This data protection declaration clarifies the type, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offer and the websites, functions and contents connected with it as well as external online presences, such as our Social Media Profile. (hereinafter jointly referred to as "online offer"). With regard to the terms used, e.g. "processing" or "responsible person", we refer to the definitions in Art. 4 of the Basic Data Protection Regulation (DSGVO).
Name/Fa.: INAKARB GmbH
Street No.: Bonner Straße 10
Postcode, City, Country: 53424 Rolandseck, Germany
Commercial Register/No.: Local Court Koblenz HRB 22840
Managing Director/Owner: Mr. David Manys
Phone number: +49 (0)2228 913 45 119
E-mail address: firstname.lastname@example.org
Data protection officer:
RR Law Office
Ernst-Ludwig-Str. 48, 68623 Lampertheim
Tel.: 06206 - 1566986
Fax.: 06206 - 1566987
types of data processed:
- inventory data (e.g., names, addresses).
- contact data (e.g., e-mail, telephone numbers).
- content data (e.g., text input, photographs, videos).
- Contract data (e.g., subject matter of contract, duration, customer category).
- Payment data (e.g., bank details, payment history).
- Usage data (e.g., websites visited, interest in content, access times).
- Meta/communication data (e.g., device information, IP addresses).
Processing of special categories of data (Art. 9 para. 1 DPA):
No special categories of data are processed.
categories of data subjects concerned by the processing operation:
- Customers, interested parties, visitors and users of the online offer, business partners.
- visitors and users of the online offer.
In the following we refer to the persons concerned collectively as "users".
Purpose of the processing:
- Provision of the online offer, its contents and shop functions.
- Provision of contractual services, service and customer care.
- Replying to contact requests and communication with users.
- Marketing, advertising and market research.
- Security measures.
1. terms used
1.1. personal data shall mean any information relating to an identified or identifiable natural person (hereinafter referred to as 'data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, a location data, an online identifier (e.g. a cookie) or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
1.2 'processing' means any operation or set of operations which is performed upon personal data, whether or not by automatic means The term is broad and covers virtually all data handling.
1.3 'controller' shall mean the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data
2.decisive legal bases
In accordance with Art. 13 DSGVO we inform you about the legal bases of our data processing. If the legal basis is not stated in the data protection declaration, the following applies: The legal basis for obtaining consent is Art. 6 Para. 1 lit. a and Art. 7 DSGVO, the legal basis for processing for the purpose of fulfilling our services and implementing contractual measures and answering enquiries is Art. 6 Para. 1 lit. b DSGVO, the legal basis for processing for the purpose of fulfilling our legal obligations is Art. 6 Para. 1 lit. c DSGVO, and the legal basis for processing for the purpose of safeguarding our legitimate interests is Art. 6 Para. 1 lit. f DSGVO. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6 paragraph 1 letter d DSGVO serves as the legal basis.
4. security measures
4.1. we take the following measures in accordance with Art. 32 DSGVO, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the varying probability of occurrence and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection commensurate with the risk; the measures include in particular securing the confidentiality, integrity and availability of data by controlling the physical access to the data as well as the access, input, transmission, securing of availability and its separation. Furthermore, we have established procedures to ensure that data subjects' rights are exercised, data is deleted, and we respond to any threats to the data. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by designing technology and by using data protection-friendly default settings (Art. 25 DSGVO).
4.2 Security measures include in particular the encrypted transmission of data between your browser and our server.
5 Disclosure and transmission of data
5.1 If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transmit it to them or otherwise grant them access to the data, this is only done on the basis of a legal authorisation (e.g. if a transmission of the data to third parties, such as payment service providers, in accordance with Art. 6 para. 1 lit. b DSGVO is necessary for the fulfilment of the contract), you have consented to this, a legal obligation provides for this or on the basis of our legitimate interests (e.g. when using agents, hosting providers, tax, business and legal advisors, customer care, accounting, billing and similar services that allow us to fulfil our contractual obligations, administrative tasks and duties efficiently and effectively).
5.2 If we commission third parties to process data on the basis of a so-called "contract processing agreement", this is done on the basis of Art. 28 DSGVO.
6. transfers to third countries
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this is done in the context of using the services of third parties or disclosure or transfer of data to third parties, this will only take place if it is done to fulfil our (pre-)contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests. Subject to legal or contractual permissions, we will only process or transfer the data in a third country if the special requirements of Art. 44 ff. DSGVO. This means that the processing is carried out, for example, on the basis of special guarantees, such as the officially recognised determination of a level of data protection corresponding to that of the EU (e.g. for the USA through the "Privacy Shield") or compliance with officially recognised special contractual obligations (so-called "standard contractual clauses").
