasons cease to exist.

General Information on the Legal Bases for Data Processing on this Website

If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a

GDPR or Art. 9 para. 2 lit. a GDPR, provided that special categories of data according to Art. 9 para. 1 GDPR

are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing

is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or

to access information on your terminal device (e.g. via device fingerprinting), data processing is additionally

carried out on the basis of § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data is necessary

for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on

the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data, if it is necessary for the fulfillment of

a legal obligation, on the basis of Art. 6 para. 1 lit. c GDPR. Data processing can also be carried out on the basis

of our legitimate interest according to Art. 6 para. 1 lit. f GDPR. Information about the respective legal bases

applicable in each individual case can be found in the following paragraphs of this privacy policy.

Recipients of Personal Data

In the course of our business activities, we work with various external bodies. In some cases, it is necessary to

transfer personal data to these external bodies. We only transfer personal data to external bodies if this is

necessary for the fulfillment of a contract, if we are legally obliged to do so (e.g. transfer of data to tax

authorities), if we have a legitimate interest according to Art. 6 para. 1 lit. f GDPR in the transfer, or if another

legal basis permits the data transfer. When using processors, we only transfer personal data of our customers

on the basis of a valid contract for order processing. In the case of joint processing, a contract for joint

processing is concluded.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent already

given at any time. The legality of the data processing carried out until the revocation remains unaffected by the

revocation.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

5 / 25WHERE DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT

TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING

FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE

PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN

THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL

DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE

PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING

SERVES THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO

ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE

THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU

FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT

IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL

SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION

PURSUANT TO ART. 21 PARA. 2 GDPR).

Right to Complain to the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have a right to lodge a complaint with a supervisory

authority, in particular in the Member State of their habitual residence, their place of work or the place of the

alleged infringement. The right to lodge a complaint exists irrespective of other administrative or judicial

remedies.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a

contract handed over to you or to a third party in a common, machine-readable format. If you request the direct

transfer of the data to another controller, this will only be done insofar as it is technically feasible.

Information, Rectification, and Erasure

Within the framework of the applicable legal provisions, you have the right to free information at any time about

your stored personal data, its origin and recipient, and the purpose of the data processing and, if applicable, a

right to rectification or erasure of this data. For this and other questions on the subject of personal data, you can

contact us at any time.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any

time for this. The right to restriction of processing exists in the following cases:

If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the

duration of the examination, you have the right to request the restriction of the processing of your personal

data.

If the processing of your personal data was/is unlawful, you can request the restriction of data processing

instead of erasure.

If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have

the right to request the restriction of the processing of your personal data instead of erasure.

6 / 25If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balance must be struck between your

interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to

request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – apart from their storage – may only be

processed with your consent or for the assertion, exercise or defense of legal claims or for the protection of the

rights of another natural or legal person or for reasons of important public interest of the European Union or a

Member State.

SSL or TLS Encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content,

such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection

by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your

browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Encrypted Payment Transactions on this Website

If, after the conclusion of a paid contract, there is an obligation to transmit your payment data (e.g. account

number for direct debit authorization) to us, this data is required for payment processing.

Payment transactions via the common payment methods (Visa/MasterCard, direct debit) are carried out

exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that

the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

With encrypted communication, your payment data that you transmit to us cannot be read by third parties.

4. Data Collection on this Website

Cookies

Our internet pages use so-called "cookies". Cookies are small data packets and do not cause any damage to

your end device. They are stored either temporarily for the duration of a session (session cookies) or

permanently (persistent cookies) on your end device. Session cookies are automatically deleted after your visit.

Persistent cookies remain stored on your end device until you delete them yourself or an automatic deletion is

carried out by your web browser.

Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies).

Third-party cookies enable the integration of certain services from third-party companies within websites (e.g.

cookies for processing payment services).

Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would

not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to

evaluate user behavior or for advertising purposes.

7 / 25Cookies that are required for carrying out the electronic communication process, for providing certain

functions desired by you (e.g., for the shopping cart function) or for optimizing the website (e.g., cookies for

measuring web audience) (necessary cookies) are stored on

stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified.

The website operator has a legitimate interest in the storage of necessary cookies for the

technically error-free and optimized provision of its services. If consent for the

storage of cookies and comparable recognition technologies has been requested, processing takes place

exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1

TDDDG); consent can be revoked at any time.

You can set your browser so that you are informed about the setting of cookies and

only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally

and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated,

the functionality of this website may be limited.

Which cookies and services are used on this website can be found in this

privacy policy.

GDPR Legal Cookie by Shopify

Our website uses GDPR Legal Cookie by Shopify to obtain your consent for the storage of certain

cookies on your device or for the use of certain technologies and to document this

in compliance with data protection regulations. The provider of this technology is beeclever GmbH, Friedrich-

Mohr-Straße 1, 56070 Koblenz (hereinafter "beeclever").

When you enter our website, a connection is established to the servers of the provider beeclever.

In this way, the provider beeclever receives personal data, such as the

browser used, the IP address and a timestamp. A cookie is then stored in your

browser in order to be able to assign the given consents or their revocation to you. The data collected in this way

is stored until you request us to delete it, delete the cookie yourself or

the purpose for data storage no longer applies. Mandatory legal retention periods remain

unaffected. You can find details under:

https://apps.shopify.com/gdpr-legal-cookie.

The use of GDPR Legal Cookie by Shopify takes place in order to obtain the legally required consents

for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.

Use of Artificial Intelligence (AI) to answer customer inquiries

We use AI-powered software to process and answer customer inquiries. The AI used by us analyzes the content of your message to autonomously or partially autonomously generate a suitable answer or a suggested answer. In this context, our AI processes all content of your message, including names, email addresses, communication content or technical information (e.g., IP addresses, device information).

The use of the AI software employed is based on Art. 6 para. 1 lit. f GDPR. We

have a legitimate interest in the most efficient customer communication possible using

modern technical solutions.

We use the following AI applications:

ChatGPT

We use ChatGPT for our customer communication. The provider is OpenAI, 3180 18th St, San

Francisco, CA 94110, USA,

8 / 25https://openai.com. So if you contact us, your inquiries including metadata can be transferred to

the ChatGPT servers and processed there to generate a suitable answer.

We have set ChatGPT so that the data we transmit to ChatGPT is not used to

train the ChatGPT algorithm.

Further information can be found here:

https://openai.com/policies/privacy-policy.

Inquiry by e-mail, telephone or fax

If you contact us by e-mail, telephone or fax, your inquiry including all personal data resulting from it (name, inquiry) will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent.

The processing of this data is based on Art. 6 para. 1 lit. b GDPR, insofar as your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be revoked at any time.

The data you send us via contact inquiries will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions - in particular legal retention periods - remain unaffected.

Registration on this website

You can register on this website to use additional functions on the site. We use the data entered for this purpose only for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration.

