Data privacy policy
Your privacy is important to us
We are delighted that you are visiting our website. The protection and security of your personal information when using our website is very important to us. We would therefore like to take this opportunity to inform you about which of your personal data we collect when you visit our website and for what purposes it is used. Personal data refers to specific details regarding the personal or factual circumstances of an identified or identifiable natural person (data subject), e.g. name, address, email addresses, user behaviour. This therefore refers to data that enables us to identify you. In addition, you will also find some information here regarding data processing activities outside this website (e.g. video conferences or newsletters).
Responsible for data processing
Data controller
For the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
Trotec GmbH
Grebbener Straße 7
52525 Heinsberg
Phone: +49 2452 962-450
Email: online@trotec.de
Data Protection Officer
exkulpa gmbh
Waldfeuchterstr. 266
52525 Heinsberg
Phone: 02452 / 99 33 11
Email: dsm@danthermgroup.com
General Information
In addition to the data you actively provide to us on this site (e.g. via our contact form), we collect certain technical data. This so-called metadata is automatically transmitted from your computer to our servers as soon as you visit our website (including browser, operating system or timestamp). We use this data to ensure our website is displayed correctly. In addition, we may collect data via integrated third-party providers (e.g. for external media such as map services or analytics tools). We will explain the specific purposes and legal bases in the course of this privacy policy.
Retention period
Unless a specific retention period is stated within this privacy policy, we will retain your personal data for as long as the purpose of the data processing remains valid. If you submit a valid request for erasure or withdraw your consent, we will delete your data. Statutory retention obligations remain unaffected.
Legal basis for data processing
If you have consented to data processing, the processing of your personal data is based on Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, if special categories of data are processed in accordance with Article 9(1) of the GDPR. Where you have given your express consent to the transfer of personal data to third countries, the data is also processed in accordance with Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or access to information on your device (e.g. through device fingerprinting), data processing also takes place on the basis of Section 25(1) of the TDDDG. Your consent may be withdrawn at any time. If your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data in accordance with Article 6(1)(b) of the GDPR. Furthermore, we process your data where this is necessary to comply with a legal obligation, on the basis of Article 6(1)(c) of the GDPR. Data processing may also take place on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR. The following sections of this privacy policy provide information on the respective legal bases in individual cases.
Note on data transfers to third countries and US companies without DPF certification
Please note that we use tools from companies based in third countries with insufficient data protection standards or in the USA, which are not covered by the EU-US Data Protection Framework (DPF). When using these tools, your personal data may be transferred to and processed in these countries. Please note that in these third countries, a level of data protection comparable to that of the EU cannot be guaranteed.
We would like to clarify that the US generally offers a level of data protection comparable to that of the EU. The transfer of data to the US is permitted if the recipient holds DPF certification or provides appropriate additional safeguards. Information on data transfers to third countries, including data recipients, can be found in our privacy policy.
Automated decision-making
Your personal data is not processed for the purposes of automated decision-making.
Your rights
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: You have the right to request confirmation from us as to whether your personal data is being processed and, if so, to receive further information about the processing and copies of the data being processed (Art. 15 GDPR).
- Right to rectification: You have the right to request the immediate rectification of inaccurate personal data concerning you and, where applicable, the completion of incomplete personal data (Art. 16 GDPR).
- Right to erasure: You have the right to request the immediate erasure of personal data concerning you where the legal conditions are met, in particular where the data is no longer necessary for the purposes for which it was collected and the processing is unlawful (Art. 17 GDPR).
- Right to restriction of processing: You have the right to request that we restrict the processing of your personal data where the legal conditions are met, in particular where you contest the accuracy of the data, the processing is unlawful and you oppose erasure (Art. 18 GDPR).
- Right to data portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided this is technically feasible (Art. 20 GDPR).
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, where the processing is based on Article 6(1)(e) or (f) of the GDPR (Article 21 of the GDPR).
- Right to withdraw consent: You have the right to withdraw your consent to the processing of personal data at any time with effect for the future. Withdrawal of your consent does not affect the lawfulness of processing carried out on the basis of your consent prior to withdrawal (Art. 7(3) GDPR).
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR (Article 77 GDPR).
Further data processing operations
General information obligations
This information is intended for customers, prospective customers, suppliers and employees. We process your personal data for the following purposes:
- To fulfil our contractual obligations to you (Art. 6(1)(b) GDPR).
