Skip to content

Cart

Your cart is empty

Privacy policy

1) INTRODUCTION AND CONTACT DETAILS OF THE RESPONSIBLE PARTY

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data in this context is any data that can be used to identify you personally.

1.2 The data protection officer for this website, as defined by the General Data Protection Regulation (GDPR), is Schmuckatelier Lang e.K.
Owner: Peter Lang, Segringer Straße 14, 91550 Dinkelsbühl, Germany, Tel.: 098517660, E-Mail: home@schmuckatelier-lang.de. The person or entity responsible for processing personal data is the natural or legal person who decides alone or together with others on the purposes and means of processing personal data.

 

2) DATA COLLECTION WHEN YOU VISIT OUR WEBSITE

2.1 When you use our website for informational purposes only, i.e., when you do not register or otherwise transmit information to us, we only collect the data that your browser transmits to the server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Reference or link from which you accessed the page
  • Browser used
  • Operating system used
  • Used IP address (if applicable: in anonymized form)

Processing is carried out in accordance with Art. 6 (1) lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be shared or used in any other way. However, we reserve the right to review the server log files at a later time if there are specific indications of unlawful use.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock icon in your browser line.


3) HOSTING & CONTENT-DELIVERY-NETWORK

3.1 Shopify

For hosting our website and displaying the content of the pages, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2. Etage, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

All data collected on our website is processed on the provider's servers. We have entered into a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

In the case of data transfer to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.


3.2 Cloudflare

We use a content delivery network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA

This service allows us to deliver large media files such as graphics, page content, or scripts more quickly through a network of regionally distributed servers. Processing is done to protect our legitimate interest in improving the stability and functionality of our website in accordance with Article 6 (1) (f) GDPR. We have entered into a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

 

4) COOKIES

To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"). "Session cookies"), some of these cookies remain on your device longer and allow page settings to be saved (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of your web browser's cookie settings.
If individual cookies we use also process personal data, processing is carried out in accordance with Article 6 (1) b GDPR either to execute the contract, in accordance with Article 6 (1) a GDPR in the case of consent, or in accordance with Article 6 (1) f GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.
You can set your browser to notify you when cookies are set and to decide individually whether to accept them or to block cookies in certain cases or in general.
Please note that if you do not accept cookies, the functionality of our website may be limited.

5) CONTACT

5.1 WhatsApp Business

We offer visitors to our website the opportunity to contact us via the WhatsApp messaging service of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. We use the so-called "business version" of WhatsApp for this purpose.

If you contact us via WhatsApp for a specific business (for example, an order you have placed), we will store and use the mobile phone number you use on WhatsApp, as well as your first and last name (if provided) in accordance with Article 6 (1) (b) GDPR to process and respond to your request. Based on the same legal basis, we may ask you to provide additional data (order number, customer number, address or email address) via WhatsApp so that we can assign your request to a specific process.

Use our WhatsApp contact for general inquiries (such as about our range of services, availability, or our website) and we will store and use the mobile phone number you use on WhatsApp, as well as your first and last name (if provided), in accordance with Article 6 (1) (f) GDPR based on our legitimate interest in the efficient and timely provision of the desired information. Your data will only be used to respond to your request via WhatsApp. No sharing with third parties.

Please note that WhatsApp Business will have access to the address book of the mobile device we use for this purpose and will automatically transfer the phone numbers stored in the address book to a Meta Platforms Inc. parent company server in the United States. We use a mobile device to operate our WhatsApp Business account, and its address book only stores the WhatsApp contact data of users who have also contacted us via WhatsApp.

This ensures that every person whose WhatsApp contact data is stored in our address book has already consented to the transmission of their WhatsApp phone number from their chat contacts' address books in accordance with Art. 6 (1) (a) GDPR upon first use of the app by accepting the WhatsApp terms of use. Transmission of data from users who do not use WhatsApp and/or have not contacted us via WhatsApp is excluded.