For important changes, for example, to the scope of the offer or to technically necessary changes, we use the e-mail address provided during registration to inform you in this way.

The processing of the data entered during registration is carried out for the purpose of carrying out the user relationship established by the registration and, if applicable, for initiating further contracts (Art. 6 para. 1 lit. b GDPR).

The data collected during registration will be stored by us as long as you are registered on this website and will then be deleted. Legal retention periods remain unaffected.

Registration with Facebook Connect

Instead of direct registration on this website, you can register with Facebook Connect.

The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the collected data is also transferred to the USA and other third countries.

If you choose to register with Facebook Connect and click on the "Login with

Facebook" / "Connect with Facebook" button, you will be automatically redirected to the Facebook platform.

There you can log in with your user data. This will link your

9 / 25Facebook profile to this website or our services. Through this link, we gain access to your data stored on Facebook. These are mainly:

Facebook name

Facebook profile and cover picture

Facebook cover picture

E-mail address stored on Facebook

Facebook ID

Facebook friend lists

Facebook Likes

Birthday

Gender

Country

Language

This data is used to set up, provide and personalize your account.

Registration with Facebook Connect and the associated data processing operations are based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time with effect for the future.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing carried out by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been laid down in an agreement on joint processing. The wording of the agreement can be found at:

https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook tool and for the data protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g., requests for information) with regard to data processed on Facebook can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum,

https://de-de.facebook.com/help/566994660333381 and

https://www.facebook.com/policy.php.

Further information can be found in the Facebook Terms of Use and the Facebook

Privacy Policy. These can be found at:

https://de-de.facebook.com/about/privacy/ and

https://de-de.facebook.com/legal/terms/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/4452.

Registration with Google

10 / 25Instead of registering directly on this website, you can register with Google. The provider of this service is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

To register with Google, you only need to enter your Google name and password. Google will identify you and confirm your identity to our website.

If you log in with Google, we may be able to use certain information from your account to complete your profile with us. You decide whether and which information this is within your Google security settings, which you can find here:

https://myaccount.google.com/security and

https://myaccount.google.com/permissions.

The data processing associated with Google registration is based on our legitimate interest in enabling our users to have the simplest possible registration process (Art. 6 (1) lit. f GDPR). Since the use of the registration function is voluntary and users can decide for themselves about the respective access options, no overriding rights of the data subjects are apparent.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/5780.

5. Social Media

Facebook

Elements of the social network Facebook are integrated on this website. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. However, according to Facebook, the collected data is also transferred to the USA and other third countries.

An overview of the Facebook social media elements can be found here:

https://developers.facebook.com/docs/plugins/?locale=de_DE.

When the social media element is active, a direct connection is established between your device and the Facebook server. Facebook thereby receives the information that you have visited this website with your IP address. If you click the Facebook "Like" button while logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to associate your visit to this website with your user account. We point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Facebook. Further information can be found in Facebook's privacy policy at:

https://de-de.facebook.com/privacy/explanation.

The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and §

25 para. 1 TDDDG. Consent can be revoked at any time.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing carried out by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been laid down in an agreement on joint processing. The wording of the agreement can be found at:

11 / 25The obligations we jointly undertake have been laid down in an agreement on joint processing. You can find the wording of the agreement at:

https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for implementing the tool on our website in a data protection-compliant manner. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g., requests for information) regarding data processed on Facebook can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum,

https://de-de.facebook.com/help/566994660333381 and

https://www.facebook.com/policy.php.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/4452.

Instagram

Functions of the Instagram service are integrated on this website. These functions are

offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

When the social media element is active, a direct connection is established between your device and the

Instagram server. Instagram thereby receives information about your visit to this website.

If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. We point out that, as the provider of the pages, we have no

information on the content of the data transmitted and its use by Instagram.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and §

25 para. 1 TDDDG. Consent can be revoked at any time.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to

Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand

Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing

responsible (Art. 26 GDPR). The joint responsibility is limited exclusively

to the collection of data and its transfer to Facebook or Instagram. The processing after the transfer

processing by Facebook or Instagram is not part of the joint responsibility.

The obligations incumbent on us jointly have been set out in a joint processing agreement.

processing agreement. The wording of the agreement can be found at:

https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing

the data protection information when using the Facebook or Instagram tool and for the

data protection compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook and Instagram products. Data subject rights

(e.g. requests for information) regarding data processed by Facebook or Instagram can be asserted directly with Facebook. If you assert your data subject rights with us, we are obliged to forward them to Facebook.

obliged to forward them to Facebook.

12 / 25The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum,

https://privacycenter.instagram.com/policy/ and

https://de-de.facebook.com/help/566994660333381.

Further information on this can be found in Instagram's privacy policy:

https://privacycenter.instagram.com/policy/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:

European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider under the following link:

https://www.dataprivacyframework.gov/participant/4452.

6. Analysis tools and advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow

Street, Dublin 4, Ireland.

Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other

technologies on our website. Google Tag Manager itself does not create user profiles,

does not store cookies and does not perform independent analyses. It is only used to

manage and play out the tools integrated via it. However, Google Tag Manager collects

your IP address, which can also be transmitted to Google's parent company in the United States.

can be transmitted.

The Google Tag Manager is used on the basis of Art. 6 para. 1 lit. f GDPR. The

website operator has a legitimate interest in the quick and uncomplicated integration and

management of various tools on its website. If a corresponding consent has been requested,

the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1

TDDDG, insofar as the consent includes the storage of cookies or access to information in the

user's end device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be

revoked at any time.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:

European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider under the following link:

https://www.dataprivacyframework.gov/participant/5780.

Google Analytics

This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland

Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyze the behavior of website visitors.

The website operator receives various usage data, such as page views, dwell time,

operating systems used and origin of the user. This data is aggregated in a user ID

and assigned to the respective end device of the website visitor.

13 / 25Furthermore, with Google Analytics we can record, among other things, your mouse and scroll movements and clicks.

record. Google Analytics also uses various modeling approaches to supplement the collected

data sets and uses machine learning technologies for data analysis.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior

user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the USA and stored there.

information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and §

25 para. 1 TDDDG. Consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://business.safety.google/adscontrollerterms/sccs/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:

European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider under the following link:

https://www.dataprivacyframework.gov/participant/5780.

IP anonymization

Google Analytics IP anonymization is activated. This means that your IP address will be shortened by Google within

of member states of the European Union or in other contracting states of the Agreement on the

European Economic Area before being transmitted to the USA. Only in exceptional cases will the

full IP address is transmitted to a Google server in the USA and shortened there. On behalf of the

operator of this website, Google will use this information to evaluate your use of the website,

to compile reports on website activities and to provide other services related to website use and internet use to the website operator.

to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

merged with other data from Google.

Browser Plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available under the following link:

following link:

https://tools.google.com/dlpage/gaoptout?hl=de.

More information on how Google Analytics handles user data can be found in the

Google's privacy policy:

https://support.google.com/analytics/answer/6004245?hl=de.