- To carry out pre-contractual obligations (Art. 6(1)(b) GDPR).
- To respond to enquiries (Art. 6(1)(b) GDPR).
- Where you have given us your consent to process your personal data for specific purposes (such as to receive our newsletter), data processing takes place on the basis of your consent (Art. 6(1)(a) GDPR).
- To comply with legal obligations to which our company is subject (Art. 6(1)(c) GDPR).
- Where necessary, we also process your data to safeguard our legitimate interests, in particular to assert legal claims and defend ourselves in legal disputes, or to ensure IT security; to consult and exchange data with credit reference agencies to assess creditworthiness and default risks; for direct marketing and market research, provided you have not objected to the use of your data for this purpose; in connection with measures for business management and the further development of services and products, in connection with measures for product and sales optimisation, in connection with risk management measures, and for the prevention or investigation of criminal offences (Art. 6(1)(f) GDPR).
Categories of recipients of personal data
Within our company, only those employees who absolutely need the data to perform their duties have access to it (need-to-know principle). Individual processes and services are carried out by carefully selected service providers, commissioned in accordance with data protection regulations, who are based within the EEA. Where service providers commissioned by us gain access to personal data whilst performing their services, data processing agreements have been concluded with them in accordance with Article 28(3) of the GDPR.
Duration of data storage
The data we process is stored for the duration of the contractual relationship and its fulfilment, and in compliance with statutory retention periods. These include, in particular, commercial and tax law retention obligations under the German Commercial Code (HGB) and the German Fiscal Code (AO). The standard retention and documentation periods amount to up to ten years. If no contractual relationship arises, we process the data only for as long as the specific purpose requires.
Cookies
Cookies are small text files that are stored by your browser on your device to save certain information whilst you are using the website. Cookies enable us to improve various aspects of our website and make your visit more convenient.
There are various types of cookies, each serving different purposes. Temporary cookies, also known as session cookies, are stored only for the duration of your use of the website and are automatically deleted when you close your browser. Persistent cookies, on the other hand, remain stored on your device for a longer period and enable us to recognise you and your preferences on subsequent visits to the website.
Cookies can also be divided into first-party cookies and third-party cookies. First-party cookies are set by our website, whilst third-party cookies are set by other websites or service providers whose content is integrated into our website, such as plugins or analytics tools.
Cookies are used for various purposes, such as ensuring the website functions properly, storing user settings, compiling anonymous statistics on user behaviour, or displaying personalised content and advertising. The legal basis for the use of cookies varies depending on the purpose of the cookies. In some cases, the setting of cookies is based on your legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to make our website functional and user-friendly. As the website operator, we have a legitimate interest in storing necessary cookies to ensure the technically flawless and optimised provision of our services. Where we seek your consent for the use of cookies, processing is carried out on the basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Your consent may be withdrawn at any time.
Cookie consent with Usercentrics
Nature and scope of processing
We use Usercentrics’ consent technology to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document this in accordance with data protection regulations. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich (hereinafter “Usercentrics”).
When you visit our website, the following personal data is transmitted to Usercentrics:
- Your consent(s) or the withdrawal of your consent(s)
- Your IP address
- Information about your browser
- Information about your device
- The time of your visit to the website
In order to be able to assign and document your consent or withdrawal of consent, the provider sets a cookie in your browser. This data is stored until you delete the cookie, request us to delete the data, or the purpose for data processing no longer applies. Statutory retention obligations remain unaffected.
Usercentrics is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Article 6(1)(c) of the GDPR.
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Data processing in detail
Below, we provide information on the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data and the respective retention period. No automated decision-making, including profiling, takes place in individual cases.
Provision of the website
When you access and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the file accessed
- Website from which the access originated (referrer URL)
- Browser used and, where applicable, your computer’s operating system, as well as the name of your internet service provider
Our website is not hosted by us, but by a service provider who processes the aforementioned data on our behalf for the purpose of providing the website, in accordance with Article 28 of the GDPR.
The use of the hosting provider is for the purpose of fulfilling our contractual obligations towards our potential and existing customers (Article 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online services by a professional provider (Article 6(1)(f) GDPR).
We use the following hosting provider:
PlusServer GmbH
Venloer Straße 47
50672 Cologne
Contact form
Nature and scope of processing
When you send us enquiries (e.g. via the contact form, email or telephone), we store all data resulting from this (e.g. name, email address, subject of the enquiry, etc.). We require this data to process your enquiry and to be able to answer any follow-up questions. We will not pass on this data without your consent.