7. the rights of the data subjects
7.1. you have the right to obtain confirmation as to whether or not data in question is being processed and to obtain information about this data and to receive further information and a copy of the data in accordance with art. 15 of the Data Protection Act.
7.2. you have accordingly. Art. 16 DSGVO the right to request the completion of data concerning you or the correction of incorrect data concerning you.
7.3 In accordance with Art. 17 DSGVO, you have the right to demand that the data in question be deleted immediately, or alternatively, in accordance with Art. 18 DSGVO, to demand a restriction on the processing of the data.
7.4 You have the right to request that the data concerning you which you have provided us with be made available to us in accordance with art. 20 of the DSGVO and to request that it be communicated to other persons responsible.
7.5 You also have the right to lodge a complaint with the competent supervisory authority pursuant to Art. 77 DSGVO.
8. right of revocation
You have the right to revoke consents granted in accordance with Art. 7 para. 3 DSGVO with effect for the future.
9. right of objection
You can object to the future processing of data concerning you in accordance with Art. 21 DSGVO at any time. The objection may in particular be made against processing for the purposes of direct advertising.
10. cookies and right of objection for direct advertising
10.1. cookies are small files that are stored on the user's computer. Different information can be stored within the cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after his visit within an online offer. Temporary cookies, or "session cookies" or "transient cookies", are cookies that are deleted after a user leaves an online offer and closes his browser. In such a cookie, for example, the contents of a shopping cart in an online shop or a login status can be stored. Cookies are described as "permanent" or "persistent" if they remain stored even after the browser is closed. For example, the login status can be saved if the user visits it after several days. Likewise, the interests of the users can be stored in such a cookie, which are used for range measurement or marketing purposes. Third party cookies" are cookies from providers other than the person responsible for operating the online service (otherwise, if it is only their cookies, it is called "first-party cookies").
If users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in the system settings of their browser. Stored cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer.
11. Deletion of data
11.1. The data processed by us will be deleted or limited in their processing in accordance with articles 17 and 18 of the DSGVO Unless expressly stated in this data protection declaration, the data stored by us will be deleted as soon as they are no longer required for their intended purpose and the deletion does not conflict with any statutory storage obligations. If the data are not deleted because they are required for other and legally permissible purposes, their processing is restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
11.2 Germany: In accordance with legal requirements, the storage is in particular for 6 years in accordance with § 257 para. 1 HGB (commercial books, inventories, opening balance sheets, annual financial statements, commercial letters, accounting vouchers, etc.) and for 10 years in accordance with § 147 para. 1 AO (books, records, management reports, accounting vouchers, commercial and business letters, documents relevant for taxation, etc.)
11.3. Austria: According to legal requirements, the storage takes place in particular for 7 J according to § 132 para. 1 BAO (accounting documents, vouchers / invoices, accounts, records, business documents, statement of income and expenditure, etc.), for 22 years in connection with real estate and for 10 years for documents in connection with electronically provided services, telecommunications, radio and television services which are provided to non-entrepreneurs in EU member states and for which the Mini-One-Stop-Shop (MOSS) is used.
12. order processing in the online shop and customer account
12.1. we process the data of our customers within the scope of the order processes in our online shop, in order to enable them to select and order the selected products and services, as well as their payment and delivery, or execution.
12.2 The processed data includes inventory data, communication data, contract data, payment data and, with regard to the persons concerned, our customers, interested parties and other business partners. The processing is carried out for the purpose of providing contractual services in the context of operating an online shop, billing, delivery and customer services. We use session cookies to store the contents of the shopping cart and permanent cookies to store the login status.
12.3 Processing shall be carried out on the basis of Art. 6 para. 1 lit. b (execution of order processes) and c (legally required archiving) DSGVO. In this context, the information marked as required is required for the establishment and fulfilment of the contract. We disclose the data to third parties only within the scope of delivery, payment or within the scope of the legal permits and obligations to legal advisors and authorities. The data will only be processed in third countries if this is necessary for the fulfilment of the contract (e.g. on customer request for delivery or payment).
12.4 Users can optionally create a user account, in particular by viewing their orders. During the registration process, the required mandatory data will be provided to the users. The user accounts are not public and cannot be indexed by search engines. If users have terminated their user account, their data will be deleted with regard to the user account, subject to their safekeeping is necessary for reasons of commercial or tax law in accordance with Art. 6 Para. 1 lit. c DSGVO. Data in the customer account will remain until its deletion with subsequent archiving in case of a legal obligation. It is the responsibility of the users to save their data in case of termination before the end of the contract.
12.5 Within the scope of registration and renewed logins and use of our online services, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as the user's need for protection against misuse and other unauthorized use. As a matter of principle, this data is not passed on to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Art. 6 Para. 1 lit. c DSGVO.