Purpose and scope of data collection and further processing and use of data by WhatsApp, as well as your rights and setting options to protect your privacy, please refer to WhatsApp's privacy policy: https://www.whatsapp.com/legal/?eea=1#privacy-policy

As part of the aforementioned processing, data may be transferred to Meta Platforms Inc. servers in the United States.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.


5.2 In the context of contacting us (e.g. via contact form or email), personal data is processed exclusively for the purpose of processing and responding to your request and only to the extent necessary.

The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Article 6 (1) (f) GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 (1) lit. b GDPR. Your data will be deleted when circumstances indicate that the matter in question has been conclusively clarified and provided that no legal retention requirements are in place.

 

6) DATA PROCESSING WHEN A CUSTOMER ACCOUNT IS OPENED

According to Article 6 (1) (b) of the GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. The required data for opening an account can be found in the input mask of the corresponding form on our website.

You can delete your customer account at any time by sending a message to the above-mentioned address of the person responsible. After your customer account is deleted, your data will be deleted, provided that all contracts concluded through it have been fully processed, there are no legal retention periods, and we have no legitimate interest in continuing to store the data.

 

7) USE OF CUSTOMER DATA FOR DIRECT MARKETING

7.1 Signing up for our email newsletter

If you sign up for our email newsletter, we will send you regular information about our offers. Your email address is the only required information for sending the newsletter. Providing additional data is voluntary and is used to address you personally. For sending the newsletter, we use the so-called Double opt-in procedure, which ensures that you receive newsletters only after you have explicitly confirmed your consent to receiving the newsletter by clicking on a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Article 6 (1) (a) of the GDPR. We store your IP address, as entered by your Internet Service Provider (ISP), as well as the date and time of registration, to be able to trace any potential misuse of your email address at a later date. The data we collect when you sign up for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a message to the controller named at the beginning. After you have unsubscribed, your email address will be deleted immediately from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data beyond that, which is permitted by law and about which we will inform you in this statement.

 

7.2 Shopify Email

Our email newsletters are sent through this provider: Shopify International Limited, Victoria Buildings, 2. Etage, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

Based on our legitimate interest in effective and user-friendly newsletter marketing, we forward your data provided during newsletter registration to this provider in accordance with Article 6 (1) lit. f GDPR, so that this provider can handle the newsletter delivery on our behalf.

Subject to your explicit consent in accordance with Article 6 (1) (a) GDPR, the provider will also conduct a statistical success evaluation of newsletter campaigns using web beacons or Count pixels in the sent emails that can measure open rates and specific interactions with the content of the newsletter. Endgerätedaten (z.B. Zeitpunkt des Aufrufs, IP-Adresse, Browsertyp und Betriebssystem) werden dabei erhoben und ausgewertet, aber nicht mit anderen Datenbeständen zusammengeführt.
You can revoke your consent to newsletter tracking at any time with future effect.

We have entered into a data processing agreement with the provider, which protects the data of our website visitors and prohibits the disclosure of such data to third parties.

In the case of data transfer to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a message to the controller named at the beginning. After you have unsubscribed, your email address will be deleted immediately from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use your data beyond that, which is permitted by law and about which we will inform you in this statement.

 

8) DATA PROCESSING FOR ORDER PROCESSING

8.1 To the extent necessary for the purpose of delivery and payment for contract processing, the personal data collected by us will be forwarded to the contracted transport company and the contracted credit institution in accordance with Art. 6 (1) b GDPR.

To process your order, we also work with the following service provider(s), who support us in whole or in part in the execution of concluded contracts. Certain personal data are transmitted to these service providers in accordance with the following information.