Google Signals

We use Google Signals. When you visit our website, Google Analytics collects, among other things, your

location, search history and YouTube history as well as demographic data (visitor data). This data

can be used for personalized advertising with the help of Google Signals. If you have a

Google account, the visitor data from Google Signals will be linked to your Google account

and used for personalized advertising messages. The data is also used to create

anonymized statistics on the user behavior of our users.

Google Analytics E-commerce Measurement

14 / 25This website uses the "e-commerce measurement" function of Google Analytics. With the help of e-commerce

measurement, the website operator can analyze the purchasing behavior of website visitors to improve their

online marketing campaigns. Information such as orders placed, average order values, shipping costs and the time from viewing to purchasing a product are recorded.

average order values, shipping costs and the time from viewing to purchasing

a product are recorded. This data can be aggregated by Google under a transaction ID

that is assigned to the respective user or their device.

Hotjar

This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit

Street, St Julians STJ 1000, Malta, Europe (Website:

https://www.hotjar.com).

Hotjar is a tool for analyzing your user behavior on this website. With Hotjar, we can, among other things,

record your mouse and scroll movements and clicks. Hotjar can also determine how long you

remained with the mouse pointer at a certain position. From this information, Hotjar creates

so-called heatmaps, which can be used to determine which areas of the website are preferred by website visitors.

preferred by the website visitor.

Furthermore, we can determine how long you remained on a page and when you left it.

You left. We can also determine at which point you stopped entering information into a contact form

have broken off (so-called conversion funnels).

In addition, direct feedback from website visitors can be obtained with Hotjar. This

function serves to improve the website operator's web offerings.

Hotjar uses technologies that enable the recognition of the user for the purpose of analyzing the

user behavior (e.g. cookies or use of device fingerprinting).

If consent has been obtained, the aforementioned service is used exclusively on the

basis of Art. 6 para. 1 lit. a GDPR and § 25 TDDDG. Consent can be revoked at any time. If

no consent has been obtained, this service is used on the basis of Art. 6 para. 1

lit. f GDPR; the website operator has a legitimate interest in analyzing user behavior in order to

optimize both its website and its advertising.

Disabling Hotjar

If you wish to deactivate data collection by Hotjar, click on the following link and follow the instructions there:

the instructions there:

https://www.hotjar.com/policies/do-not-track/

Please note that Hotjar must be deactivated separately for each browser and each end device.

must be deactivated separately.

Further information about Hotjar and the data collected can be found in the privacy policy

of Hotjar under the following link:

https://www.hotjar.com/privacy

Google Ads

The website operator uses Google Ads. Google Ads is an online advertising program of Google

Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads allows us to display advertisements in the Google search engine or on third-party websites

15 / 25when the user enters certain search terms in Google (keyword targeting). Furthermore,

targeted advertisements can be displayed based on user data available to Google (e.g.

location data and interests) (audience targeting). As website operators,

we can quantitatively evaluate this data by, for example, analyzing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.

led to the display of our advertisements and how many advertisements led to corresponding clicks.

led to corresponding clicks.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a DSGVO and §

25 para. 1 TDDDG. Consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://policies.google.com/privacy/frameworks and

https://business.safety.google/controllerterms/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:

European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider under the following link:

https://www.dataprivacyframework.gov/participant/5780.

Google Ads Remarketing

This website uses the functions of Google Ads Remarketing. The provider is Google Ireland Limited

("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

With Google Ads Remarketing, we can assign people who interact with our online offering to

specific target groups in order to then display interest-based advertising in the Google

advertising network (remarketing or retargeting).

Furthermore, the advertising target groups created with Google Ads Remarketing can be linked with the

cross-device functions of Google. In this way,

interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and browsing behavior on one end device (e.g. mobile phone) can also be displayed on another of your end devices (e.g. tablet or PC).

browsing behavior on one end device (e.g. mobile phone) can also be displayed on another of your

end devices (e.g. tablet or PC).

If you have a Google account, you can object to personalized advertising under the following

link:

https://adssettings.google.com/anonymous?hl=de.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a DSGVO and §

25 para. 1 TDDDG. Consent can be revoked at any time.

Further information and the data protection provisions can be found in Google's privacy policy

at:

https://policies.google.com/technologies/ads?hl=de.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider under the following link:

European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider under the following link:

https://www.dataprivacyframework.gov/participant/5780.

16 / 25Target group formation with customer matching

For target group formation, we use, among other things, Google Ads Remarketing's customer matching.

Here, we transfer certain customer data (e.g. email addresses) from our customer lists to

Google. If the customers concerned are Google users and logged into their Google account, they will be shown relevant advertising messages within the Google network (e.g. on YouTube, Gmail or in the search engine).

appropriate advertising messages within the Google network (e.g. on YouTube, Gmail or in the

search engine).

Google Conversion Tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon

House, Barrow Street, Dublin 4, Ireland.

With the help of Google Conversion Tracking, Google and we can recognize whether the user has performed certain

actions. For example, we can evaluate how often certain buttons on our website

were clicked and which products were viewed or purchased most frequently. These

Information is used to create conversion statistics. We learn the total number of users

who clicked on our ads and what actions they performed. We do not receive

information that can personally identify the user. Google itself uses cookies or similar recognition technologies for identification.

The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and §

25 Para. 1 TDDDG. Consent can be revoked at any time.

More information on Google Conversion Tracking can be found in Google's privacy policy:

https://policies.google.com/privacy?hl=de.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with

European data protection standards for data processing in the USA. Every company certified under the

DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/5780.

Meta Pixel (formerly Facebook Pixel)

This website uses the visitor action pixel from Meta for conversion measurement. The provider of this

service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Meta, the collected data

is also transferred to the USA and other third countries.

This allows the behavior of website visitors to be tracked after they have been redirected to the provider's website by clicking on a Meta ad.

This allows the effectiveness of Meta ads to be evaluated for statistical and market research purposes and future

advertising measures to be optimized.

The collected data is anonymous for us as the operator of this website; we cannot draw conclusions about the identity of the users.

However, the data is stored and processed by Meta, so a connection to the respective user profile on Facebook or Instagram is possible, and Meta can use the data for its own advertising purposes, in accordance with the Meta Data Usage Policy (

https://de-de.facebook.com/about/privacy/). This allows Meta to enable the display of advertisements on Facebook or Instagram pages and other advertising channels.

This use of the data cannot be influenced by us as the website operator.

The use of this service is based on your consent pursuant to Art. 6 Para. 1 lit. a GDPR and §

17 / 2525 Para. 1 TDDDG. Consent can be revoked at any time.

We use the enhanced matching function within the Meta pixel.

Enhanced matching allows us to transmit various types of data (e.g., place of residence, federal state, postal code, hashed email addresses, names, gender, date of birth, or telephone number) of our customers and interested parties, which we collect via our website, to Meta.