12.6 Deletion takes place after expiry of statutory warranty and comparable obligations, the necessity of data storage is reviewed every three years; in the case of statutory archiving obligations, deletion takes place after expiry (end of commercial law (6 years) and tax law (10 years) storage obligation); data in the customer account remain until its deletion.
13. business management analyses and market research
13.1. in order to run our business economically, to identify market trends, customer and user wishes, we analyse the data available to us on business transactions, contracts, enquiries, etc. We process inventory data, communication data, contract data, payment data, usage data, meta data on the basis of Art. 6 para. 1 lit. f. DSGVO, whereby the persons concerned include customers, interested parties, business partners, visitors and users of the online offer. The analyses are carried out for the purpose of business management evaluations, marketing and market research. In doing so, we can take into account the profiles of the registered users with information, e.g. on their purchase transactions. The analyses serve us to increase user-friendliness, to optimise our offer and business efficiency. The analyses serve only us and are not disclosed externally, unless they are anonymous analyses with summarized values.
13.2 If these analyses or profiles are personal, they will be deleted or made anonymous upon termination by the user, otherwise after two years from conclusion of the contract. In all other respects, the macroeconomic analyses and general trend determinations are prepared anonymously wherever possible.
2. the creditworthiness of a customer may be checked if there is otherwise a risk of non-payment, i.e. if the goods are delivered without payment having been received (i.e. if the customer chooses to buy on account). On the other hand, there is no risk of non-payment if the customer chooses, for example, the prepayment option or makes the payment via third-party providers such as Paypal.
It should also be noted that obtaining automatic creditworthiness information constitutes an "automated decision in individual cases" pursuant to Art. 22 DSGVO, i.e. a legal decision without human involvement. This is permissible if the customer has consented or if this decision is necessary for the conclusion of the contract. Whether the decision is necessary has not yet been conclusively clarified, but is often taken as given, even by the author of this sample. However, if you wish to exclude any risk, you should obtain consent.
Consent is also necessary if the credit rating information is already being used to decide whether the option "on account" should be shown at all. This is because it could have been that the customer would have decided for prepayment or Paypal anyway and the credit check would not have been necessary.
Such consent could, for example, be as follows:
14. creditworthiness information
14.1. if we make advance payments (e.g. when purchasing on account), we reserve the right to obtain identity and creditworthiness information for the purpose of assessing the credit risk on the basis of mathematical-statistical procedures from service companies specialising in this area (credit agencies) in order to safeguard legitimate interests.
14.2 Within the scope of the credit information, we transmit the following personal data of the customer (name, postal address, date of birth, details of the type of contract, bank details [Please provide further data if necessary]) to the following credit agencies:
[Please provide the credit agencies here, e.g.:] SCHUFA-Gesellschaft (SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden), data protection information: https://www.schufa.de/de/ueber-uns/daten-scoring/.
14.3 We process the information received from credit agencies on the statistical probability of a payment default within the scope of a proper discretionary decision on the establishment, execution and termination of the contractual relationship. We reserve the right to refuse payment on account or any other advance payment in the event of a negative result of the credit assessment.
14.4 The decision as to whether we will make advance payment is made in accordance with Art. 22 DSGVO solely on the basis of an automated decision in the individual case, which our software makes on the basis of information from the credit agency.
14.5 If we obtain your express consent, the legal basis for credit information and the transmission of the customer's data to the credit agencies is the consent pursuant to Art. 6 para. 1 lit. a, 7 DSGVO. If consent is not obtained, our justified interests in the security of your payment claim are the legal basis in accordance with Art. 6 Para. 1 lit. f. DSGVO.
15. contacting and customer service
15.1. when contacting us (via contact form or e-mail) the user's details are processed for the purpose of handling the contact request and its processing in accordance with Art. 6 Para. 1 lit. b) DSGVO.
15.2. Die Angaben der Nutzer können in unserem Customer-Relationship-Management System (“CRM System”) oder vergleichbarer Anfragenorganisation gespeichert werden.
15.3 We delete the requests if they are no longer necessary. We review the necessity every two years; we permanently store inquiries from customers who have a customer account and refer to the information on the customer account for deletion. Furthermore, the statutory archiving obligations apply.
16. Collection of access data and log files
16.1. We collect data on the basis of our legitimate interests within the meaning of Article 6 Paragraph 1 lit. f. DSGVO, we collect data on every access to the server on which this service is located (so-called server log files). The access data includes the name of the accessed website, file, date and time of access, transferred data volume, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited site), IP address and the requesting provider.
16.2 For security reasons (e.g. for the investigation of abuse or fraud), log file information is stored for a maximum period of seven days and then deleted. Data whose further storage is required for evidential purposes are excluded from deletion until the respective incident has been finally clarified.
