Privacy policy


General information



For MARCEL OSTERTAG the compliance with the data protection laws is not only a legal obligation but also an important factor of confidence. With the following data protection regulations we would therefore like to inform you transparently about the type, scope and purpose of the personal data collected and processed by you within this internet presence as well as your rights.



Responsibility for data processing



MARCEL OSTERTAG, owner Marcel Ostertag, Schlüterstraße 12 in 10625 Berlin (hereinafter referred to as "We"), as the operator of the website www.marcelostertag.com, is responsible in accordance with Art. 4 No. 7 of the EU Data Protection Basic Regulation (DSGVO). If you have any questions, please contact info@marcelostertag.com.



Data protection officer



You can reach our data protection officer by e-mail at: info(at)marcelostertag.com



Rights of data subjects



Your rights as a data subject


As a data subject, you have the following rights in relation to your personal data. You have:

  • A right to be informed, inter alia, about the categories of data processed, the purposes of processing, the duration of storage and any recipients, pursuant to Art. 15 DSGVO and Art. 34 BDSG.
  • A right to the correction or deletion of incorrect or incomplete data, in accordance with Art. 16 and 17 DSGVO and § 35 BDSG
  • A right to restrict processing under the conditions of Art. 18 DSGVO or § 35 para. 1 sentence 2 BDSG.
  • A right to object to processing in accordance with Art. 21 Paragraph 1 DSGVO, if the data processing was carried out on the basis of a legitimate interest.
  • A right to revoke a consent given with effect for the future in accordance with Art. 7 Para. 3 DSGVO.
  • A right to data transferability in a standard format in accordance with Art. 20 DSGVO.
  • Pursuant to Art. 22 DSGVO, you have a right not to be subjected to a decision based exclusively on automated processing which has legal effect vis-à-vis you or significantly affects you in a similar manner. This also includes profiling within the meaning of Art. 4 No. 4 DSGVO.
  • You also have the right, pursuant to Art. 77 DSGVO, to complain to a data protection supervisory authority about the processing of your personal data by us, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.


Procedure


If you assert your rights under the DSGVO and the BDSG against us, we will process the data you provide us with in the process in order to fulfil your claim.

Subsequently, we will store the data transmitted by you to us and the data transmitted by us to you in return for the purpose of documentation until the expiry of the statutory period of limitation (3 years).

The legal basis for the processing and storage of the data is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). The legitimate interest results from our obligation to comply with your request and the need to be able to exonerate us in any fine proceedings by proving that we have properly complied with your request.

You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint. However, we would like to point out that the processing of your data to prove compliance with the rights of the persons concerned is mandatory within the meaning of Art. 21 para. 1 DSGVO, as other means of proof do not exist or are not equally suitable.


Data protection measures


We secure our website and other systems - and thus also your data - by technical and organisational measures against loss, destruction, access, modification or distribution by unauthorised persons. In particular, your personal data will be encrypted as it is transmitted through the Internet. We use the TLS (Transport Layer Security) coding system for this purpose.

However, the transmission of information via the Internet is never completely secure, which is why we cannot guarantee the security of the data transmitted by our website to 100%.



Modalities of data processing



Sources and categories of personal data


We process your personal data insofar as they are necessary for the establishment, content design or modification of a contractual relationship between you and us (inventory data). Inventory data can be in particular: Name, form of address, contact data (postal address, telephone, e-mail address), date of birth, etc.

Furthermore we process your usage data. Usage data is data that is generated by your behaviour when using our website and our services, in particular your IP address, the beginning and end of your visit to our website and information about what content you have called up on our website.

We collect the aforementioned data either directly from you (e.g. by visiting the website) or, as far as permitted by the data protection laws, from third parties or from publicly accessible sources (e.g. commercial and association registers, press, media, Internet).


Data transfer to third countries outside the EU


All information that we receive from you or about you is generally processed on servers within the European Union. Your data will only be transferred to or processed in third countries without your express consent if this is provided for or permitted by law and an appropriate level of data protection is ensured in the third country.


Transfer of data, processing of orders


We never pass on your personal data to third parties without authorisation. However, we may pass on your data to third parties, in particular if you have consented to the disclosure of your data, if the disclosure is necessary for the fulfilment of our legal obligations or if we are entitled or obliged to disclose your data due to legal regulations or official or court orders. This may, in particular, involve the provision of information for the purposes of criminal prosecution, averting danger or enforcing intellectual property rights.

We may pass on the personal data collected from you to third parties, particularly in the context of contract implementation, for example to the transport company commissioned with the delivery or the service used for payment, insofar as this is necessary for the fulfilment of the contract. The individual service providers and further information can be found below in the section "Third party services".

Under certain circumstances, we may also transfer your data to external service providers who process data on our behalf and according to our instructions (processors) in order to simplify or relieve the burden on our own data processing. Each processor is bound by a contract in accordance with Art. 28 DSGVO. This means in particular that the processor must provide sufficient guarantees that suitable technical and organisational measures are implemented by him/her in such a way that the processing is carried out in accordance with the requirements of the DSGVO and that the protection of your rights as a data subject is ensured. Despite the commissioning of contract processors, we remain the responsible body for the processing of your personal data in accordance with the data protection laws.