Purpose and legal basis
The processing of this data is based on Article 6(1)(b) of the GDPR, provided that your enquiry relates to the performance of a contract or is necessary for the implementation of pre-contractual measures. Otherwise, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) of the GDPR) or on your consent (Article 6(1)(a) of the GDPR) if you have previously given it.
Retention period
The data you enter in the contact form will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
Zendesk
Nature and scope of processing
We use the Zendesk CRM system to process user enquiries. The provider is Zendesk, Inc., 1019 Market Street, San Francisco, CA 94103, USA.
You can submit enquiries by providing only your email address and without giving your name. If you do not wish for us to process your enquiry via Zendesk, you may alternatively use our other channels (e.g. email or telephone).
Further information can be found in Zendesk’s privacy policy: www.zendesk.de/company/customers-partners/privacy-policy/.
Zendesk chat functions
We have a chat window on our website that is operated by Zendesk. When you use the chat, we store your IP address and your messages. You do not need to provide your name to use the chat function.
Purpose and legal basis
We use Zendesk on the basis of our legitimate interest in the rapid and efficient processing of enquiries pursuant to Article 6(1)(f) of the GDPR. The basis for data transfers to third countries, in particular the USA, is the Binding Corporate Rules (BCR). These are binding internal company rules that legitimise the internal transfer of data to third countries outside the EU and the EEA. You can find details here: www.zendesk.de/blog/update-privacy-shield-invalidation-european-court-justice/.
Retention period
We retain the messages until you request their deletion or the purpose for data storage no longer applies (e.g. once your enquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Contact form for applicants
Nature and scope of processing
We collect and process the personal data of applicants. Such data processing may also take place electronically, for example, when applicants send their application documents to us via email or via a web form on our website at . On our website, we offer you the option of submitting applications for advertised vacancies to us via email.
Purpose and legal basis
We process applicants’ personal data in accordance with legal requirements for the purpose of establishing an employment relationship (Art. 6(1)(b) GDPR). You are not obliged to provide us with this data. However, without this data, we cannot carry out an application process with you.
If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Article 6(1)(b) of the GDPR and, insofar as you provide us with special categories of personal data such as health information, on the basis of Article 9(2)(b) for the purpose of carrying out the employment relationship.
We also use the professional networking services LinkedIn and XING to approach potential applicants. In this respect, the operators of these networks act as data processors on our behalf in accordance with our instructions. The legal basis for data processing when contacting potential applicants on our behalf is Article 6(1)(f) of the GDPR (our legitimate interests). If, following such contact, you send us your application, we process your data for the purpose of establishing an employment relationship as described above on the basis of Article 6(1)(b) of the GDPR.
Retention period
In the event of a rejection, your data will be stored for a period of 6 months beyond the conclusion of the application process. This is done to safeguard our legitimate interests, to assess whether we require the data to defend against any claims arising in connection with the application process. We are then obliged to delete or anonymise your data. In this case, the data will only be available to us as so-called metadata without any direct personal reference for statistical analysis (for example, the proportion of female and male applicants, the number of applications per period, etc.).
If it becomes apparent that further storage of the data is necessary after the expiry of the 6-month period to safeguard our legitimate interests (e.g. due to an impending or pending legal dispute), deletion will only take place once the purpose for the continued storage no longer applies. The legal basis for this further data storage is our legitimate interest in the assertion, exercise or defence of civil law claims (Art. 6(1)(f) GDPR in conjunction with Section 24(1)(2) BDSG or, where special categories of personal data are stored, Art. 9(2)(f) GDPR in conjunction with Section 24(2) BDSG).
Inclusion in the applicant pool
As part of the application process, we offer applicants the opportunity to be included in our “talent pool” for a period of 24 months on the basis of consent within the meaning of Article 6(1)(a) and Article 9(2)(a) of the GDPR. If you have provided special categories of personal data in your application, such as health information, your consent also extends to this data. You are not obliged to provide us with your application data for our talent pool. However, without this data, we cannot consider you for future vacancies unless you submit a new application.
Consent to the inclusion of application data in the talent pool is voluntary and may be withdrawn at any time with future effect. Withdrawal of consent does not affect the lawfulness of data processing carried out on the basis of consent prior to withdrawal.