17. online presences in social media
17.1. we maintain on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f. DSGVO, we maintain online presences within social networks and platforms in order to be able to communicate with customers, interested parties and users active there and to inform them about our services. When calling up the respective networks and platforms, the terms and conditions and data processing guidelines of their respective operators apply.
17.2 Unless otherwise stated in our data protection declaration, we process the data of users if they communicate with us within social networks and platforms, e.g. write articles on our online presences or send us messages.
If the "Remarketing" or "Google Analytics Audiences" functions are used, the following passage must be added to these functions as a second point:
17.2 We use Google Analytics in order to display the advertisements placed within the advertising services of Google and its partners only to those users who have also shown an interest in our online offer or who exhibit certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited) which we transmit to Google (so-called "remarketing" or "Google Analytics Audiences"). With the help of remarketing audiences, we also want to ensure that our advertisements correspond to the potential interest of the users and do not appear annoying.
18. Google Analytics
18.2 Google is certified under the Privacy Shield Agreement and thereby offers a guarantee to comply with European data protection law(https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
18.3 Google will use this information on our behalf in order to evaluate the use of our website by users, to compile reports on the activities within this website and to provide us with further services associated with the use of this website and the use of the Internet. In doing so, pseudonymous user profiles of the users can be created from the processed data.
18.4 We only use Google Analytics with activated IP anonymisation. This means that the IP address of users is shortened by Google within member states of the European Union or in other states that are party to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there.
18.5 The IP address transmitted by the user's browser is not merged with other data from Google. Users can prevent the storage of cookies by adjusting their browser software accordingly; users can also prevent the collection of data generated by the cookie and related to their use of the online offer to Google and the processing of this data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
18.6 Further information on Google's use of data, setting and objection options can be found on Google's websites: https://www.google.com/intl/de/policies/privacy/partners ("Data use by Google when you use the websites or apps of our partners"), https://policies.google.com/technologies/ads ("Data use for advertising purposes"), https://adssettings.google.com/authenticated ("Manage information that Google uses to show you advertising").
19.1. we use on the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offer in the sense of Art. 6 para. 1 lit. f. DSGVO) the marketing and remarketing services (in short "Google Marketing Services") of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, ("Google").
19.2 Google is certified under the Privacy Shield Agreement and thus offers a guarantee that it complies with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
19.3. Die Google-Marketing-Services erlauben uns Werbeanzeigen für und auf unserer Website gezielter anzuzeigen, um Nutzern nur Anzeigen zu präsentieren, die potentiell deren Interessen entsprechen. Falls einem Nutzer z.B. Anzeigen für Produkte angezeigt werden, für die er sich auf anderen Webseiten interessiert hat, spricht man hierbei vom „Remarketing“. Zu diesen Zwecken wird bei Aufruf unserer und anderer Webseiten, auf denen Google-Marketing-Services aktiv sind, unmittelbar durch Google ein Code von Google ausgeführt und es werden sog. (Re)marketing-Tags (unsichtbare Grafiken oder Code, auch als “Web Beacons” bezeichnet) in die Webseite eingebunden. Mit deren Hilfe wird auf dem Gerät der Nutzer ein individuelles Cookie, d.h. eine kleine Datei abgespeichert (statt Cookies können auch vergleichbare Technologien verwendet werden). Die Cookies können von verschiedenen Domains gesetzt werden, unter anderem von google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com oder googleadservices.com. In dieser Datei wird vermerkt, welche Webseiten der Nutzer aufgesucht, für welche Inhalte er sich interessiert und welche Angebote er geklickt hat, ferner technische Informationen zum Browser und Betriebssystem, verweisende Webseiten, Besuchszeit sowie weitere Angaben zur Nutzung des Onlineangebotes. Es wird ebenfalls die IP-Adresse der Nutzer erfasst, wobei wir im Rahmen von Google-Analytics mitteilen, dass die IP-Adresse innerhalb von Mitgliedstaaten der Europäischen Union oder in anderen Vertragsstaaten des Abkommens über den Europäischen Wirtschaftsraum gekürzt und nur in Ausnahmefällen ganz an einen Server von Google in den USA übertragen und dort gekürzt wird. Die IP-Adresse wird nicht mit Daten des Nutzers innerhalb von anderen Angeboten von Google zusammengeführt. Die vorstehend genannten Informationen können seitens Google auch mit solchen Informationen aus anderen Quellen verbunden werden. Wenn der Nutzer anschließend andere Webseiten besucht, können ihm entsprechend seiner Interessen die auf ihn abgestimmten Anzeigen angezeigt werden.
19.4 The data of the users are processed pseudonymously within the framework of the Google marketing services. This means that Google does not store and process e.g. the name or e-mail address of the users, but processes the relevant data cookie-related within pseudonymous user profiles. I.e. from Google's point of view, the ads are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymisation. The information collected by Google marketing services about users is transmitted to Google and stored on Google's servers in the USA.