Purpose of the data processing


As a matter of principle, we use the data only for the purpose for which it was collected from you. We may further process the data for another purpose, unless this other purpose is incompatible with the original purpose (Art. 5 para. 1 lit. c) DSGVO).


Storage period


Unless otherwise stated in detail, we only store data collected from you for as long as it is necessary for the respective purpose, unless statutory storage obligations prevent deletion, e.g. under commercial or tax law.


Individual processing activities


In the following, we would like to present to you as transparently as possible what data we process from you, on what occasion, on what basis and for what purpose.


Server log files


Every time a web page is called up and every time data is retrieved from a server, general information is automatically transmitted to the server providing it. This data transfer is automatic and is a fundamental part of the communication between devices on the Internet.

The standard data transmitted includes the following information: Your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed the site (so-called referer), date and time of the request (so-called timestamp). In addition, the http status and the amount of data transferred are recorded in the context of this request.

This information is logged by the server, filed in a table and stored there for a short period of time (so-called server log files). By analysing these log files, we are able to identify and then correct website errors, determine the website load at certain times and, based on this, make adjustments or improvements, and ensure the security of the server by being able to trace from which IP address attacks on our server were carried out.

Your IP address is only stored for the time of your use of the website and is then immediately deleted or partially obscured by shortening. The remaining data is stored for a limited period of time (usually 7 days).

The legal basis for the use of the server log files is Art. 6 para. 1 p. 1 letter f) DSGVO (legitimate interest in data processing). The legitimate interest results from the necessity for the operation and maintenance of our website, as we have explained above. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact data given in the imprint for this purpose. However, we would like to point out in advance that the processing of your data in server log files is mandatory within the meaning of Art. 21 para. 1 DSGVO, otherwise the website cannot be operated at all.


Cookies and Web Storage


We use so-called "cookies" or the "web storage" of your browser to improve user-friendliness on our website.



Cookies



What cookies are


In very simplified terms, a cookie is a small text file that stores data about visited websites. Cookies can be used in many different ways. For example, you can store a kind of "user profile", which is things like your preferred language and other page settings that are needed by our website to provide certain services to you. The cookie file is stored on your device and may also help us to recognise you when you return to our website.

Cookies may also enable us to obtain information about your preferred activities on our website and thus tailor our website to your individual interests or even increase the speed of navigation on our website.


How you can avoid cookies


You can manually delete the cookies in the security settings of your browser at any time.

However, you can also prevent the storage of cookies from the outset by adjusting your browser settings accordingly. Please note, however, that you may then not be able to use all the functions of our website to their full extent or that errors may occur in the display and use of the website.


Cookies from third parties


It is possible that third-party providers, with the help of which we design and operate our site, in particular by means of so-called plug-ins (see below in the section "Third Party Services"), may independently store their own cookies on your terminal device. If you only want to accept our own cookies, but not cookies from these third parties, you can prevent the storage of these cookies by selecting the appropriate browser setting "Block third-party cookies".


Which cookies are used


In detail our website sets the following cookies:


Name

Explanation

Origin (domain)

Validity/ Storage duration

Third party access

__cfduid

This cookie is used by the Cloudflare content network to identify trusted web traffic.

.marcelostertag.com

1 Month

Yes, Shopify

_landing_page

This cookie is set by the third party provider Shopify and is used for range measurement or analysis by storing information regarding target pages. Target pages are specially set up web pages that appear after a mouse click on an advertising medium or after a click on an entry in a search engine.

.marcelostertag.com

2 Weeks

Yes, Shopify

_orig_referrer

This cookie is set by the provider Shopify and is used for range measurement or analysis by storing information about the user. This information represents an ID chain of a specific user, which can be used to identify groups with similar interests and preferences as target groups. The information may also be used by third parties or for advertising purposes.

.marcelostertag.com

2 Weeks

Yes, Shopify

_secure_session_id

This cookie is set by the third-party provider Shopify and is used in connection with navigation in the web shop.enhang mit der Navigation im Webshop eingesetzt.

.marcelostertag.com

1 Day

Yes, Shopify

_shopify_fs

This cookie is set by the provider Shopify and is used to analyse the user by tracking and storing the user's browsing behaviour in order to optimise the website and make the advertising on the website more relevant.

.marcelostertag.com

2 Years

Yes, Shopify

_shopify_sa_p, _shopify_sa_t

These cookies are set by the provider Shopify and are used to analyse the user's marketing by tracking and storing the user's browsing behaviour. The cookie also makes it possible to recognise links from other websites.

.marcelostertag.com

30 Minutes

Yes, Shopify

_shopify_s, _s

These cookies are set by the provider Shopify and are used to analyse the user's browsing behaviour.

.marcelostertag.com

30 Minutes

Yes, Shopify

_shopify_y, _y

These cookies are set by the third-party provider Shopify and are used to analyse the user's browsing behaviour.