This enables us to tailor our advertising campaigns on Facebook and Instagram even more precisely to people who are interested in our offers.

In addition, enhanced matching improves the attribution of website conversions and expands Custom Audiences.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR).

Joint responsibility is limited exclusively to the collection of data and its transfer to Meta.

The processing carried out by Meta after the transfer is not part of the joint responsibility. The obligations jointly incumbent upon us have been laid down in an agreement on joint processing.

The text of the agreement can be found at:

https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Meta tool and for the data protection compliant implementation of the tool on our website.

Meta is responsible for the data security of Meta products. Data subject rights (e.g., requests for information) regarding data processed on Facebook or Instagram can be asserted directly with Meta.

If you assert data subject rights with us, we are obliged to forward them to Meta.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum and

https://de-de.facebook.com/help/566994660333381.

Further information on privacy at Meta can be found in their privacy policy:

https://de-de.facebook.com/about/privacy/.

You can also deactivate the "Custom Audiences" remarketing function in the ad settings section at

https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this,

you must be logged in to Facebook.

If you do not have a Facebook or Instagram account, you can disable usage-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance:

http://www.youronlinechoices.com/de/praferenzmanagement/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with

European data protection standards for data processing in the USA. Every company certified under the

DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/4452.

Meta Conversion API

We have integrated the Meta Conversion API on this website. The provider of this service is Meta

Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Meta, the data collected is also transferred to the USA and other third countries.

18 / 25The Meta Conversion API enables us to record the website visitor's interactions with our website

and transmit them to Meta to improve advertising performance on Facebook and Instagram.

In particular, the time of access, the accessed website, your IP address and user agent, and, if applicable, other specific data (e.g., purchased products, shopping cart value, and currency) are collected.

A complete overview of the data that can be collected can be found here:

https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.

The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and §

25 Para. 1 TDDDG. Consent can be revoked at any time.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR).

Joint responsibility is limited exclusively to the collection of data and its transfer to Meta.

The processing carried out by Meta after the transfer is not part of the joint responsibility. The obligations jointly incumbent upon us have been laid down in an agreement on joint processing.

The text of the agreement can be found at:

https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Meta tool and for the data protection compliant implementation of the tool on our website.

Meta is responsible for the data security of Meta products. Data subject rights (e.g., requests for information) regarding data processed on Facebook or Instagram can be asserted directly with Meta.

If you assert data subject rights with us, we are obliged to forward them to Meta.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum and

https://de-de.facebook.com/help/566994660333381.

Further information on privacy at Meta can be found in their privacy policy:

https://de-de.facebook.com/about/privacy/.

You can also deactivate the "Custom Audiences" remarketing function in the ad settings section at

https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this,

you must be logged in to Facebook.

If you do not have a Facebook or Instagram account, you can disable usage-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance:

http://www.youronlinechoices.com/de/praferenzmanagement/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with

European data protection standards for data processing in the USA. Every company certified under the

DPF undertakes to comply with these data protection standards. Further

information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/4452.

Order processing

We have concluded a contract for order processing (AVV) for the use of the above-mentioned service.

This is a contract required by data protection law that ensures that personal data of our website visitors is processed only according to our instructions and in compliance with the GDPR.

19 / 25ensures that it processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

7. Newsletter

Newsletter data

If you would like to receive the newsletter offered on the website, we require an e-mail address from you and information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter.

Other data is not collected or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

The processing of the data entered in the newsletter registration form takes place exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR).

You can revoke the consent given for storing the data, the e-mail address and its use for sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.

The data you have provided for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after unsubscribing or when the purpose ceases to apply.

We reserve the right to delete or block e-mail addresses from our newsletter distribution list at our own discretion within the framework of our legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.

Data stored by us for other purposes remains unaffected by this.

After you unsubscribe from the newsletter distribution list, your e-mail address may be stored in a blacklist by us or the newsletter service provider, if this is necessary to prevent future mailings.

The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR).

Storage in the blacklist is not time-limited. You can object to the storage if your interests outweigh our legitimate interest.

Newsletter dispatch to existing customers

If you order goods or services from us and provide your e-mail address, this e-mail address may subsequently be used by us for sending newsletters, provided we inform you about this beforehand.

In such a case, the newsletter will only be used for direct advertising for our own similar goods or services. You can cancel the sending of this newsletter at any time. For this purpose, there is a corresponding link in every newsletter.

The legal basis for sending the newsletter in this case is Art. 6 Para. 1 lit. f GDPR in conjunction with Section 7 Para. 3 UWG.

After you unsubscribe from the newsletter distribution list, your e-mail address may be stored in a blacklist by us to prevent future mailings to you.

The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR).

Storage in the blacklist is not time-limited. You can object to the storage if your interests outweigh our legitimate interest.

20 / 258. Plugins and Tools

YouTube with extended data protection

This website integrates videos from the YouTube website. The operator of the website is Google Ireland Limited

("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of these websites where YouTube is embedded, a connection to the YouTube servers is established.

The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you allow YouTube to directly associate your surfing behavior with your personal profile.

You can prevent this by logging out of your YouTube account.

We use YouTube in extended data protection mode. Videos played in extended data protection mode are not used by YouTube to personalize browsing on YouTube.

Advertisements displayed in extended data protection mode are also not personalized. No cookies are set in extended data protection mode.

Instead, however, so-called local storage elements are stored in the user's browser, which, similar to cookies, contain personal data and can be used for recognition. Details on the extended data protection mode can be found here:

https://support.google.com/youtube/answer/171780.

After activating a YouTube video, further data processing operations may be triggered, over which we have no influence.

The use of YouTube is in the interest of an appealing presentation of our online offers.

This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. If corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 Para. 1 lit. a

GDPR and § 25 Para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG.

Consent can be revoked at any time.

Further information on data protection at YouTube can be found in their privacy policy at:

https://policies.google.com/privacy?hl=de.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which aims to ensure compliance with

European data protection standards for data processing in the USA. Every company certified under the

DPF commits to adhering to these data protection standards. Further information can be obtained from the

provider at the following link:

https://www.dataprivacyframework.gov/participant/5780.

9. E-commerce and Payment Providers

Processing of Customer and Contract Data

We collect, process, and use personal customer and contract data for the establishment,

contentual design, and modification of our contractual relationships. We collect, process, and use personal

data about the use of this website (usage data) only to the extent necessary to enable the user to use the

service or to bill for it. The legal basis for this is Art. 6 para. 1 lit. b GDPR.

The collected customer data will be deleted after the order is completed or the business relationship ends

and any existing legal retention periods expire.

21 / 25Legal retention periods remain unaffected.