19.5 The Google marketing services we use include the online advertising program "Google AdWords". In the case of Google AdWords, each AdWords customer receives a different "conversion cookie". Cookies can therefore not be tracked through the websites of AdWords customers. The information collected through the cookie is used to compile conversion statistics for AdWords customers who have opted in to conversion tracking. AdWords advertisers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
19.6. Wir können auf Grundlage des Google-Marketing-Services “DoubleClick” Werbeanzeigen Dritter einbinden. DoubleClick verwendet Cookies, mit denen Google und seinen Partner-Websites, die Schaltung von Anzeigen auf Basis der Besuche von Nutzern auf dieser Website bzw. anderen Websites im Internet ermöglicht wird.
19.8. Ebenfalls können wir den Dienst „Google Optimizer“ einsetzen. Google Optimizer erlaubt uns im Rahmen so genannten “A/B-Testings” nachzuvollziehen, wie sich verschiedene Änderungen einer Website auswirken (z.B. Veränderungen der Eingabefelder, des Designs, etc.). Für diese Testzwecke werden Cookies auf den Geräten der Nutzer abgelegt. Dabei werden nur pseudonyme Daten der Nutzer verarbeitet.
19.9. Ferner können wir den “Google Tag Manager” einsetzen, um die Google Analyse- und Marketing-Dienste in unsere Website einzubinden und zu verwalten.
19.11. If you wish to opt-out of interest-based advertising through Google marketing services, you can use the setting and opt-out options provided by Google: https://adssettings.google.com/authenticated.
Furthermore, when using the Facebook pixel, we use the additional function "extended matching" (here, data such as telephone numbers, email addresses or Facebook IDs of users) to create target groups ("custom audiences" or "look like audiences") and send them to Facebook (encrypted). Further notes on "extended matching ": https://www.facebook.com/business/help/611774685654668).
We also use the "Custom Audiences from File" method of the social network Facebook, Inc. In this case, the email addresses of the newsletter recipients are uploaded to Facebook. The upload process is encrypted. The upload is only used to determine recipients of our Facebook ads. We want to ensure that the ads are only displayed to users who have an interest in our information and services.
Please include the following addition in case of your own opt-out:
Um die Erfassung Ihrer Daten mittels des Facebook-Pixels auf unserer Webseite zu verhindern, klicken Sie bitten den folgenden Link: Facebook-Opt-Out Hinweis: Wenn Sie den Link klicken, wird ein „Opt-Out“-Cookie auf Ihrem Gerät gespeichert. Wenn Sie die Cookies in diesem Browser löschen, dann müssen Sie den Link erneut klicken. Ferner gilt das Opt-Out nur innerhalb des von Ihnen verwendeten Browsers und nur innerhalb unserer Webdomain, auf der der Link geklickt wurde.
20. Facebook-, Custom Audiences und Facebook-Marketing-Dienste
20.1. Innerhalb unseres Onlineangebotes wird aufgrund unserer berechtigten Interessen an Analyse, Optimierung und wirtschaftlichem Betrieb unseres Onlineangebotes und zu diesen Zwecken das sog. “Facebook-Pixel” des sozialen Netzwerkes Facebook, welches von der Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, bzw. falls Sie in der EU ansässig sind, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland betrieben wird (“Facebook”), eingesetzt.
20.2 Facebook is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
20.3. Mit Hilfe des Facebook-Pixels ist es Facebook zum einen möglich, die Besucher unseres Onlineangebotes als Zielgruppe für die Darstellung von Anzeigen (sog. “Facebook-Ads”) zu bestimmen. Dementsprechend setzen wir das Facebook-Pixel ein, um die durch uns geschalteten Facebook-Ads nur solchen Facebook-Nutzern anzuzeigen, die auch ein Interesse an unserem Onlineangebot gezeigt haben oder die bestimmte Merkmale (z.B. Interessen an bestimmten Themen oder Produkten, die anhand der besuchten Webseiten bestimmt werden) aufweisen, die wir an Facebook übermitteln (sog. „Custom Audiences“). Mit Hilfe des Facebook-Pixels möchten wir auch sicherstellen, dass unsere Facebook-Ads dem potentiellen Interesse der Nutzer entsprechen und nicht belästigend wirken. Mit Hilfe des Facebook-Pixels können wir ferner die Wirksamkeit der Facebook-Werbeanzeigen für statistische und Marktforschungszwecke nachvollziehen, in dem wir sehen ob Nutzer nachdem Klick auf eine Facebook-Werbeanzeige auf unsere Website weitergeleitet wurden (sog. „Conversion“).