.marcelostertag.com

1 Years

Yes, Shopify

cart_currency

This cookie is set by the third-party provider Shopify and is used for the functionality of the shopping cart in the webshop by storing the selected currency in the cookie.

. .marcelostertag.com

2 Weeks

Yes, Shopify

cart_sig, cart_ts

These cookies are set by the provider Shopify and are required in connection with the checkout of the webstore for the functionality of the webstore.

.marcelostertag.com

2 Weeks

Yes, Shopify

cart_ver

This cookie is set by the provider Shopify and serves the functionality of the shopping cart in the webshop.

.marcelostertag.com

2 Weeks

Yes, Shopify

cart

This cookie is set by the provider Shopify and is needed in connection with the shopping cart of the webstore for the functionality of the webstore.

.marcelostertag.com

2 Weeks

Yes, Shopify

secure_customer_sig

This cookie is set by the third-party provider Shopify and is used for the functionality of the user's login function on the website.

.marcelostertag.com

40 Years

Yes, Shopify

shopify_pay_redirect

These cookies are set by the third-party provider Shopify and are required for the check out.

.marcelostertag.com

1 Hour

Yes, Shopify

storefront_digest

This cookie is set by the third-party provider Shopify and is used for the functionality of the user's login function on the website.

.marcelostertag.com

End of session

Yes, Shopify

akavpau_ppsd, nsid, x-cdn, X-PP-L7, x-pp-s

Diese Cookies werden im Zusammenhang mit der PayPal-Zahlungsfunktion auf der Webseite verwendet und werden für eine funktionelle und sichere Transaktion über Paypal benötigt.

.www.paypal.com

End of session

Yes, Paypal

enforce_policy

These cookies are used in connection with the PayPal payment function on the website and are required for a functional and secure transaction via PayPal.

.paypal.com

1 Year

Yes, Paypal

LANG, tsrce

This cookie is used in connection with the PayPal payment function on the website, and is required for a functional and secure transaction via PayPal.

.paypal.com

3 Day

Yes, Paypal

ts_c, ts

These cookies are used in connection with the PayPal payment function on the website, and are required for a functional and secure transaction via PayPal.

.paypal.com

3 Jahre

Yes, Paypal

x-csrf-jwt

These cookies are used in connection with the PayPal payment function on the website, and are required for a functional and secure transaction via PayPal.

.paypal.com

1 Week

Yes, Paypal

X-PP-SILOVER

These cookies are used in connection with the PayPal payment function on the website, and are required for a functional and secure transaction via PayPal.

.paypal.com

45 Minutes

Yes, Paypal

_landing_page, _orig_referrer

These cookies are set by the third party provider Shopify and are used for range measurement or analysis by storing information regarding target pages. Target pages are specially set up web pages that appear after a mouse click on an advertising medium or after a click on an entry in a search engine.

.shopify.com

14 Days

Yes, Shopify

_pay_session

This cookie is set by the used payment provider Shopify-Payment, and is used for the secure payment function and check-out in the webshop.

pay.shopify.com

End of session

Yes, Shopify

_shopify_y, _y

These cookies are set by the third-party provider Shopify and are used to analyse the user's browsing behaviour.

.shopify.com

1 Year

Yes, Shopify

tracked_start_checkout

This cookie is set by the third party provider Shopify and is used to analyse the user when checking out of the web shop, where the user's browsing behaviour is tracked and stored.

.marcelostertag.com

1 Year

Yes, Shopify



Legal basis



The legal basis for the use of cookies that are absolutely necessary for the functioning of the website (e.g. shopping basket cookie, session cookie) is Art. 6 para. 1 p. 1 letter f) DSGVO (legitimate interest in data processing). The legitimate interest results from our need to be able to offer you a functioning website. Cookies are required for this purpose because they are an integral part of current Internet technology and without cookies many functions of current websites would not be available. We therefore need cookies to be able to provide you with the website upon your request.

You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


We would like to point out, however, that the processing of your data in certain cookies is mandatory within the meaning of Art. 21 para. 1 DSGVO, as otherwise the website cannot be operated at all and we do not have the technical means to prevent the setting of cookies on certain individual terminals. However, you may be able to do this yourself in your browser. For further information on this, please refer to the instructions for your browser.


The legal basis for the use of cookies, which are not absolutely necessary for the functioning of the website, is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the person concerned). When you first call up the website, we ask you to give your consent to the use of non-essential cookies by means of a displayed information text. You can withdraw your consent at any time with effect for the future by deleting all cookies in your browser. You can find out how this works in your browser from the browser instructions.



Web storage



What is the Web Storage


Web storage is a technique for web applications that stores data in a web browser. The Web Storage can be seen in a simplified way as a further development of cookies, but differs from them in some points.

Unlike cookies, which can be accessed by both server and client, the Web Storage is completely controlled by the client. This means that data is not transferred to the server every time the Web page is called. The access is exclusively local via scripts on the website. In concrete terms, this means that third parties cannot access the stored information via the website. Only you and we can access the locally stored data.