Your application documents will be deleted from the talent pool at the latest upon expiry of the retention period, or in the event of a withdrawal of consent, or upon acceptance of a job offer from one of the companies responsible for the talent pool.
If, as part of the application process, you receive an offer of employment from us and accept it, we or that company will store the personal data collected during the application process for the purpose of implementing the employment relationship. The legal basis for this data processing is Article 6(1)(b) of the GDPR or, insofar as you provide us with special categories of personal data such as health information, Article 9(2)(b).
Newsletter
We offer our newsletter on this website. If you wish to subscribe to it, we require your email address and further data to verify that the email address belongs to you and that you consent to receiving the newsletter. No other personal data is collected unless you provide it voluntarily (e.g. name, telephone number, place of residence, etc.).
When processing the data you provide when registering for the newsletter, we rely exclusively on your consent pursuant to Article 6(1)(a) of the GDPR as the legal basis. You may withdraw your consent to the processing and storage of your personal data at any time (e.g. via the ‘Unsubscribe’ link in the newsletter) with effect for the future.
We store the personal data you have provided for the purpose of receiving the newsletter until you unsubscribe from the newsletter via us or the mailing service provider. This does not apply to data we have stored about you for other purposes.
If you unsubscribe from the newsletter mailing list, your email address will be stored by us or the mailing service provider on a blacklist for an indefinite period. This is done to prevent future mailings from being sent to you. The data from the blacklist is used exclusively for this purpose and is not combined with other data. This is not only in your interest, but also in our legitimate interest pursuant to Article 6(1)(f) of the GDPR to fulfil our legal obligations regarding the sending of newsletters. You may object to the storage of your data if your personal interests override our legitimate interest.
Emarsys
On this website, we use the Emarsys service, provided by Emarsys eMarketing Systems GmbH, Lassallestraße 7b, 1020 Vienna, Austria, for sending our newsletter and for other marketing activities. In doing so, personal data such as your email address, name and, where applicable, other contact details you have provided are processed . In addition, Emarsys may collect technical information such as your IP address, the device used, operating system, browser, products viewed, browsing history, your user behaviour and the time of registration.
When newsletters are sent, Emarsys carries out an analysis to determine whether and when an email was opened and which links were clicked. This information is used to improve our offering and is linked to the information you provided upon registration. Furthermore, you consent to us collecting the open and click-through rates of our newsletters for the purpose of personalising and designing future newsletters and compiling them into recipient profiles.
Our online shop also transmits the following information:
Abandoned shopping baskets
Product pages visited
Purchasing behaviour/purchase history
Purpose and legal basis
Your data is processed for the purpose of sending and personalising the newsletter, as well as for measuring the reach and evaluating the success of marketing measures. The legal basis is your consent in accordance with Article 6(1)(a) of the GDPR.
Withdrawal/Objection
You may withdraw your consent to receive newsletters at any time with future effect, or object to the use of your data for direct marketing purposes. You can do this via the unsubscribe link at the end of each newsletter or, alternatively, by sending an email to unsubscribe@emarsys.com. Following your withdrawal, your personal data will be deleted from the mailing list, provided there are no legal retention obligations to the contrary.
Retention period
Your data will only be stored for as long as your newsletter subscription remains active. Following unsubscription or withdrawal of consent, your data will be deleted or blocked, provided there are no legal requirements to the contrary.
Further details on data processing can be found in Emarsys’ privacy policy at: emarsys.com/de/privacy-policy/.
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Blog with comment function
Scope of data processing
Our website offers the option to use the blog with a comment function. When using this function, the data entered in the input form is transmitted to us.
Name
Email address
IP address
Comments
Your consent is sought for the processing of data as part of the commenting process, and reference is made to this privacy policy.
10.2 Purpose & legal basis for data processing
The legal basis for processing data relating to the user’s use of the blog’s commenting function is Article 6(1)(a) of the GDPR, provided the user has given their consent. The collection of the personal data referred to in 10.1 as part of the commenting process serves to prevent misuse of the services or the email address provided.
10.4 Duration of storage
The data will be deleted as soon as it is no longer required to fulfil the purpose for which it was collected. The user’s email address will therefore be stored for as long as the comment remains active on our blog.
10.5 Right to object and right to erasure
You can prevent the storage and disclosure of your personal data by not using the comment function.