Data transfer upon conclusion of contract for online shops, merchants and goods dispatch

When you order goods from us, we pass on your personal data to the transport company responsible for

delivery and to the payment service provider commissioned with payment processing. Only such data is

disclosed as the respective service provider requires for the performance of its task. The legal basis for this

is Art. 6 Para. 1 lit. b GDPR, which permits the processing of data for the fulfilment of a contract or pre-

contractual measures. If you have given corresponding consent in accordance with Art. 6 Para. 1 lit. a

GDPR, we will pass on your e-mail address to the transport company entrusted with the delivery so that it

can inform you by e-mail about the shipping status of your order; you can revoke your consent at any time.

Payment services

We integrate payment services from third-party companies on our website. If you make a purchase from us,

your payment data (e.g., name, payment amount, bank details, credit card number) will be processed by

the payment service provider for the purpose of payment processing. The respective contractual and data

protection provisions of the respective providers apply to these transactions. The use of payment service

providers is based on Art. 6 Para. 1 lit. b GDPR (contract processing) and in the interest of a smooth,

convenient, and secure payment process (Art. 6 Para. 1 lit. f GDPR). Insofar as your consent is requested for

certain actions, Art. 6 Para. 1 lit. a GDPR is the legal basis for data processing; consent can be revoked at

any time for the future.

We use the following payment services/payment service providers on this website:

PayPal

The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-

2449 Luxembourg (hereinafter "PayPal").

Data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.

For details, please refer to PayPal's privacy policy:

https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

Apple Pay

The provider of the payment service is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple's privacy

policy can be found at:

https://www.apple.com/legal/privacy/de-ww/.

Google Pay

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy

policy can be found here:

https://policies.google.com/privacy.

Stripe

The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand

Canal Dock, Dublin, Ireland (hereinafter "Stripe").

22 / 25Data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://stripe.com/de/privacy and

https://stripe.com/de/guides/general-data-protection-regulation.

Further details can be found in Stripe's privacy policy at the following link:

https://stripe.com/de/privacy.

Klarna

The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers

various payment options (e.g., installment purchase). If you choose to pay with Klarna (Klarna checkout

solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the

Klarna checkout solution. Details on the use of Klarna cookies can be found at the following link:

https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.

Further details can be found in Klarna's privacy policy at the following link:

https://www.klarna.com/de/datenschutz/.

Paydirekt

The provider of this payment service is Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main,

Germany (hereinafter "Paydirekt"). If you make a payment using Paydirekt, Paydirekt collects various

transaction data and forwards it to the bank with which you are registered for Paydirekt. In addition to the

data required for payment, Paydirekt may collect further data as part of the transaction processing, such as

the delivery address or individual items in the shopping cart. Paydirekt then authenticates the transaction

using the authentication procedure stored for this purpose at the bank. Subsequently, the payment amount is

transferred from your account to our account. Neither we nor third parties have access to your account data.

Details on payment with Paydirekt can be found in the general terms and conditions and the data protection

provisions of Paydirekt at:

https://www.paydirekt.de/agb/index.html.

Sofortüberweisung (Instant Transfer)

The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter "Sofort

GmbH"). With the "Sofortüberweisung" procedure, we receive a payment confirmation from Sofort GmbH in

real time and can immediately begin fulfilling our obligations. If you have chosen the payment method

"Sofortüberweisung," you transmit the PIN and a valid TAN to Sofort GmbH, with which it can log into your

online banking account. After logging in, Sofort GmbH automatically checks your account balance and carries

out the transfer to us using the TAN you provided. It then immediately transmits a transaction confirmation to

us. After logging in, your transactions, the credit limit of the overdraft facility, and the existence of other

accounts and their balances are also automatically checked. In addition to the PIN and TAN, the payment

data you entered and data about your person are also transmitted to Sofort GmbH. The data about your

person includes your first and last name, address, telephone number(s), e-mail address, IP address, and, if

applicable, other data required for payment processing. The transmission of this data is necessary to clearly

establish your identity and to prevent fraud attempts. Details on payment with Sofortüberweisung can be found

at the following link:

https://www.klarna.com/sofort/.

Shopify Payment

The provider of this payment service in the EU is Shopify International Limited, 2nd Floor Victoria

23 / 25Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter "Shopify Payment").

For details, please refer to Shopify Payment's privacy policy:

https://www.shopify.de/legal/datenschutz.

American Express

The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486

Frankfurt am Main, Germany (hereinafter "American Express").

American Express may transmit data to its parent company in the USA. Data transfer to the USA is based on

Binding Corporate Rules. Details can be found here:

https://www.americanexpress.com/en-cz/company/legal/privacy-centre/binding-corporate-rules/.

Further information can be found in American Express's privacy policy:

https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/.

Mastercard

The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410

Waterloo, Belgium (hereinafter "Mastercard").

Mastercard may transfer data to its parent company in the USA. The data transfer to the USA is based on

Mastercard's Binding Corporate Rules. Details can be found here:

https://www.mastercard.de/de-de/datenschutz.html and

https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.

VISA

The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London

W2 6TT, Great Britain (hereinafter "VISA").

Great Britain is considered a secure third country under data protection law. This means that Great Britain

has a level of data protection that corresponds to the level of data protection in the European Union.

VISA may transfer data to its parent company in the USA. The data transfer to the USA is based on the

standard contractual clauses of the EU Commission. Details can be found here:

https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-

zustandigkeitsfragen-fur-den-ewr.html.

Further information can be found in VISA's privacy policy:

https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

 

Data Protection Rocco's Wine Storage

Privacy Policy

1. Data protection at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you visit this

website. Personal data is any data with which you can be personally identified. Detailed information on the

subject of data protection can be found in our privacy policy listed below this text.

Data collection on this website

Who is responsible for data collection on this website?

The data processing on this website is carried out by the website operator. Their contact details can be found

in the "Information on the responsible body" section of this privacy policy.

How do we collect your data?

Your data is collected, on the one hand, by you providing it to us. This can be, for example, data that you

enter into a contact form.

Other data is collected automatically or with your consent when you visit the website by our IT systems. This

is primarily technical data (e.g., internet browser, operating system, or time of page view). This data is

collected automatically as soon as you enter this website.

What do we use your data for?

Some of the data is collected to ensure the website is provided without errors. Other data may be used to

analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data

will also be processed for contract offers, orders, or other order inquiries.

What rights do you have regarding your data?

You have the right at any time to receive free information about the origin, recipient, and purpose of your

stored personal data. You also have the right to request the correction or deletion of this data. If you have

given consent to data processing, you can revoke this consent at any time for the future. You also have the

right, under certain circumstances, to request the restriction of the processing of your personal data. Further,

you have a right to complain to the competent supervisory authority.

For this purpose, as well as for further questions on the subject of data protection, you can contact us at any

time.

Analysis tools and third-party tools

When visiting this website, your surfing behavior can be statistically evaluated. This is mainly done with so-

called analysis programs.

3 / 18Detailed information on these analysis programs can be found in the following

data protection declaration.

2. Hosting

We host the content of our website with the following provider:

Shopify

The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32,

Ireland (hereinafter "Shopify").

Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP

address and information about the device and browser you are using. Shopify also analyzes visitor numbers,

visitor sources, and customer behavior, and creates user statistics. If you make a purchase on our website,

Shopify also collects your name, email address, delivery and billing addresses, payment data, and other data

related to the purchase (e.g., phone number, sales volume, etc.). Shopify stores cookies in your browser for

analysis purposes.

Further details can be found in Shopify's privacy policy:

https://www.shopify.de/legal/datenschutz.

The use of Shopify is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in presenting our

website as reliably as possible. If corresponding consent has been requested, processing is exclusively based

on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies

or access to information in the user's end device (e.g., device fingerprinting) within the meaning of the

TDDDG. Consent can be revoked at any time.

3. General information and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal

data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected.

Personal data is data with which you can be personally identified. This privacy policy explains what data we

collect and what we use it for. It also explains how and for what purpose this happens.

We point out that data transmission on the Internet (e.g., when communicating by e-mail) can have security

gaps. Complete protection of data from access by third parties is not possible.

Information on the responsible body

The responsible body for data processing on this website is:

Rocco Pasquariello

4 / 18Handorfer Straße 21

48157 Münster

Phone: 0251-32256028

Email: roccosweinlager@freenet.de

The responsible body is the natural or legal person who alone or jointly with others decides on the purposes

and means of processing personal data (e.g. names, email addresses, etc.).

Storage duration

Unless a more specific storage period has been mentioned within this privacy policy, personal data will remain

your personal data with us until the purpose for data processing no longer applies. If you submit a

legitimate request for erasure or withdraw consent for data processing, your data will be erased, unless we have

other legally permissible reasons for storing your personal data (e.g., retention periods under tax or commercial law); in

the latter case, erasure will occur after these reasons cease to apply.

General information on the legal basis for data processing on this

Website

If you have given your consent to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, provided that special categories of data

according to Art. 9 para. 1 GDPR are processed. In the event of explicit consent to the transfer of

personal data to third countries, data processing also takes place on the basis of Art.

49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or to access to information on

your terminal device (e.g. via device fingerprinting), data processing will also take place

on the basis of § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data is required for

the fulfillment of a contract or for the implementation of pre-contractual measures, we process your

data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if it is

necessary for compliance with a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR.

Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f

GDPR. Information on the respective legal bases applicable in individual cases will be provided in the following

paragraphs of this privacy policy.

Recipients of personal data

In the course of our business activities, we cooperate with various external bodies. In some cases,

this also requires the transfer of personal data to these external bodies.

We only pass on personal data to external bodies if this is necessary for the fulfillment of a contract,

if we are legally obliged to do so (e.g. transfer of data to tax authorities), if we have a legitimate interest

pursuant to Art. 6 para. 1 lit. f GDPR in the transfer or if another legal basis permits the transfer of data.

When using processors, we only pass on personal data of our customers on the basis of a valid

contract for order processing. In the case of joint processing, a contract for joint processing is concluded.

Revocation of your consent to data processing

Many data processing operations are only possible with your express consent. You can revoke consent that has already been given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

5 / 18Right to object to data collection in special cases and to

direct marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR,

YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR

SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA;

THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS.

THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT,

WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS

WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING

WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE

PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION ACCORDING TO ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES,

YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR

PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING;

THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT,

YOUR PERSONAL DATA WILL NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION

ACCORDING TO ART. 21 PARA. 2 GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, affected persons have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint exists irrespective of other administrative or judicial remedies.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place if it is technically feasible.

Information, rectification and erasure

Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, their origin and recipient and the purpose of the data processing and, if applicable, a right to rectification or erasure of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time. The right to restriction of processing exists in the following cases:

If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.

If the processing of your personal data was/is unlawful, you can demand the restriction of data processing instead of erasure.

6 / 18If we no longer need your personal data, but you need it for the exercise, defense or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.

If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balancing of your and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data – apart from its storage – may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

4. Data collection on this website

Cookies

Our website uses so-called "cookies". Cookies are small data packets and do not cause any damage to your end device. They are stored on your end device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or an automatic deletion occurs by your web browser.

Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g. cookies for processing payment services).

Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.

Cookies that are necessary for carrying out the electronic communication process, for providing certain functions desired by you (e.g. for the shopping cart function) or for optimizing the website (e.g. cookies for measuring web audience) (necessary cookies) are stored on the basis of Art. 6 Para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent for the storage of cookies and comparable recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG); consent can be revoked at any time.

7 / 18You can configure your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

You can find out which cookies and services are used on this website in this privacy policy.

Consent with Usercentrics

This website uses Usercentrics' consent technology to obtain your consent to the storage of certain cookies on your terminal device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Website:

https://usercentrics.com/de/ (hereinafter "Usercentrics").

When you enter our website, the following personal data is transferred to Usercentrics:

Your consent(s) or the revocation of your consent(s)

Your IP address

Information about your browser

Information about your terminal device

Time of your visit to the website

Geolocation

Furthermore, Usercentrics stores a cookie in your browser in order to be able to assign the consents given or their revocation to you. The data collected in this way is stored until you request us to delete it, delete the Usercentrics cookie yourself or the purpose for data storage ceases to apply. Mandatory legal retention periods remain unaffected.

Usercentrics is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.

GDPR Legal Cookie by Shopify

Our website uses GDPR Legal Cookie by Shopify to obtain your consent to the storage of certain cookies on your terminal device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is beeclever GmbH, Friedrich-Mohr-Straße 1, 56070 Koblenz (hereinafter "beeclever").

When you enter our website, a connection is established to the servers of the provider beeclever. In this way, the provider beeclever receives personal data, such as the browser used, the IP address and a timestamp. A cookie is then stored in your browser in order to be able to assign the consents given or their revocation to you. The data collected in this way is stored until you request us to delete it, delete the cookie yourself or the purpose for data storage ceases to apply. Mandatory legal retention periods remain unaffected. Details can be found at:

https://apps.shopify.com/gdpr-legal-cookie.

The use of GDPR Legal Cookie by Shopify takes place in order to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.

Contact form

8 / 18If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not pass on this data without your consent.

The processing of this data is based on Art. 6 para. 1 lit. b GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be revoked at any time.

The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to storage or the purpose for data storage ceases to apply (e.g. after your inquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.

Use of AI on the Website

We use AI-powered services and/or applications on our website.

We use Artificial Intelligence (AI) on our website as follows:

Phone support by Safina AI

If you interact with or come into contact with elements on our website that use artificial intelligence (e.g. chatbot), your input including metadata will be processed to generate an appropriate answer or response.

The use of these AI-powered functions is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in using modern technologies on our website to improve our services and to identify new potential from interacting with our customers. If consent is required, processing is exclusively based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. You can revoke your consent at any time.

Further information on the data processing of this tool or service can be found in the relevant section of this privacy policy.

Inquiry by e-mail, telephone or fax

If you contact us by e-mail, telephone or fax, your inquiry including all personal data resulting from it (name, inquiry) will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.