Legal basis


The legal basis for the use of the Web Storage, which is absolutely necessary for the functioning of the website, is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). The legitimate interest results from our need to be able to offer you a functioning website. The web storage is necessary for this purpose because it is an integral part of current Internet technology and without it many functions of current websites would not be available. We therefore need the Web Storage to be able to provide you with the website at your request.


You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.

We would like to point out, however, that the processing of your data in web storage may be mandatory within the meaning of Art. 21 para. 1 DSGVO, as otherwise the website cannot be operated at all and we have no technical means of preventing its use on certain individual terminals. However, you may be able to do this yourself in your browser. For further information on this, please refer to the instructions for your browser.


The legal basis for the use of the Web Storage, which is not absolutely necessary for the functioning of the website, is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the person concerned). We ask you for your consent to use the Web Storage the first time you call up the website via a superimposed information text. You can withdraw your consent at any time with effect for the future by deleting all cookies in your browser. You can find out how this works in your browser from the browser instructions.


Newsletter


We offer you to keep you regularly updated through our newsletter and to inform you about special offers. To subscribe to the newsletter, you can add your email address to our distribution list. You must then confirm your registration again (double opt-in procedure). We use the data you provide us with only for the purpose of sending out the newsletter and do not pass it on to third parties for other purposes.


You will find further information on data transfer below in the section "Third Party Services - External Newsletter Service".


Further information on data processing when receiving our newsletter can be found below in the section "Third Party Services - Analysis Services".

The legal basis for the use of your e-mail address is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the data subject). You can revoke your consent at any time with effect for the future. To do so, please use the link in every newsletter e-mail or contact us using the contact details given in the imprint.


Use of our webshop


If you would like to order in our web shop, it is absolutely necessary for the conclusion of the contract and the processing of your order that you provide certain data. These details, which are essential for processing, are marked separately, all other details can be provided voluntarily. We process the data you provide during the ordering process only for processing your order. If you do not provide the required data, this means that your order cannot be processed.

Furthermore, it may be necessary to pass on your data to third parties, e.g. banks/payment service providers, logistics companies, etc., in order to process your order. You will find more detailed information above under "Passing on of data" and below in the section "Third party services".


The legal basis for the use of your data for processing the order is Art. 6 para. 1 sentence 1 letter b) DSGVO (data processing for the fulfilment of a contract). The legal basis for the data you provide voluntarily during the ordering process is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the person concerned). You can revoke your consent at any time with effect for the future. Please use the contact details given in the imprint for this purpose.


We are obliged by commercial and tax law to store your address, payment and order data for a period of ten years. Web storage is necessary because it is an integral part of current Internet technology and without it many features of current websites would not be available.


To prevent unauthorised access to your personal data by third parties, in particular financial data, the ordering process is encrypted using TLS technology.


We may also process the data you provide in order to inform you about other interesting products from our portfolio or to send you e-mails with technical information.


The legal basis for the use of your contact data for this purpose is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). The justified interest results from our need to send you interesting information about our products and services and our company (direct advertising).

You can object to the processing of your data on the basis of our justified interest in direct advertising at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint for this purpose.



Registration area


Our website offers you the opportunity to register for additional, personalised functions of the site. During registration, personal data (e.g. email address and name) is collected and processed for the purpose of providing personalised services.



We require the following information from you:


Password: The specification of a password is necessary for us, because this is the only way we can protect your account sufficiently. We will use your details exclusively for this purpose.


The legal basis for the data provided by you in the registration process is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the person concerned). You can revoke your consent at any time with effect for the future. Please use the contact details given in the imprint for this purpose.


The legal basis for the processing of mandatory data is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). We have explained the justified interest in the above list. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact data given in the imprint for this purpose.

You also have the option of changing or completely deleting the data provided during the registration process at any time.



Third party services



We use third party services/resources, such as plug-ins, external content, software or other external service providers (services) to simplify our data processing and to extend the range of functions of our website. Personal data may also be transmitted to the service provider in the process. In order to protect your data, we have, if necessary, contractually obliged the service providers in accordance with Art. 28 DSGVO to process your data only according to our instructions.


We expressly point out that we are regularly only responsible for the collection and transmission of data by the service in the sense of the DSGVO, but not for any processing by the respective service provider that may occur at a later date.


In detail we use the following services:


Google services


Our website uses the following services provided by Google Ireland Limited ("Google EU"), Gordon House, Barrow Street, Dublin 4, Ireland This company represents in the EU the company Google LLC ("Google US"), 1600 Amphitheatre Parkway Mountain View, CA 94043, USA

By using the services, data is transmitted to Google EU and possibly from Google EU to Google US. The Google Group may process the transmitted data to create anonymous user profiles for statistical purposes. If you also have a Google Account and are logged in to it, Google may associate the information submitted with your account, including across devices. We have no influence on this data processing. Google EU is therefore responsible for this data processing.

You can find more information on the handling of user data in Google's privacy policy: https://policies.google.com/privacy.

You can manage your Google advertising settings on the following website: https://adssettings.google.com/?hl=de (This setting is deleted when you delete your cookies)


We use:


Google Fonts


Our website uses the external font service "Google Fonts" from Google. This service enables us to present our website in a uniform and appealing way even with very differently configured user end devices by loading fonts from an external server instead of from the user's end device. For this purpose the required fonts are usually requested from a Google server in the USA. As a result of this request, the following information, among others, is transmitted to the Google server and stored there: Your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed the site (so-called referrer), date and time of the request and possibly your Internet service provider.