20.4 The processing of data by Facebook is carried out within the framework of Facebook's Data Use Policy. Accordingly, general information on the presentation of Facebook Ads, in the Facebook Data Usage Policy: https://www.facebook.com/policy.php. Specific information and details about the Facebook pixel and its functionality can be found in the Facebook help section: https://www.facebook.com/business/help/651294705016616.
20.5 You may object to the collection by the Facebook Pixel and use of your data to display Facebook Ads. To control what types of ads are displayed to you within Facebook, you can go to the page set up by Facebook and follow the instructions for usage-based advertising settings: https://www.facebook.com/settings?tab=ads. The settings are platform-independent, which means they apply to all devices, such as desktop computers or mobile devices.
21. Facebook Social Plugins
21.1. Wir nutzen auf Grundlage unserer berechtigten Interessen (d.h. Interesse an der Analyse, Optimierung und wirtschaftlichem Betrieb unseres Onlineangebotes im Sinne des Art. 6 Abs. 1 lit. f. DSGVO) Social Plugins (“Plugins”) des sozialen Netzwerkes facebook.com, welches von der Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland betrieben wird (“Facebook”). Die Plugins können Interaktionselemente oder Inhalte (z.B. Videos, Grafiken oder Textbeiträge) darstellen und sind an einem der Facebook Logos erkennbar (weißes „f“ auf blauer Kachel, den Begriffen “Like”, “Gefällt mir” oder einem „Daumen hoch“-Zeichen) oder sind mit dem Zusatz “Facebook Social Plugin” gekennzeichnet. Die Liste und das Aussehen der Facebook Social Plugins kann hier eingesehen werden: https://developers.facebook.com/docs/plugins/.
21.2 Facebook is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
21.3 If a user calls up a function of this online offer that contains such a plugin, his device establishes a direct connection with the Facebook servers. The content of the plugin is transmitted by Facebook directly to the user's device and integrated into the online offer by the user. User profiles can be created from the processed data. We therefore have no influence on the scope of the data that Facebook collects with the help of this plugin and therefore inform the users according to our state of knowledge.
21.4 By integrating the plugins, Facebook receives the information that a user has called up the corresponding page of the online offer. If the user is logged in to Facebook, Facebook can assign the visit to his or her Facebook account. If users interact with the plugins, for example, by pressing the Like button or making a comment, the corresponding information is transmitted directly from your device to Facebook and stored there. If a user is not a member of Facebook, it is still possible for Facebook to find out his or her IP address and store it. According to Facebook, only an anonymized IP address is stored in Germany.
21.6 If a user is a Facebook member and does not want Facebook to collect data about him or her via this online offer and link it to his or her membership data stored on Facebook, he or she must log out of Facebook and delete his or her cookies before using our online offer. Further settings and objections to the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US-American page http://www.aboutads.info/choices/ or the EU page http://www.youronlinechoices.com/. The settings are platform-independent, i.e. they are adopted for all devices, such as desktop computers or mobile devices.
22nd Reach Analysis with Matomo
22.1. Within the scope of the reach analysis of Matomo, based on our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer in the sense of Art. 6 Par. 1 lit. f. DSGVO) the following data are processed: the type and version of browser you use, the operating system you use, your country of origin, date and time of the server request, the number of visits, your time spent on the website and the external links you have activated. The IP address of the user is made anonymous before it is saved.
22.3 Users can object to the anonymous data collection by the Matomo program at any time with effect for the future by clicking on the link below. In this case a so-called opt-out cookie is stored in their browser, which has the consequence that Matomo no longer collects any session data. If users delete their cookies, however, this has the consequence that the opt-out cookie is also deleted and therefore must be reactivated by the users.
22.4 [Please use Matomo's IFRAME with the opt-out cookie at this point (and switch on IP anonymization in the settings area)].
23. Jetpack (WordPress Stats)
23.1. We use on the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f. DSGVO) the Jetpack plugin (here the sub-function "Wordpress Stats"), which integrates a tool for the statistical evaluation of visitor access and is provided by Automattic, Inc. 132 Hawthorne Street San Francisco, CA 94107, USA. Jetpack uses so-called "cookies", text files which are stored on your computer and which enable an analysis of your use of the website.
23.2 Automattic is certified under the Privacy Shield Agreement and thereby provides a guarantee of compliance with European data protection law(https://www.privacyshield.gov/participant?id=a2zt0000000CbqcAAC&status=Active).
24.1. On the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offer within the meaning of Art. 6 Para. 1 lit. f. DSGVO), we use the "etracker" analysis service of etracker GmbH, Erste Brunnenstraße 1 20459 Hamburg.
24.2 The data processed by etracker can be used to create user profiles under a pseudonym. Cookies can be used for this purpose. The cookies make it possible to recognize your browser. The data collected using etracker technologies will not be used to personally identify visitors to our website without the separately granted consent of the person concerned and will not be merged with personal data about the bearer of the pseudonym. Furthermore, the personal data is only processed for us, i.e. it is not merged with personal data collected within other online offers.