The processing of this data is based on Art. 6 para. 1 lit. b GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your

consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be

withdrawn at any time.

The data you send to us via contact inquiries will remain with us until you request us to delete it, revoke your

consent to storage, or the purpose for data storage no longer applies (e.g. after your request has been

processed). Mandatory legal provisions – in particular statutory retention periods – remain unaffected.

9 / 185. Social Media

Facebook

Elements of the social network Facebook are integrated into this website. The provider of this service is

Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. However, according to

Facebook, the collected data is also transferred to the USA and other third countries.

An overview of the Facebook social media elements can be found here:

https://developers.facebook.com/docs/plugins/?locale=de_DE.

When the social media element is active, a direct connection is established between your device and the

Facebook server. Facebook thereby receives the information that you have visited this website with your IP

address. If you click the Facebook "Like" button while logged into your Facebook account, you can link the

content of this website to your Facebook profile. This allows Facebook to associate your visit to this website

with your user account. We point out that as the provider of the pages, we have no knowledge of the content

of the transmitted data or its use by Facebook. Further information can be found in Facebook's privacy

policy at:

https://de-de.facebook.com/privacy/explanation.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1

TDDDG. Consent can be withdrawn at any time.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to

Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2,

Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited

exclusively to the collection of data and its transfer to Facebook. The processing carried out by Facebook

after the transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been laid

down in an agreement on joint processing. The wording of the agreement can be found at:

https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for

providing data protection information when using the Facebook tool and for the data protection-compliant

implementation of the tool on our website. Facebook is responsible for the data security of Facebook

products. Data subject rights (e.g., requests for information) regarding data processed by Facebook can be

asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to

Facebook.

Data transfer to the USA is based on the EU Commission's standard contractual clauses.

Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum,

https://de-de.facebook.com/help/566994660333381 and

https://www.facebook.com/policy.php.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement

between the European Union and the USA, which aims to ensure compliance with European data protection

standards when processing data in the USA. Every company certified under the DPF undertakes to comply

with these data protection standards. Further information on this can be obtained from the provider at the

following link:

https://www.dataprivacyframework.gov/participant/4452.

Instagram

10 / 18Functions of the Instagram service are integrated into this website. These functions are offered by Meta

Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

When the social media element is active, a direct connection is established between your device and the

Instagram server. Instagram thereby receives information about your visit to this website.

If you are logged into your Instagram account, you can link the content of this website to your Instagram profile

by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user

account. We point out that as the provider of the pages, we have no knowledge of the content of the transmitted

data or its use by Instagram.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1

TDDDG. Consent can be withdrawn at any time.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to

Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour,

Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is

limited exclusively to the collection of data and its transfer to Facebook or Instagram. The processing carried

out by Facebook or Instagram after the transfer is not part of the joint responsibility. The obligations incumbent

on us jointly have been laid down in an agreement on joint processing. The wording of the agreement can be

found at:

https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for

providing data protection information when using the Facebook or Instagram tool and for the data protection-

compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook

or Instagram products. Data subject rights (e.g., requests for information) regarding data processed by

Facebook or Instagram can be asserted directly with Facebook. If you assert data subject rights with us, we are

obliged to forward them to Facebook.

Data transfer to the USA is based on the EU Commission's standard contractual clauses.

Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum,

https://privacycenter.instagram.com/policy/ and

https://de-de.facebook.com/help/566994660333381.

Further information can be found in Instagram's privacy policy:

https://privacycenter.instagram.com/policy/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement

between the European Union and the USA, which aims to ensure compliance with European data protection

standards when processing data in the USA. Every company certified under the DPF undertakes to comply

with these data protection standards. Further information on this can be obtained from the provider at the

following link:

https://www.dataprivacyframework.gov/participant/4452.

6. Analytics tools and advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4,

Ireland.

11 / 18Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies

into our website. Google Tag Manager itself does not create user profiles, store cookies, or perform its own

analyses. It merely serves to manage and deploy the tools integrated through it. However, Google Tag Manager

collects your IP address, which can also be transferred to Google's parent company in the United States.

The use of Google Tag Manager is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate

interest in quickly and easily integrating and managing various tools on his website. If appropriate consent has

been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para.

1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device

(e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement

between the European Union and the USA, which aims to ensure compliance with European data protection

standards when processing data in the USA. Every company certified under the DPF undertakes to comply

with these data protection standards. Further information on this can be obtained from the provider at the

following link:

https://www.dataprivacyframework.gov/participant/5780.

Google Analytics

This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland

Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics allows the website operator to analyze the behavior of website visitors. The website operator

receives various usage data, such as page views, duration of stay, operating systems used, and the user's

origin. This data is aggregated into a user ID and assigned to the respective device of the website visitor.

Furthermore, with Google Analytics, we can record, among other things, your mouse and scroll movements and

clicks. Google Analytics also uses various modeling approaches to supplement the collected data records and

employs machine learning technologies in data analysis.

Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior

(e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is

usually transmitted to a Google server in the USA and stored there.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1

TDDDG. Consent can be withdrawn at any time.

Data transfer to the USA is based on the EU Commission's standard contractual clauses.

Details can be found here:

https://business.safety.google/adscontrollerterms/sccs/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement

between the European Union and the USA, which aims to ensure compliance with European data protection

standards when processing data in the USA. Every company certified under the DPF undertakes to comply

with these data protection standards. Further information on this can be obtained from the provider at the

following link:

https://www.dataprivacyframework.gov/participant/5780.

12 / 18IP Anonymization

Google Analytics IP anonymization is activated. This means that your IP address will be truncated by Google

within member states of the European Union or in other contracting states of the Agreement on the European

Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be

transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google

will use this information to evaluate your use of the website, to compile reports on website activity and to provide

other services related to website and internet use to the website operator. The IP address transmitted by your

browser as part of Google Analytics will not be merged with other Google data.

Browser Plugin

You can prevent Google from collecting and processing your data by downloading and installing the browser

plugin available at the following link:

https://tools.google.com/dlpage/gaoptout?hl=de.

More information on how Google Analytics handles user data can be found in Google's privacy policy:

https://support.google.com/analytics/answer/6004245?hl=de.

Google Signals

We use Google Signals. When you visit our website, Google Analytics collects, among other things, your

location, search history, and YouTube history, as well as demographic data (visitor data). This data can be used

with the help of Google Signals for personalized advertising. If you have a Google account, the visitor data from

Google Signals will be linked to your Google account and used for personalized advertising messages. The data

is also used to create anonymized statistics on the user behavior of our users.

Google Analytics E-commerce Measurement

This website uses the "E-commerce measurement" function of Google Analytics. With the help of e-commerce

measurement, the website operator can analyze the purchasing behavior of website visitors to improve their

online marketing campaigns. This involves collecting information such as orders placed, average order values,

shipping costs, and the time from viewing to purchasing a product. This data can be aggregated by Google

under a transaction ID, which is assigned to the respective user or their device.