The legal basis for the processing of your data in relation to the "Google Fonts" service is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). The justified interest results from our need for an attractive and uniform presentation of our online offer. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint for this purpose.


Google reCAPTCHA

Our website uses the abuse protection "Google reCAPTCHA" by Google. reCAPTCHA serves to prevent cyber attacks and harassment by so-called "bots" (artificial website users) by checking via an input field whether the person visiting the website is a real person. This service enables us to keep our website stable and to protect it from abuse. For this purpose, the data entered is usually transferred to a Google server in the USA and processed there for verification. Through this request, the following information, among others, is transmitted to the Google server and stored there: Your input in the input field, your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed the site (so-called referrer), date and time of the request and possibly your Internet service provider.


This service uses the web storage of your browser. For more information, please refer to the section "Web Storage" above.

The legal basis for the processing of your data in relation to the "Google reCAPTCHA" service is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). The justified interest results from our need for effective protection of our online service against cyber attacks and misuse. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.



External newsletter service


We use external service providers who enable us to provide you with a newsletter containing current information and offers. The services are usually a cloud-based service for newsletter dispatch. This allows you to create, send and manage newsletters. The software is provided via the Internet, so that we use the service via a web interface on an external server of the respective provider, so that data processing can also take place outside the EU. In particular, it may be necessary to transmit the data you provide when registering for the newsletter to the respective provider. We have concluded a so-called contract processing agreement with the respective provider to ensure that they process your data only according to our instructions.


Since we ask you for your consent before sending our newsletter, the legal basis for data processing for sending the newsletter is Art. 6 Para. 1 S. 1 Letter a) DSGVO (consent of the data subject). You can revoke this consent at any time with effect for the future. Please use the unsubscribe link in the newsletter or contact us.


The legal basis for the transfer of data within the framework of the use of cloud newsletter software and the associated registration software is Art. 6 Para. 1 S. 1 Letter f) DSGVO (legitimate interest in data processing), unless otherwise stated for the respective service. The justified interest results from our need to simplify and relieve our data processing. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


We use:


MailJet


We use the newsletter service "Mailjet" of Mailjet GmbH, Rankestr. 21, 10789 Berlin, a subsidiary of Mailjet SAS, 13-13 bis, rue de l'Aubrac, 75012 Paris, France.


For more information on how user data is handled, please refer to the Mailjet privacy policy: https://www.mailjet.de/privacy-policy.


Content Delivery Networks


Our website uses so-called Content Delivery Networks (CDN). A CDN is a network of powerful servers that cache content at various locations around the world. A CDN has two main tasks: firstly, it should provide content in the shortest possible time and secondly, it should relieve the web host by distributing the data traffic.


CDNs transmit two types of content: Static and dynamic content. Static content is provided to all website visitors in the same form, such as video content from streaming services or code frameworks (e.g. Javascript, jQuery). Dynamic content is first adapted to the user and only created at the moment of the request. This includes content that is personalised and delivered via web applications, e-mail or online shops. To use the latter, information about the website visitor must first be transmitted to the CDN. Personal data may also be transmitted by you in this process.


Every time you call up the application, general information is automatically transmitted to the server by your browser (so-called server log files). For further information see above under "Server log files".


The legal basis for the use of CDNs and the transmission of your data to them is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing), unless otherwise stated for the service in question. The justified interest results from our need for a technically perfect and fast presentation of our website and the relief of our IT infrastructure. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


We use:


Amazon Web Services - Cloudfront


We use the CDN service "Cloudfront" from Amazon Web Services. The company Amazon Web Services EMEA SARL ("AWS EU"), 38 Avenue John F. Kennedy, L-1855 Luxembourg, is responsible for personal data collected and processed via the offers of "Amazon Web Services". AWS EU is the authorised representative of Amazon Web Services Inc. ("AWS US"), 410 Terry Avenue North, Seattle WA 98109, United States.


Through your use of the Services, data will be transmitted to AWS EU and possibly from AWS EU to AWS US. The Amazon Group may process the transmitted data to create anonymous user profiles for statistical purposes. In principle, we have no influence on this data processing. AWS EU is therefore responsible for this data processing.


More information on the handling of user data can be found in the AWS EU Privacy Policy at https://aws.amazon.com/de/privacy/?nc1=f_pr.

Cloudflare


We use the CDN service of Cloudflare Inc. ("Cloudflare"), 101 Townsend St., San Francisco, California 94107, USA.


For more information on how we handle user data, please see Cloudflare's privacy policy: https://www.cloudflare.com/security-policy/.


NetDNA


We use the CDN service "Net DNA" of the company NetDNA LLC. This company belongs to StackPath LLC ("StackPath"), 2021 McKinney Ave., Suite 1100, Dallas, TX 75201, USA.