 

8.2 Disclosure of personal data to shipping service providers

- Parcelbroker

As a transportation service provider, we use the following provider: Parcel Broker GmbH, Richard-Strauss-Str. 7, 81677 Munich, Germany

As a transportation service provider, we use the following provider: Parcel Broker GmbH, Richard-Strauss-Str. 7, 81677 Munich, Germany

We will forward your email address and/or phone number to the provider in accordance with Art. 6 (1) lit. a GDPR prior to delivery of the goods for the purpose of coordinating a delivery date or delivery notification, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 (1) (b) GDPR, we only pass on the name of the recipient and the delivery address to the provider. The transfer only occurs to the extent necessary for the delivery of goods. In this case, it is not possible to agree on a delivery date with the supplier in advance or to announce the delivery.

Consent may be revoked at any time with effect for the future vis-à-vis the controller designated above or vis-à-vis the provider.

 

- DHL Express

As a transportation service provider, we use the following provider: DHL Express Germany GmbH, Heinrich-Brüning-Str. 5, 53113 Bonn, Germany

We will forward your email address and/or phone number to the provider in accordance with Art. 6 (1) lit. a GDPR prior to delivery of the goods for the purpose of coordinating a delivery date or delivery notification, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 (1) (b) GDPR, we only pass on the name of the recipient and the delivery address to the provider. The transfer only occurs to the extent necessary for the delivery of goods. In this case, it is not possible to agree on a delivery date with the supplier in advance or to announce the delivery.

Consent may be revoked at any time with future effect by contacting the controller or provider named above.

As a transportation service provider, we use the following provider: DHL Express Germany GmbH, Heinrich-Brüning-Str. 5, 53113 Bonn, Germany

 

- FedEx

As a transportation service provider, we use the following provider: FedEx Express Germany GmbH, Langer Kornweg 34 k, 65451 Kelsterbach, Germany

We will forward your email address and/or phone number to the provider in accordance with Art. 6 (1) lit. a GDPR prior to delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 (1) (b) GDPR, we only pass on the name of the recipient and the delivery address to the provider. The transfer only occurs to the extent necessary for the delivery of goods. In this case, it is not possible to agree on a delivery date with the supplier in advance or to announce the delivery.

Consent may be revoked at any time with effect for the future vis-à-vis the controller designated above or vis-à-vis the provider.

 

- UPS

As a transportation service provider, we use the following provider: United Parcel Service Deutschland Inc. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany

We will forward your email address and/or phone number to the provider in accordance with Art. 6 (1) lit. a GDPR prior to delivery of the goods for the purpose of coordinating a delivery date or delivery notification, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 (1) (b) GDPR, we only pass on the name of the recipient and the delivery address to the provider. The transfer only occurs to the extent necessary for the delivery of goods. In this case, it is not possible to agree on a delivery date with the supplier in advance or to announce the delivery.

Consent may be revoked at any time with effect for the future vis-à-vis the controller designated above or vis-à-vis the provider.

 

8.3 Use of payment service providers (payment services)

- PayPal

One or more online payment methods are available on this website from the following provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

When you select a payment method from the provider that requires you to pay upfront, your payment information (including name, address, bank and credit card information, currency, and transaction number) and information about the content of your order will be shared with the provider in accordance with Article 6 (1) (b) of the GDPR. In this case, your data is shared exclusively for the purpose of processing payment with the provider, and only to the extent necessary for this purpose.

When selecting a payment method where we pay in advance, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly To provide data for an alternative payment method.

To maintain our legitimate interest in determining your ability to pay in such cases, we will forward this data to the provider for the purpose of a credit check in accordance with Art. 6 (1) lit. f GDPR. The provider checks based on the personal data you provided and other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option you selected can be granted with regard to payment and/or debt collection risks.

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by objecting to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

 

- PayPal Checkout

This website uses PayPal Checkout, an online payment system from PayPal, which consists of PayPal's own payment methods and local payment methods from third-party providers.

When you pay via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "Pay Later" via PayPal, we will forward your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. The transfer takes place in accordance with Art. 6 (1) lit. b GDPR and only insofar as this is necessary for payment processing.

PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "Pay later" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 (1) lit. f GDPR on the basis of PayPal's legitimate interest in determining your payment ability. The result of the credit check with regard to the statistical probability of default is used by PayPal for the purpose of deciding on the provision of the respective payment method. The credit information may contain probability values (so-called score values). Insofar as score values are included in the credit information result, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of score values includes, but is not limited to, address data.

You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may continue to be entitled to process your personal data if this is necessary for contractual payment processing.

When you select the PayPal payment method "invoice purchase," your payment data is first transmitted to PayPal in preparation for payment, at which point PayPal forwards it to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin ("Ratepay") to process the payment. The legal basis is Art. 6 (1) lit. b GDPR in each case. In this case, RatePay conducts an identity and credit check in its own name to determine the solvency in accordance with the principle mentioned above and passes on your payment data to credit agencies based on the legitimate interest in determining solvency in accordance with Art. 6 (1) lit. f GDPR. A list of credit reporting agencies that Ratepay can use is available here: https://www.ratepay.com/legal-payment-creditagencies/

When using a local third-party payment method, your payment data is initially forwarded to PayPal in accordance with Article 6 (1) (b) GDPR for payment preparation. Depending on your selection of a locally available payment method, PayPal will transmit your payment data to the corresponding provider for the execution of the payment in accordance with Art. 6 (1) lit. b GDPR:

  • Sofort (SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany)
  • iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
  • giropay (Paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main
  • bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
  • blik (Polski Standard Płatności sp. z o.o., ul. Czerniakowska 87A, 00-718 Warsaw, Poland)
  • eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2 1200 Vienna, Austria)
  • MyBank (PRETA S.A.S, 40 Rue de Courcelles, F-75008 Paris, France)
  • Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)

For more information on data protection, please refer to the PayPal Privacy Policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

 

- Shopify Payments

One or more online payment methods are available on this website from the following provider: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

When you select a payment method from the provider where you pay upfront (such as credit card payment), your payment information (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be shared with the provider in accordance with Article 6 (1) (b) GDPR as part of the order process. In this case, your data is shared exclusively for the purpose of processing payment with the provider, and only to the extent that it is necessary for this purpose.

 

- Stripe

One or more online payment methods from the following provider are available on this website: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

When you select a payment method from the provider where you pay upfront (such as credit card payment), your payment information (including name, address, bank and credit card information, currency, and transaction number) as well as information about the content of your order will be shared with the provider in accordance with Article 6 (1) (b) GDPR as part of the order process. In this case, your data is shared exclusively for the purpose of processing payment with the provider, and only to the extent that it is necessary for this purpose.

When selecting a payment method where the provider pays upfront (such as invoice or installment purchase or During the ordering process, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly To provide data for an alternative payment method.

To maintain our legitimate interest in determining the creditworthiness of our customers, this data is forwarded to the provider for the purpose of a credit check in accordance with Art. 6 (1) lit. f GDPR. The provider checks based on the personal data you provided and other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option you selected can be granted with regard to payment and/or debt collection risks.

The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data.

You can object to this processing of your data at any time by sending us a message or by objecting to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

 

9) WEB ANALYSIS SERVICES

9.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which allows us to analyze your use of our website.

By default, Google Analytics sets cookies when you visit the website. These cookies are small text blocks that are stored on your device and collect certain information. This information also includes your IP address, which is truncated by Google to exclude direct personal identification.

The information is transferred to Google servers and processed there. Transmissions to Google LLC, which is based in the USA, are also possible.

Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activity for us, and provide other services related to website activity and internet usage. The abbreviated IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google. The data collected as part of the use of Google Analytics 4 is stored for a period of two months and then deleted.

All processing described above, particularly the setting of cookies on the device used, only occurs if you have given us your explicit consent in accordance with Article 6 (1) (a) GDPR.