Registration of a customer account
Processing of customer and contract data
We collect, process and use your personal data only to the extent necessary for the establishment, amendment or fulfilment of a legal relationship. This is done for the purpose of fulfilling a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.
The customer data collected will be deleted upon completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Data transfer upon conclusion of a contract for online shops, retailers and goods dispatch
We only transfer personal data where this is necessary for the performance of the contract, for example to delivery service providers or the bank responsible for payment processing. No further transfer of data takes place, or only if you have expressly consented to such transfer.
The basis for data processing is the performance of a contract or pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.
Credit checks
In the case of a purchase on account or any other payment method where we provide the goods or services in advance, we may carry out a credit check (scoring). To this end, we will transfer the data you have entered (e.g. name, address, age or bank details) to a credit reference agency. On the basis of this data, the probability of non-payment is determined. If the risk of non-payment is excessive, we may refuse the payment method in question.
The basis for data processing is the performance of a contract or pre-contractual measures pursuant to Article 6(1)(b) of the GDPR, as well as the prevention of payment defaults (legitimate interest pursuant to Article 6(1)(f) of the GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; consent may be withdrawn at any time.
Payment services
We integrate third-party payment services into our website. When you make a purchase from us, your payment details (e.g. name, payment amount, bank account details, credit card number) are processed by the payment service provider for the purpose of payment processing; the respective contractual and data protection provisions of the relevant providers apply. The basis for data processing is the performance of a contract or pre-contractual measures pursuant to Article 6(1)(b) of the GDPR, as well as in the interest of ensuring a payment process that is as smooth, convenient and secure as possible (Article 6(1)(f) of the GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; consent may be withdrawn at any time.
We use the following payment service providers:
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).
Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
Please refer to PayPal’s privacy policy for further details: www.paypal.com/de/webapps/mpp/ua/privacy-full.
Apple Pay
The payment service provider is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple’s privacy policy can be found at: www.apple.com/legal/privacy/de-ww/.
Klarna
The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter “Klarna”). Klarna offers various payment options (e.g. instalment purchases). If you choose to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimise the use of the Klarna checkout solution. For details on the use of Klarna cookies, please refer to the following link: cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
You can read more about this in Klarna’s privacy policy at the following link: www.klarna.com/de/datenschutz/.
Sofortüberweisung
The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter “Sofort GmbH”). With the help of an “Sofortüberweisung”, we receive a payment confirmation from Sofort GmbH in real time and can immediately begin fulfilling our obligations.
With a “Sofortüberweisung”, you provide Sofort GmbH with your PIN and a valid TAN, which they use to log in to your online banking account. After logging in, Sofort GmbH automatically checks your account balance, your transactions, the overdraft limit and the existence of other accounts, and carries out the transfer to us using the TAN you have provided. It then immediately sends us a transaction confirmation. In addition to the PIN and TAN, the following data entered by you is also transmitted to Sofort GmbH: first name and surname, address, telephone number(s), email address, IP address and, where applicable, any further data required for payment processing. The transmission of this data is necessary to verify your identity beyond doubt and to prevent fraud. For details on paying via Sofortüberweisung, please refer to the following links: www.sofort.de/datenschutz.html and www.klarna.com/sofort/.
Amazon Pay
The provider of this payment service is Amazon Payments Europe S.C.A., 38 avenue J.F. Kennedy, L-1855 Luxembourg.
You can find details on how your data is handled in the Amazon Pay Privacy Policy at the following link: pay.amazon.de/help/201212490.
Mondu
The provider of this payment service is Mondu GmbH, Alexanderstraße 36, 10179 Berlin.
You can find details on how your data is handled in the provider’s privacy policy: www.mondu.ai/de/privacy-policy/
American Express
The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter “American Express”).
American Express may transfer data to its parent company in the USA. The data transfer to the USA is based on the Binding Corporate Rules. Further details can be found here: www.americanexpress.com/en-pl/company/legal/privacy-centre/european-implementing-principles/.
For further information, please refer to the American Express Privacy Policy: www.americanexpress.com/de/legal/online-datenschutzerklarung.html.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter “Mastercard”).
Mastercard may transfer data to its parent company in the USA. The transfer of data to the USA is based on Mastercard’s Binding Corporate Rules. Details can be found here: www.mastercard.de/de- de/datenschutz.html and www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
VISA
The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).
The United Kingdom is considered a safe third country for data protection purposes. This means that the United Kingdom has a level of data protection equivalent to that in the European Union.