For more information about how StackPath handles user information, please see StackPath's Privacy Policy: https://www.stackpath.com/privacy-statement/

Cloud applications


Our website uses cloud based applications. Cloud-based applications are, for example, web shops that are provided for us by a third party provider on their servers. When you use these applications, the third party provider collects personal data which it can process on our behalf in accordance with our and its privacy policy.


Whenever you call up the application, general information is automatically transmitted from your browser to the server (so-called server log files). For more information, see above under "Server log files".


The legal basis for the use of cloud applications and the transmission of your data to them is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing), unless otherwise stated for the respective service. The justified interest results from our need for a technically perfect and fast presentation of our website and the relief of our IT infrastructure. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


We use:


Shopify


We use the cloud based shop system of the service provider Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland for hosting and presentation of the online shop. All data collected on our website is processed on Shopify's servers. As part of the above Shopify services, data may also be transferred for further processing to Shopify Inc, 150 Elgin ST, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc, Shopify Payments (USA) Inc or Shopify (USA) Inc. In the event that data is transferred to Shopify Inc. in Canada, an adequacy finding by the European Commission will ensure an adequate level of data protection.

For more information on Shopify's privacy policy, please visit: https://www.shopify.de/legal/datenschutz


Analyses Tools


We use certain services that record data from website visitors and make it available to us for analysis. We use this data to improve our website, our services and offers in a user-oriented manner. In particular, the following information on visitor behaviour may be collected: Your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed our website (so-called referrer), date and time of the request and possibly your Internet service provider, approximate origin (country and city), language, clicks on content and viewing time.


As long as no other legal basis is specified for the specific service, the legal basis for the use of analysis tools is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the person concerned). When you first call up the website, we will ask you for your consent to use the service by means of a superimposed information text. You can withdraw your consent at any time with effect for the future by deleting all cookies in your browser. You can find out how this works in your browser from the browser instructions.


We use:


Bugsnag


This website uses Bugsnag an analysis tool from Bugsnag Inc, 939 Harison Street, San Francicso, CA 94107, USA.


The tool is used to analyse errors on the website. The tool records, analyses and categorises errors and helps us to maintain the functionality of our website. In the event of an error, the following data (referrer, time of error, error, IP address) can be transmitted to Bugsnag in an anonymous form.

For more information on data protection at BugSnag, please click on the following link:

https://docs.bugsnag.com/legal/privacy-policy/


The legal basis for the use of Bugsnag is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing. The justified interest results from our interest in being able to offer you a technically flawlessly running and visually attractive website. Error analyses are indispensable in this respect. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact

details given in the imprint.


Shopify Analysis


We are using a service from Shopify International Limited, Victoria Buildings, 2nd floor, 1- 2 Haddington Road, Dublin 4, D04 XN32, Ireland to analyse the online shop.

For more information on the provider, please see above.


Newsletter Tracking


Our newsletter uses so-called web beacons or tracking pixels to analyse your reading behaviour. Counting pixels are extremely small image files which are integrated into the newsletter e-mail and thus allow a log file recording and log file analysis.


When you open the newsletter e-mail, the pixel-code is loaded from the server of the newsletter service and at the same time some information about you is transmitted, such as whether the e-mail has been opened, the time of access and the corresponding IP address.


In addition, links in the e-mail can provide information about which products are more interesting - i.e. which were clicked on more often than others.


Both the respective web beacon/counting pixel and the links in the email can be clearly assigned to the email address used for sending and thus allow a conclusion to the respective newsletter recipient.


Media services


We use certain services to fill and supplement our website with digital content. For this purpose, we usually use the integration functions of external platforms. This means that when the content is called up from the provider's server, data is transmitted to the provider and generally stored there, e.g. your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed the site (so-called referrer), the date and time of the request and possibly your Internet service provider. For more information, see above under "Server log files".


In general, the legal basis for the use of media services is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing), unless otherwise stated for the respective service. The legitimate interest results from our interest in being able to offer you a website that is attractive in terms of content and appearance. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


We use:


Google Fonts


Our website uses the service "Google Fonts" of the company Google. See the privacy policy above.


Vimeo


Our website uses the video service "Vimeo" from Vimeo Inc. ("Vimeo"), 555 West 18th Street, New York, New York 10011, USA. Vimeo is used to integrate videos into our website at various locations. When you access our website, which is equipped with a Vimeo plug-in, a connection is established to the Vimeo servers. During this process, information such as your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed our site (so-called referrer), the date and time of the request, and possibly your Internet service provider, is transmitted to Vimeo. Vimeo can also track your interactions with the plugin. If you have a Vimeo user account and are logged into it on the same terminal device, your visit to our website will be assigned to your user account. If you wish to avoid this, you can log out of your account before visiting our website and delete the cookies set by Vimeo.


In order to keep the transmission of personal data to Vimeo as low as possible, the video has been integrated in the so-called "Do Not Track" version.

You can object to the use of non-essential cookies by Vimeo by removing the tick at the bottom of the following page (opt-out): https://vimeo.com/cookie_policy.


For more information on how Vimeo handles user data, please refer to the Vimeo privacy policy at https://vimeo.com/privacy.