Hotjar

This website uses Hotjar. The provider is Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit

Street, St Julians STJ 1000, Malta, Europe (Website:

https://www.hotjar.com).

Hotjar is a tool for analyzing your user behavior on this website. With Hotjar, we can record, among other

things, your mouse and scroll movements and clicks. Hotjar can also determine how long you have remained

with the mouse pointer at a certain position. From this information, Hotjar creates so-called heatmaps, which

can be used to determine which areas of the website are preferred by website visitors.

Furthermore, we can determine how long you have remained on a page and when you left it. We can also

determine where you interrupted your entries in a contact form (so-called conversion funnels).

13 / 18In addition, Hotjar can be used to obtain direct feedback from website visitors. This function serves to improve

the website operator's web offerings.

Hotjar uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies

or the use of device fingerprinting).

Insofar as consent has been obtained, the aforementioned service is used exclusively on the basis of Art. 6

para. 1 lit. a GDPR and § 25 TDDDG. Consent can be withdrawn at any time. Insofar as no consent has been

obtained, this service is used on the basis of Art. 6 para. 1 lit. f GDPR; the website operator has a legitimate

interest in analyzing user behavior to optimize both its web offering and its advertising.

Disabling Hotjar

If you wish to disable data collection by Hotjar, click on the following link and follow the instructions there:

https://www.hotjar.com/policies/do-not-track/

Please note that Hotjar must be deactivated separately for each browser or device.

For more information about Hotjar and the data collected, please refer to the privacy policy

of Hotjar at the following link:

https://www.hotjar.com/privacy

Google Ads

The website operator uses Google Ads. Google Ads is an online advertising program of Google

Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads allows us to display advertisements in the Google search engine or on third-party websites

when the user enters specific search terms into Google (keyword targeting). Furthermore,

targeted advertisements can be displayed based on user data available to Google (e.g.,

location data and interests) (audience targeting). As website operators,

we can evaluate this data quantitatively, for example, by analyzing which search terms led to the display

of our advertisements and how many advertisements led to corresponding clicks.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and §

25 para. 1 TDDDG. Consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission.

Details can be found here:

https://policies.google.com/privacy/frameworks and

https://business.safety.google/controllerterms/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which aims to ensure compliance with

European data protection standards for data processing in the USA. Every company certified under

the DPF commits to adhering to these data protection standards. Further

information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/5780.

Google Ads Remarketing

14 / 18This website uses the functions of Google Ads Remarketing. The provider is Google Ireland Limited

("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

With Google Ads Remarketing, we can assign people who interact with our online offering to

certain target groups, in order to then display interest-based advertising to them in the Google

advertising network (remarketing or retargeting).

Furthermore, the advertising target groups created with Google Ads Remarketing can be linked with the

cross-device functions of Google. In this way,

interest-based, personalized advertising messages, which have been adapted to you depending on your previous usage and

browsing behavior on one device (e.g., mobile phone), can also be displayed on another of your

devices (e.g., tablet or PC).

If you have a Google account, you can object to personalized advertising at the following

link:

https://adssettings.google.com/anonymous?hl=de.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and §

25 para. 1 TDDDG. Consent can be revoked at any time.

Further information and the data protection provisions can be found in Google's privacy policy

at:

https://policies.google.com/technologies/ads?hl=de.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which aims to ensure compliance with

European data protection standards for data processing in the USA. Every company certified under

the DPF commits to adhering to these data protection standards. Further

information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/5780.

Google Conversion Tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon

House, Barrow Street, Dublin 4, Ireland.

With the help of Google Conversion Tracking, Google and we can recognize whether the user has performed certain

actions. For example, we can evaluate which buttons on our website

were clicked how often and which products were viewed or purchased particularly often. This

information is used to create conversion statistics. We learn the total number of users

who clicked on our ads and what actions they performed. We do not receive any

information that would allow us to personally identify the user. Google itself uses cookies or

comparable recognition technologies for identification.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and §

25 para. 1 TDDDG. Consent can be revoked at any time.

More information on Google Conversion Tracking can be found in Google's privacy policy

at:

https://policies.google.com/privacy?hl=de.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The

DPF is an agreement between the European Union and the USA, which aims to ensure compliance with

European data protection standards for data processing in the USA. Every company certified under

the DPF commits to adhering to these data protection standards. Further

15 / 18information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/participant/5780.

7. Newsletter

Newsletter data

If you wish to subscribe to the newsletter offered on the website, we require an e-mail address from you

as well as information that allows us to verify that you are the owner of the

e-mail address provided and that you agree to receive the newsletter. Further

data is not collected or only on a voluntary basis. We use this data exclusively for

sending the requested information and do not pass it on to third parties.

The processing of the data entered into the newsletter registration form is based exclusively on

your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent to the storage of

data, the e-mail address, and its use for sending the newsletter at any time,

for example, via the "unsubscribe" link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the revocation.

The data you have stored with us for the purpose of newsletter subscription will be stored by us until you

unsubscribe from the newsletter with us or the newsletter service provider and will be deleted after

unsubscribing from the newsletter or when the purpose ceases to apply from the newsletter distribution list. We

reserve the right to delete or block e-mail addresses from our newsletter distribution list at our discretion within the scope

of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

Data stored with us for other purposes remains unaffected by this.

After you unsubscribe from the newsletter distribution list, your e-mail address will be stored with us or the

newsletter service provider, if necessary, in a blacklist, provided this is necessary to prevent future

mailings. The data from the blacklist will only be used for this purpose and will not be combined with

other data. This serves both your interest and our interest in

complying with legal requirements when sending newsletters (legitimate interest within the meaning of

Art. 6 para. 1 lit. f GDPR). Storage in the blacklist is not time-limited. You can object to the

storage if your interests outweigh our legitimate interest.

8. eCommerce and Payment Providers

Processing of customer and contract data

We collect, process, and use personal customer and contract data for the establishment,

content-related design, and amendment of our contractual relationships. We only collect, process, and use personal data about the

use of this website (usage data) insofar as this is

necessary to enable the user to use the service or to bill for it.

The legal basis for this is Art. 6 para. 1 lit. b GDPR.

The collected customer data will be deleted after the completion of the order or the termination of the

business relationship and the expiry of any applicable statutory retention periods.

Statutory retention periods remain unaffected.

Data transfer upon conclusion of contract for online shops, retailers, and shipping of goods

When you order goods from us, we pass on your personal data to the transport company entrusted with the delivery

and to the payment service provider entrusted with payment processing

16 / 18. Only such data is released as the respective service provider requires to fulfill its

task. The legal basis for this is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for

the performance of a contract or pre-contractual measures. If you have given corresponding

consent according to Art. 6 para. 1 lit. a GDPR, we will transfer your e-mail address to the transport company entrusted with the

delivery so that it can inform you by e-mail about the shipping status

of your order; you can revoke your consent at any time.