24.3 You can object to the collection and storage of data at any time with effect for the future. In order to object to the future collection and storage of your visitor data, you can obtain an opt-out cookie from etracker using the following link. This will ensure that no visitor data from your browser will be collected and stored by etracker in the future: http://www.etracker.de/privacy?et=Account-ID [Please enter your account ID here].
24.4. Durch das Opt-Out wird ein Opt-Out-Cookie mit dem Namen “cntcookie” von etracker gesetzt. Bitte löschen dieses Cookie nicht, solange Sie Ihren Widerspruch aufrechterhalten möchten. Weitere Informationen finden Sie in den Datenschutzbestimmungen von etracker: http://www.etracker.com/de/datenschutz.html.
27. Communication via mail, e-mail, fax or telephone
27.1 We use remote communication media, such as mail, telephone or e-mail, for business and marketing purposes. We process inventory data, address and contact data as well as contract data of customers, participants, interested parties and communication partners.
27.2 The processing is based on Art. 6 para. 1 letter a, Art. 7 DSGVO, Art. 6 para. 1 letter f DSGVO in connection with legal requirements for advertising communications. Contact will only be established with the consent of the contact partners or within the scope of the legal permissions and the processed data will be deleted as soon as they are not required and otherwise with objection/ revocation or discontinuation of the basis of entitlement or legal archiving obligations.
Note: Please indicate the contents of the newsletter and the evaluation of the opening and clicking behaviour already during the registration, i.e. in the registration form, e.g:
If you use a shipping service provider, you will need to complete information on them and can use these examples as a guide (use of one EU service provider and one from a third country):
Dispatch service provider: The dispatch of the newsletter is carried out by CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany, hereinafter referred to as "shipping service provider". You can view the data protection regulations of the mail-order service provider here: https://www.cleverreach.com/de/datenschutz/.
Dispatch service provider: Newsletters are sent via "MailChimp", a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. The data protection regulations of the mail service provider can be viewed here: https://mailchimp.com/legal/privacy/. The Rocket Science Group LLC d/b/a MailChimp is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with the European level of data protection (https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active).
Note on the legal basis: Please select the variant for Germany or Austria in the information on the legal basis.
Bitte Please note that in Austria, due to a provision of the E-Commerce Act (ECG), the so-called "ECG list" must be taken into account. This list is maintained by the Austrian Regulatory Authority for Telecommunications and Broadcasting (RTR-GmbH): https://www.rtr.at/de/tk/TKKS_Spam. It contains those e-mail addresses to which e-mails may not be sent.
28.1. With the following notes, we would like to inform you about the contents of our newsletter as well as the registration, dispatch and statistical evaluation procedures and your rights of objection. By subscribing to our newsletter, you agree to receive it and to the described procedures.
28.2 Content of the newsletter: We send newsletters, e-mails and other electronic notifications containing advertising information (hereinafter "newsletters") only with the consent of the recipients or a legal permission. Insofar as the contents of the newsletter are specifically described in the context of a registration for the newsletter, they are decisive for the consent of the users. Furthermore, our newsletters contain information about our products, offers, promotions and our company.
28.3 Double-Opt-In and logging: The registration for our newsletter is done in a so-called Double-Opt-In procedure. This means that after registration you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that nobody can register with foreign e-mail addresses. The newsletter registrations are logged in order to be able to prove the registration process according to the legal requirements. This includes the storage of the registration and confirmation time as well as the IP address. Changes to your data stored by the shipping service provider are also logged.
28.4. dispatch service provider: Newsletters are sent by "MailChimp", a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. The data protection regulations of the mail service provider can be viewed here: https://mailchimp.com/legal/privacy/. The Rocket Science Group LLC d/b/a MailChimp is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with the European level of data protection (https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active).
28.5 If we use a dispatch service provider, the dispatch service provider may, according to its own information, use this data in pseudonymous form, i.e. without allocation to a user, to optimise or improve its own services, e.g. for technical optimisation of dispatch and presentation of the newsletter or for statistical purposes to determine from which countries the recipients come. However, the dispatch service provider does not use the data of our newsletter recipients to write to them itself or pass them on to third parties.
28.6. registration data: To subscribe to the newsletter, it is sufficient to enter your e-mail address. Optionally, we ask you to enter a name in order to address you personally in the newsletter.