Google Analytics 4 will not be used during your visit to the site without your consent. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with Google, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

For more legal information about Google Analytics 4, see https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de and https://policies.google.com/technologies/partner-sites


- Demographic characteristics

Google Analytics 4 uses the special "demographic features" function and can create statistics that make statements about the age, gender, and interests of site visitors. This is done by analyzing advertisements and information from third-party providers. This allows target groups for marketing activities to be identified. However, the collected data cannot be assigned to a specific person and will be deleted after being stored for two months.

 

- Google Signals

As an extension to Google Analytics 4, Google Signals can be used on this website to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google can, subject to your consent to the use of Google Analytics in accordance with Article 6 (1) lit. a GDPR, analyze your usage behavior across devices and create database models, including for cross-device conversions. We receive no personal data from Google, only statistics. If you want to stop cross-device analysis, you can deactivate the "Personalized advertising" function in the settings of your Google account. To do this, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de For more information about Google Signals, see the following link: https://support.google.com/analytics/answer/7532985?hl=de

 

- UserIDs

As an extension to Google Analytics 4, the "UserIDs" function can be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Article 6 (1) (a) GDPR, set up an account on this website, and log in to this account on different devices, your activities, including conversions, can be analyzed across devices.

 

- Collection of data provided by users

To improve analysis results for users whose contact information we have obtained in the course of business or business-like relationships, we use the "collection of user-provided data" function.

Subject to your express consent in accordance with Art. 6 (1) lit. a GDPR, we will transmit one or more files with aggregated customer data (primarily email address and phone number) to Google electronically as part of this function. Google does not have access to clear data in this case, but encrypts the information in the customer files automatically during the transmission process using a special algorithm. The encrypted information can then only be used by Google to associate it with existing Google accounts set up by the affected individuals.

The processing serves to refine measurement data, improves cross-device user tracking, and enables the integration of analysis results into Google Ads' advertising personalization and conversion tracking functions.

You can revoke your consent to us at any time with effect for the future. For more information on Google's data protection measures regarding the transmission of customer data, see: https://support.google.com/google-ads/answer/6334160?hl=de&ref_topic=10550182

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

 

9.2 Google Tag Manager

This website uses the "Google Tag Manager", a service of the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").

The Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analysis services, and calibrating, controlling, and linking them to conditions via a uniform user interface. The Google Tag Manager itself does not store any information on user devices or read it from them. The service also does not perform independent data analysis. However, when a page is loaded, the Google Tag Manager transfers your IP address to Google and possibly stores it there. It is also possible to transfer it to Google LLC servers in the USA.

This processing will only be carried out if you have given us your explicit consent in accordance with Art. 6 (1) lit. a GDPR. Without this consent, Google Tag Manager will not be used during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your right to opt out, please deactivate this service in the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

For more legal information about Google Tag Manager, see below:
https://business.safety.google/intl/de/privacy/ und https://policies.google.com/privacy?hl=de&gl=de

 

9.3 Shopify Analytics
This website uses the web analytics service of the following provider: Shopify International Limited, Victoria Buildings, 2. Etage, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada
Using cookies and/or comparable technologies (tracking pixels, web beacons, algorithms for reading end device and browser information), the service collects and stores pseudonymized visitor data, including information about the end device used, such as the IP address and browser information, in order to evaluate it for statistical analyses of user behavior on our website and to create pseudonymized user profiles. Among other things, this includes the evaluation of movement patterns (so-called "activity patterns"). Heatmaps) that show the duration of page visits and interactions with page content (e.g., text input, scrolling, clicks, and mouse-overs). Pseudonymization essentially precludes direct personal identification. A combination with other collected clear data about you will not take place.

All processing described above, particularly reading or storing information on the device used, will only be performed if you have given us your explicit consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with the provider that protects the data of our website visitors and prohibits the disclosure of such data to third parties.