Service provider for processing your order


We may pass on the personal data collected from you to third parties within the framework of the contract implementation, for example to the transport company commissioned with the delivery or the service used for payment, insofar as this is necessary for the fulfilment of the contract.


The legal basis for the transmission of those data which are necessary for the processing of the order is Art. 6 para. 1 sentence 1 letter b) DSGVO (data processing for the fulfilment of a contract). The provision and transmission of your data is necessary, otherwise your order cannot be processed.


The legal basis for the data transfer voluntarily chosen by you in the ordering process (e.g. for shipping status by email) is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the person concerned). You can revoke your consent at any time with effect for the future. Please use the contact details given in the imprint for this purpose.


In detail we use the following service providers:


Apple Pay


We use the Apple Pay service of Apple Distribution International Ltd, Holyhill, Cork, Ireland, for payment processing.


To enable the processing of your payment, the data collected during the ordering process (name, first name, e-mail address, order, payment amount) is transmitted to Apple in encrypted form. After transmission, the data is again encrypted by Apple, so that only the transmitting website can access the payment method deposited with Apple Pay. After the payment has been made, Apple will send a specific transaction number to the submitting website.

Apple retains anonymised transaction information, including the approximate amount of the purchase, the approximate date and time, and whether the transaction was completed successfully. Apple uses this information to improve Apple Pay and other products and services.


For more information about Apple Pay's privacy policy, please visit:

https://support.apple.com/de-de/HT203027


DHL


If the goods are delivered by the transport service provider DHL Paket GmbH ("DHL"), Sträßchensweg 10, 53113 Bonn, Germany, we will pass on your name and address to DHL for the purpose of delivery.


You can find further information on data protection at DHL at: https://www.dhl.de/de/toolbar/footer/datenschutz.html


Klarna


We use the Klarna service of Klarna Bank AB, Sveavägen 46, 11134 Stockholm, Sweden, for payment processing. In order to enable the processing of the payment, your data (first and last name, street, house number, postcode, city, gender, e-mail address, telephone number and IP address) as well as data collected in connection with your order (invoice amount, delivery method, items) will be passed on to Klarna for the purpose of identity and credit assessment.



To which credit agencies your data can be passed on in this connection, you can find out here: https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies


For further information on data protection, please refer to Klarna's privacy policy:

https://www.klarna.com/de/datenschutz/


PayPal


We use the "PayPal Plus" service of PayPal (Europe) S.à.r.l. et Cie, S.C.A. ("PayPal"), 22-24 Boulevard Royal, L-2449 Luxembourg, for the processing of payments. This service allows us to offer you different payment methods in our webshop. By using our website, data is transmitted from our website to PayPal, in particular your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed our website (so-called referrer), the date and time of the request and possibly your internet service provider. In addition, the status and the amount of data transmitted in the context of this request are recorded.


Details of the data collected and information on how PayPal processes the data collected can be found in PayPal's Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE


We have a legitimate interest in the use of PayPal within the meaning of Art. 6 para. 1 sentence 1 letter f) DSGVO, which consists in offering a number of payment methods as simply as possible via a service provider and not having to commission a separate service provider for each payment method. This also reduces the number of recipients of your data.


In the case of payment via "PayPal via PayPal Plus", "Direct debit via PayPal Plus", "Credit card via PayPal Plus" or "PayPal Plus invoice", we also pass on your payment and order data to PayPal within the framework of the payment processing. PayPal reserves the right to carry out a credit check for the payment methods credit card and direct debit. PayPal uses the result of the credit assessment with regard to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values).


Insofar as score values are included in the result of the creditworthiness information, these are based on a scientifically recognised mathematical-statistical procedure. Among other things, address data are included in the calculation of the score values.


Further information on data protection, including information on the credit agencies used, can also be found in PayPal's data protection declaration: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE

Shopify Payments We use the service Shopify Payments, 3rd Floor, Europa House, Harcourt Building, Harcourt Street, Dublin 2


If you choose to pay via Shopify Payments, payment will be processed by Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
The following information about your order (name, address, account number, bank code, credit card number, invoice amount, etc.) is transmitted.

For further information on data protection, please also refer to the data protection declaration of Stripe Payments Europe Ltd:

https://www.shopify.de/legal/datenschutz


Instant bank transfer


We use the service "Sofort-Überweisung" of Sofort GmbH, Theresienhöhe 12 in 80339 Munich for payment processing. This service enables us to provide you with various payment methods in our webshop.
In this case the data is collected by Sofort GmbH. We do not store the data ourselves.


Sofort GmbH requires the IBAN as well as PIN and TAN of your online banking account. During the ordering process, you will be automatically forwarded to the secure payment form of Sofort GmbH. Immediately afterwards you will receive a confirmation of the transaction. Thereupon we receive the transfer credit directly.


Details about the data collected and information about how Sofort GmbH processes the data collected can be found in the notes of Sofort GmbH: https://www.klarna.com/sofort/



Other services



Beeclever


Our website uses the "GDPR Legal Cookie" service of beeclever GmbH, Universitätsstraße 3, 56070 Koblenz, Germany. This service enables us to obtain the legally compliant consent of the website visitor for the storage of not absolutely necessary data (cookies, local storage data, pixels) on his or her end device.