28.7 Success measurement - The newsletters contain a so-called "web-beacon", i.e. a pixel-sized file which is retrieved from our server when the newsletter is opened, or from the server of a mailing service provider if we use one. Within the scope of this retrieval, technical information such as information on the browser and your system, as well as your IP address and time of retrieval are initially collected. This information is used for the technical improvement of the services based on the technical data or the target groups and their reading behaviour based on their retrieval locations (which can be determined by means of the IP address) or the access times. Statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our intention nor, if used, that of the dispatch service provider to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
28.8. Germany: The dispatch of the newsletter and the measurement of success are based on the consent of the recipients in accordance with Art. 6 Para. 1 lit. a, Art. 7 DSGVO in conjunction with § 7 Para. 2 No. 3 UWG or on the basis of the legal permission in accordance with § 7 Para. 3 UWG.
28.9. Austria: The dispatch of the newsletter and the measurement of success are based on the consent of the recipients pursuant to Art. 6 Par. 1 lit. a, Art. 7 DSGVO in connection with § 107 Par. 2 TKG or on the basis of the legal permission pursuant to § 107 Par. 2 and 3 TKG.
28.10. The logging of the registration procedure is based on our legitimate interests in accordance with Art. 6 Para. 1 letter f DSGVO and serves as proof of consent to receive the newsletter.
28.11. Newsletter recipients can cancel the receipt of our newsletter at any time, i.e. revoke their consent. A link to cancel the newsletter can be found at the end of each newsletter. At the same time, their consent to the performance measurement expires. A separate revocation of the performance measurement is unfortunately not possible, in which case the entire newsletter subscription must be cancelled. When you unsubscribe from the newsletter, your personal data will be deleted, unless their storage is legally required or justified, in which case their processing will be limited to these exceptional purposes only. In particular, we may store the unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before we delete them for the purpose of sending the newsletter, in order to be able to prove that we have previously given our consent. The processing of this data is limited to the purpose of a possible defence against claims. An individual request for deletion is possible at any time, provided that the former existence of a consent is confirmed at the same time.
29. Einbindung von Diensten und Inhalten Dritter
29.1. Wir setzen innerhalb unseres Onlineangebotes auf Grundlage unserer berechtigten Interessen (d.h. Interesse an der Analyse, Optimierung und wirtschaftlichem Betrieb unseres Onlineangebotes im Sinne des Art. 6 Abs. 1 lit. f. DSGVO) Inhalts- oder Serviceangebote von Drittanbietern ein, um deren Inhalte und Services, wie z.B. Videos oder Schriftarten einzubinden (nachfolgend einheitlich bezeichnet als “Inhalte”). Dies setzt immer voraus, dass die Drittanbieter dieser Inhalte, die IP-Adresse der Nutzer wahrnehmen, da sie ohne die IP-Adresse die Inhalte nicht an deren Browser senden könnten. Die IP-Adresse ist damit für die Darstellung dieser Inhalte erforderlich. Wir bemühen uns nur solche Inhalte zu verwenden, deren jeweilige Anbieter die IP-Adresse lediglich zur Auslieferung der Inhalte verwenden. Drittanbieter können ferner so genannte Pixel-Tags (unsichtbare Grafiken, auch als “Web Beacons” bezeichnet) für statistische oder Marketingzwecke verwenden. Durch die “Pixel-Tags” können Informationen, wie der Besucherverkehr auf den Seiten dieser Website ausgewertet werden. Die pseudonymen Informationen können ferner in Cookies auf dem Gerät der Nutzer gespeichert werden und unter anderem technische Informationen zum Browser und Betriebssystem, verweisende Webseiten, Besuchszeit sowie weitere Angaben zur Nutzung unseres Onlineangebotes enthalten, als auch mit solchen Informationen aus anderen Quellen verbunden werden können.
29.2. the following presentation offers an overview of third party providers and their contents, including links to their privacy policies, which contain further information on the processing of data and, in some cases already mentioned here, the possibility to object (so-called opt-out)
We use technology from eKomi Ltd., Markgrafenstraße 11, 10969 Berlin ("eKomi") for the purposes of suppliers–and product reviews by our customers and for our own quality management. Therefore hawe will use this waya Evaluation software from eKomi integrated. Via this evaluation software you can Sie,after we have rendered our servicesn,an anonymous assessment of the experience with us. You can object to the use of your data for the sending of this mail at any time contradict. Address your objection email@example.com. For this technical implementation, an agreement on order processing with eKomi. eKomi takes over all organizational and technical Measures to Protection this Data. According to the legal retention periods, these data will be stored vand then deleted. More detailed information about eKomi's data protection can be found atwww.ekomi.de/de/datenschutz.In the course of your evaluation via eKomi you can enter your email address, click which we will later inform you about your evaluatorscan contact you in the event of an emergency. In this way we can, for example, respond individually to your criticism, answer your questions or provide other assistance. We would like to point out that the indication of your E–Mail–Addressis voluntary.Legal basis for the use ofng your data for sending the evaluation mail is in accordance with Art. 6 para. 1 lit. a DSGVO Your consent