In the case of data transfer to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

 

10) RETARGETING/ REMARKETING AND CONVERSION TRACKING

10.1 Meta Pixel with extended data matching

Within our online offer, we use the "Meta Pixel" service in the mode of extended data matching from the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Meta")

When a user clicks on an ad we've placed on Facebook or Instagram, the URL of our linked page is extended by a parameter using "Meta Pixel". This URL parameter is then entered into the user's browser after redirection by a cookie set by our linked page. Furthermore, this cookie captures specific customer data such as the email address that we collect on our website linked to the Facebook or Instagram ad during processes such as purchases, account logins, or registrations (extended data matching). The cookie is then read and allows the transmission of data, including specific customer data, to Meta.

We use "Meta Pixel" with extended data matching to make our advertisements (so-called "ads") on Facebook and/or Instagram more effective and to ensure that they correspond to the interests of the users or have certain characteristics (e.g., interests in specific topics or products, which are determined based on the visited websites), which we transmit to Meta (so-called "Custom Audiences").

We also analyze the effectiveness of our ads by tracking whether users are redirected to our website after clicking on an ad (conversion). Compared to the standard "Meta Pixel" variant, the advanced data matching feature helps us better measure the effectiveness of our advertising campaigns by capturing more assigned conversions.

All transmitted data is stored and processed by Meta, so that it can be associated with the respective user profile and Meta can use the data for its own advertising purposes in accordance with Meta's data usage guidelines (https://www.facebook.com/about/privacy/). The data may allow Meta and its partners to display ads on and off Facebook.

All processing described above, particularly the setting of cookies to read information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

The information generated by Meta is generally transmitted to a Meta server and stored there; in this context, it may also be transmitted to Meta Platforms Inc. servers in the USA.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

 

10.2 Google Ads Remarketing

This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

For this purpose, Google sets a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you visit. Further data processing will only take place if you have agreed to Google linking your internet and app browser history with your Google account and using information from your Google account to personalize ads you view on the web.

If you are logged in to Google while visiting our website, Google will use your data together with Google Analytics data to create and define target audience lists for cross-device remarketing. For this purpose, your personal data will be temporarily linked with Google Analytics data to create target groups. As part of the use of Google Ads Remarketing, personal data may also be transmitted to the servers of Google LLC. in the USA.

All processing described above, particularly the setting of cookies to read information on the device used, will only be performed if you have given us your explicit consent in accordance with Art. 6 (1) (a) GDPR. Without this consent, retargeting technology will not be used during your visit to the site.

You can revoke your consent at any time with effect for the future. To exercise your right to opt out, please deactivate this service in the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

Details about the processing initiated by Google and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites

For more information on Google's privacy policy, please visit: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

 

10.3 Google Ads Conversion-Tracking

This website uses the online advertising program "Google Ads" and, as part of Google Ads, conversion tracking by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").

We use Google Ads to draw attention to our attractive offers on external websites with the help of advertising materials (so-called Google Adwords). We can determine the success of individual advertising measures in relation to the data of the advertising campaigns. We are pursuing the goal of showing you advertisements that are of interest to you, making our website more interesting for you, and achieving a fair calculation of the advertising costs incurred.

The cookie for conversion tracking is set when a user clicks on an ad displayed by Google. Cookies are small text files that are stored on your device. These cookies typically expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can see that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Cookies can thus not be tracked through the websites of Google Ads customers. The information obtained with the help of the conversion cookie is used to create conversion statistics for Google Ads customers who have opted for conversion tracking. 

Customers are shown the total number of users who have clicked on their ad and were forwarded to a page with a conversion tracking tag. However, you will not receive any information that can be used to personally identify users. As part of the use of Google Ads, personal data may also be transmitted to the servers of Google LLC. in the United States.

Details about the processing initiated by Google Ads Conversion Tracking and Google's handling of data from websites can be found here: https://policies.google.com/technologies/partner-sites

All processing described above, particularly the setting of cookies to read information on the device used, will only be performed if you have given us your explicit consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

You can also permanently object to Google setting cookies for conversion tracking by downloading and installing the Google browser plug-in available at the following link:

https://support.google.com/My-Ad-Center-Help/answer/12155656?hl=de

To target users whose data we have received in the context of business or business-like relationships with even more interest-based advertising, we use a customer matching function in the context of Google Ads. We transmit one or more files with aggregated customer data (primarily email addresses and phone numbers) to Google electronically for this purpose. Google does not have access to clear data in this case, but encrypts the information in the customer files automatically during the transmission process using a special algorithm. The encrypted information can then only be used by Google to associate it with existing Google accounts set up by the affected individuals. This allows personalized ads to be displayed across all Google services linked to the respective Google account.