VISA may transfer data to its parent company in the USA. The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.
For further information, please refer to VISA’s privacy policy: www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
Presence on social media platforms
We maintain public profiles on various social networks via our website. You can find more detailed information about the social networks we use in the relevant sections of our privacy policy.
Social networks such as Facebook, Twitter and others can comprehensively analyse your user behaviour when you visit their websites or a website with integrated social media content (e.g. ‘Like’ buttons or advertising banners). Visiting our social media pages triggers numerous data processing operations relevant to data protection:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal may associate this visit with your user account. However, your personal data may also be collected even if you are not logged in or do not have an account with the relevant social media portal. In this case, data collection takes place, for example, via cookies stored on your device or by recording your IP address.
Using the data collected in this way, the operators of the social media platforms can create user profiles containing your preferences and interests. This enables interest-based advertising to be displayed to you both within and outside the respective social media platform. If you have an account with the relevant social network, interest-based advertising may be displayed on all devices on which you are logged in or have been logged in.
Please note that we cannot track all processing activities on social media platforms. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media platforms. For details, please refer to the terms of use and privacy policies of the respective social media platforms.
Legal basis for data processing
Our social media presence serves to ensure the most comprehensive online presence possible. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The analysis processes initiated by the social networks may be based on different legal grounds, which must be specified by the operators of the social networks (e.g. consent within the meaning of Article 6(1)(a) of the GDPR).
Data controller and exercising of rights
When you visit our social media pages (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both against us and against the operator of the relevant social media portal (e.g. against Facebook).
Despite our joint responsibility with the social media portal operators, we do not have full control over the data processing operations of the social media portals. Our options depend largely on the corporate policy of the respective provider.
Duration of data storage
Data collected directly by us via our social media presence will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.
We have no influence over the duration of storage of your data that is stored by the operators of social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. via their privacy policy, see below).
Facebook page
Our company has a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter ‘Meta’). According to Meta, the data collected is also transferred to the USA and other third countries.
We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement sets out which data processing operations we and Meta are responsible for when you visit our Facebook page. You can view the agreement via the following link: www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in: www.facebook.com/settings.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA . Certification under the DPF obliges companies to adhere to these data protection standards.
Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Details can be found here: www.facebook.com/legal/EU_data_transfer_addendum and de-de.facebook.com/help/566994660333381.
For further information, please refer to Facebook’s privacy policy: www.facebook.com/about/privacy/.
Instagram page
Our company has a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.
Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: www.facebook.com/legal/EU_data_transfer_addendum, help.instagram.com/519522125107875 and de-de.facebook.com/help/566994660333381.
For further information on how your personal data is handled, please refer to Instagram’s privacy policy: help.instagram.com/519522125107875.
Twitter page
Our company uses the short message service X (formerly Twitter). The provider is Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.
You can adjust your X privacy settings yourself in your user account; to do so, log in via the following link: x.com/settings/account/personalization.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.
Data transfers to the US are based on the EU Commission’s Standard Contractual Clauses. Details can be found here: gdpr.x.com/en/controller-to-controller-transfers.html.
For further information, please refer to X’s privacy policy: x.com/de/privacy.
Video Conferencing
Data processing
We use online conferencing tools to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference, your personal data is collected and processed by us and the provider of the relevant tool.
The tools collect the data you provide, including your email address and telephone number. They also process the duration of the conference, when you joined the conference, the number of participants and other metadata.
In addition, the tool provider processes all technical data necessary for the conference to take place. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.
When you share content via this service, it is stored on the providers’ servers. This includes cloud recordings, chat messages, voice messages, as well as photos and videos that you have shared whilst using this service.
Please note that we do not have full control over the data processing operations of the tools used. For further details on data processing by the conference tools, please refer to the privacy policies of the respective tools used.
Purpose and legal basis
The conference tools are used to communicate with prospective or existing contractual partners or to offer specific services to our customers (Art. 6(1)(b) GDPR). Furthermore, the use of the tools serves to generally simplify and expedite communication with us or our company (legitimate interest within the meaning of Art. 6(1)(f) GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; consent may be withdrawn at any time.
Retention period
The data collected directly by us via the video and conferencing tools will be deleted from our systems as soon as you request us to do so, withdraw your consent to storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected.
We have no influence over the storage period of your data that is stored by the operators of the conference tools for their own purposes. For further details, please contact the operators of the conference tools directly.