A banner is displayed to the website visitor by integrating a JavaScript code. The user can consent to certain processing (storage of cookies) by ticking the appropriate box. The banner can also be called up again via a button.

The data will only be stored on the user's terminal device after consent has been given.


For the functionality of the banner, data (IP address, referrer, browser information etc.) is transmitted to the servers of beeclever GmbH.

The legal basis for the use of the plugin is Art. 6 para. 1 p. 1 letter f) DSGVO (Justified interest in data processing). The justified interest results from our need to be able to offer you a legally compliant website. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint for this purpose.


CloudSearch


Our website uses the CloudSearch service of Qualiteam Software Ltd, Georgiou Katsounotou, 6, Limassol, 3036 Cyprus as a product filter.

This service enables us to offer you an attractive product search on our website. Through this, data is transmitted to the provider and usually stored there, e.g. your IP address, product and version information about the browser and operating system used (so-called user agent), the website from which you accessed our site (so-called referrer), the date and time of the request and possibly your Internet service provider.


Qualiteam Software Ltd. reserves the right to collect anonymous search statistics.

For more information about CloudSearch's privacy policy, please visit

https://cloudsearchapp.com/terms_of_service


The legal basis for the use of the plugin is Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). The justified interest results from our need to be able to offer you a search filter on our website in order to make the website more attractive for you and other potential customers. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


Social media fan pages


In addition to our website, we maintain online presences on social platforms in order to communicate with the customers, interested parties and users active there and to inform them about our services.


If you visit our presence on a social platform, your data is usually processed for our market research and advertising purposes by the respective provider of the platform. The provider may also process the data for its own purposes. User profiles can be created from your usage behaviour and the interests that arise from it. These user profiles can in turn be used, for example, to place advertisements within and outside the platforms that presumably correspond to your interests. For these purposes, cookies (see above) are usually stored on your end device, in which your usage behaviour and interests are saved. In particular, if you are a member of the respective platforms and are logged in to them, additional data may be stored independently in the user profiles. For a detailed presentation of the respective data processing and the possibilities of objection, we refer to the following linked information from the providers, as only they know the exact procedures of their data processing.


We point out that your data may also be processed outside the European Union. This can result in risks, because it could, for example, make it more difficult to enforce your rights.


The legal basis for the use of online presences and the associated data processing is generally Art. 6 para. 1 sentence 1 letter f) DSGVO (legitimate interest in data processing). The justified interest results from our need to present ourselves to visitors and users of social networks and to introduce statements of all kinds into the media and opinion market. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


The use of statistical data of all visitors to our social media websites, which are collected, processed and made available to us by the respective website operators, is based on Art. 6 Para. 1 S. 1 Letter f) DSGVO (legitimate interest in data processing). The justified interest results from our need for an anonymous evaluation of the visiting and usage behaviour on our websites in order to improve the use-oriented design of our online offer and to optimise our communication with interested parties. You can object to the processing of your data on the basis of our legitimate interest at any time under the conditions of Art. 21 DSGVO. Please use the contact details given in the imprint.


If you are asked by the respective providers for consent to data processing, the legal basis for processing is Art. 6 para. 1 sentence 1 letter a) DSGVO (consent of the data subject). You can revoke this consent at any time with effect for the future. To do so, please contact the provider who has asked you for your consent.


In the event that you wish to assert your above-mentioned rights, we would like to point out that, despite possible joint responsibility, these can be asserted most effectively with the providers. As a rule, only the providers have direct access to your data and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you can contact us and we will support you at any time within the scope of our possibilities.


We are represented on:


Facebook


Facebook is a social network operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Facebook Ireland Ltd is the European subsidiary of Facebook Inc, 1601 Willow Road, Menlo Park, California 94025, USA.


Further information on Facebook's privacy policy can be found at: https://www.facebook.com/about/privacy/. We inform you about our own data processing in this declaration.


We have concluded a supplementary agreement with Facebook as part of our usage contract, which regulates the responsibility for data processing with regard to the Page Insights function in accordance with Art. 26 DSGVO. The details of the agreement can be found here: https://www.facebook.com/legal/terms/page_controller_addendum.

In it, Facebook has undertaken, among other things, to inform you about the data processing within the framework of the Page Insights function. This information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data.


Instagram


Instagram is a social network of Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Facebook Ireland Ltd is the European subsidiary of Facebook Inc, 1601 Willow Road, Menlo Park, California 94025, USA.


For further information on data protection at Instagram, please visit: http://instagram.com/about/legal/privacy/.

For more information about Facebook's privacy policy, please visit: https://www.facebook.com/about/privacy/.


Vimeo


Vimeo is a social video platform of Vimeo Inc, 555 West 18th Street, New York, New York 10011, USA.

For more information on data protection at Vimeo, please visit: https://vimeo.com/de/features/video-privacy


Status of the privacy policy: 20.08.2020

Source: Süddeutsche Datenschutzgesellschaft mbH