The transmission of customer data to Google occurs only if you have given us your explicit consent in accordance with Art. 6 (1) lit. a GDPR. You can revoke this consent at any time with future effect. For more information on Google's data protection measures regarding the customer match function, see: https://support.google.com/google-ads/answer/6334160?hl=en&ref_topic=10550182

Google's privacy policy can be viewed here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

 

11) SIDE FUNCTIONALITY

11.1 Google Maps

This website uses an online map service from the following provider: Google Maps (API) by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").

Google Maps is a web service for displaying interactive (land) maps to visually display geographic information. Our location will be displayed to you, making it easier to find us, when you use this service.

Upon accessing the subpages that include the Google Maps map, information about your use of our website (such as your IP address) is transmitted to Google servers and stored there, and may also be transmitted to the servers of Google LLC. in the United States. This occurs regardless of whether Google provides a user account through which you are logged in or whether a user account exists. If you are logged in to Google, your data will be directly associated with your account. If you do not want the assignment to your Google profile, you must log out before activating the button. Google stores your data (even for unlogged-in users) as usage profiles and evaluates them.

The collection, storage, and analysis are carried out in accordance with Art. 6 (1) lit. f GDPR on the basis of Google's legitimate interest in displaying personalized advertising, market research, and/or the needs-based design of Google websites. You have the right to object to the creation of these user profiles, and you must contact Google to exercise this right. If you do not agree with the future transmission of your data to Google as part of the use of Google Maps, you also have the option to completely deactivate the Google Maps web service by turning off the JavaScript application in your browser. Google Maps and the map display on this website cannot be used.

To the extent required by law, we have obtained your consent to the processing of your data as described above in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please follow the instructions for objection outlined above.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

Additional information about Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

 

11.2 Google reCAPTCHA

On this website, we use the CAPTCHA service of the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

Data can also be transmitted to: Google LLC, USA.

The provider uses "Google Fonts", which are fonts loaded from the Internet by Google, for the visual design of the Captcha window. No processing of additional information beyond the ones mentioned above, which are already transmitted to Google via ReCaptcha's functionality, occurs here.

The service checks whether an input is made by a natural person or misused through machine and automated processing, and blocks spam, DDoS attacks, and similar automated malicious access. To ensure that an action is taken by a human and not an automated bot, the provider collects the IP address of the end device used, identification data of the browser and operating system type used, and the date and duration of the visit, and transmits this for evaluation to the provider's servers. Cookies, also smaller text files stored in the browser of the end device, can be used for this purpose.

If the above-described processing is based on cookies, they will only be set if you have given us your explicit consent in accordance with Art. 6 (1) lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

If the processing described above is carried out without the use of cookies, the legal basis is our legitimate interest in determining individual self-responsibility on the Internet and preventing misuse and spam in accordance with Art. 6 (1) f GDPR.

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on a decision of adequacy by the European Commission.

Additional information about Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

 

12) TOOLS AND OTHER

12.1 DATEV

For accounting purposes, we use the cloud-based accounting software service of the following provider: DATEV eG, Paumgartnerstr. 6-14, 90429 Nürnberg, Deutschland

The provider processes incoming and outgoing invoices as well as our company's bank transactions, if applicable, to automatically record invoices, match them to transactions, and create the financial accounting in a semi-automated process.

If personal data is also processed in this context, processing is based on our legitimate interest in the efficient organization and documentation of our business processes in accordance with Article 6 (1) (f) GDPR.

 

12.2 Cookie Consent Tool

This website uses a so-called "cookie consent tool" to obtain effective user consent for consent-required cookies and cookie-based applications. The "cookie consent tool" is displayed to users in the form of an interactive user interface when a page is loaded, where consent for specific cookies and/or cookie-based applications can be granted by checking boxes. By using this tool, all consent-required cookies/services are only loaded if the respective user grants consent by checking boxes. This ensures that such cookies are only set on the user's respective device if consent is granted.

The tool sets technically necessary cookies to store your cookie preferences. Personal user data is not processed in this case.

If, in an individual case, personal data (such as an IP address) is processed for the purpose of storing, assigning, or logging cookie settings, this is done in accordance with Article 6 (1) lit. f GDPR on the basis of our legitimate interest in a lawful, user-specific, and user-friendly consent management for cookies and, accordingly, in a lawful design of our website.

Further legal basis for processing is also Art. 6 (1) c GDPR. As the responsible party, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user's consent.

As necessary, we have entered into a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

For more information about the operator and the settings options of the cookie consent tool, please refer directly to the corresponding user interface on our website.

 

13) RIGHTS OF THE DATA SUBJECT

13.1 Under applicable data protection law, you have the following data subject rights (right to information and intervention rights) with respect to the controller with regard to the processing of your personal data. The respective preconditions for exercising these rights are set out in the legal basis cited:

  • Right to information in accordance with Article 15 GDPR;
  • Right to rectification under Article 16 GDPR;
  • Right to erasure under Article 17 GDPR;
  • Right to restriction of processing according to Art. 18 GDPR;
  • Right to be informed under Article 19 GDPR;
  • Right to data portability in accordance with Article 20 GDPR;
  • Right to revoke consent granted in accordance with Article 7(3) GDPR;
  • Right to lodge a complaint in accordance with Article 77 GDPR.

13.2 Right to object

If we process your personal data within the scope of a balancing of interests due to our overriding legitimate interest, you have the right to object to this processing at any time for reasons arising from your particular situation with effect for the future.

Machen Sie von Ihrem Widerspruchsrecht Gebrauch, beenden wir die Verarbeitung der betroffenen Daten. Eine Weiterverarbeitung bleibt aber vorbehalten, wenn wir zwingende schutzwürdige Gründe für die Verarbeitung nachweisen können, die Ihre Interessen, Grundrechte und Grundfreiheiten überwiegen, oder wenn die Verarbeitung der Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen dient.

Werden Ihre personenbezogenen Daten von uns verarbeitet, um Direktwerbung zu betreiben, haben Sie das Recht, jederzeit Widerspruch gegen die Verarbeitung Sie betreffender personenbezogenerer Daten zum Zwecke derartiger Werbung einzulegen. Sie können den Widerspruch wie oben beschrieben ausüben.

Machen Sie von Ihren Widerspruchsrecht Gebrauch, beenden wir die Verarbeitung der betroffenen Daten zu Direktwerbezwecken.


14) DURATION OF STORAGE OF PERSONAL DATA

The duration of the storage of personal data is measured based on the respective legal basis, the processing purpose, and – if applicable – additionally based on the respective legal retention period (e.g., commercial and tax retention periods).

When processing personal data based on explicit consent in accordance with Article 6 (1) (a) GDPR, the data in question will be stored until you revoke your consent.

If there are legal retention periods for data processed under legal or quasi-legal obligations based on Art. 6 (1) (b) GDPR, this data will be routinely deleted after the retention periods expire, unless it is no longer necessary for contract fulfillment or initiation and/or we have no legitimate interest in continued storage.

When processing personal data based on Article 6 (1) lit. f GDPR, this data is stored until you exercise your right to object under Article 21 (1) GDPR, unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

When processing personal data for direct marketing purposes based on Article 6 (1) lit. f GDPR, this data is stored until you exercise your right to object under Article 21 (2) GDPR.

Unless otherwise indicated by other information in this statement about specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.