Video conferencing tools used:
Microsoft Teams
We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to the Microsoft Teams privacy policy: privacy.microsoft.com/de-de/privacystatement.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: www.dataprivacyframework.gov/s/participant-search/participant-detail
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider. Website visitors’ data is processed solely in accordance with our instructions and in compliance with the GDPR.
We have a profile on Pinterest. The operator is Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland. For details on how they handle your personal data, please refer to Pinterest’s privacy policy: policy.pinterest.com/de/privacy-policy.
TikTok
Our company has a profile on TikTok. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. For further information on how your personal data is handled, please refer to TikTok’s privacy policy: www.tiktok.com/legal/page/eea/privacy-policy/de.
YouTube
We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For details on how they handle your personal data, please refer to YouTube’s privacy policy: policies.google.com/privacy.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards.
Services and tools used
YouTube Video
This website embeds videos from YouTube. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use YouTube in enhanced privacy mode. According to YouTube, this mode ensures that no information about visitors to the website is stored before the video is viewed. However, the enhanced privacy mode does not necessarily prevent the transfer of data to YouTube partners. YouTube establishes a connection to the Google DoubleClick network, regardless of whether you watch a video.
When you start a YouTube video on this website, a connection is established with their servers. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you also allow YouTube to associate your browsing behaviour with your personal profile. You can prevent this by logging out of your account. Once a video has started, YouTube may store various cookies on your device or use comparable recognition technologies, such as device fingerprinting. This allows YouTube to obtain information about visitors to this website. This information is used, amongst other things, to collect video statistics, improve user-friendliness and prevent fraud. It cannot be ruled out that further data processing operations may take place after a video has started, over which we have no control.
Legal basis
The use of YouTube is based on our legitimate interest in presenting our online services in an appealing manner (Art. 6(1)(f) GDPR). If consent has been requested, the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. This consent may be withdrawn at any time.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the US that aims to ensure compliance with European data protection standards when processing data in the US. Certification under the DPF requires companies to adhere to these data protection standards.
Further information on data protection on YouTube can be found in the privacy policy: policies.google.com/privacy.
YouTube with enhanced data protection
Nature and scope of data processing
This website embeds videos from YouTube. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use YouTube in enhanced privacy mode. According to YouTube, this mode ensures that no information about visitors to the website is stored before the video is viewed. However, the enhanced privacy mode does not necessarily prevent data from being passed on to YouTube partners. YouTube establishes a connection to the Google DoubleClick network, regardless of whether you watch a video.
When you start a YouTube video on this website, a connection is established with their servers. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you also allow YouTube to associate your browsing behaviour with your personal profile. You can prevent this by logging out of your account. Once a video has started, YouTube may store various cookies on your device or use comparable recognition technologies , such as device fingerprinting. This allows YouTube to obtain information about visitors to this website. This information is used, amongst other things, to collect video statistics, improve user-friendliness and prevent fraud. It cannot be ruled out that further data processing operations may take place after a video has started, over which we have no control.
Legal basis
The use of YouTube is based on our legitimate interest in presenting our online services in an appealing manner (Art. 6(1)(f) GDPR). If consent has been requested, the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. Further information on data protection at YouTube can be found in the privacy policy: policies.google.com/privacy.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: www.dataprivacyframework.gov/s/participant-search/participant-detail
Google Play
To provide the content of our website efficiently and securely, we use Google Play CDN, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
Google Play CDN acts as a Content Delivery Network (CDN) on our website. A CDN supports the rapid delivery of website content, in particular files such as graphics or scripts, through the use of regionally or internationally distributed servers. When you access this content, your device connects to Google’s servers. In doing so, your IP address and, where applicable, further browser data such as your user agent are transmitted. This data is processed exclusively for the purpose of providing the service and to ensure the security and functionality of Google Play CDN. Further information can be found in the Google Play CDN Privacy Policy: policies.google.com/privacy.
Legal basis
The use of Google Play CDN is based on Article 6(1)(f) of the GDPR, as we have a legitimate interest in providing the content of our website efficiently and securely.
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Google DoubleClick
On this website, we use services and functions provided by Google DoubleClick, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
Google DoubleClick enables us to display targeted advertisements in Google applications that match users’ interests. In order to provide relevant advertising, Google DoubleClick must identify users and link their website visits, clicks and other information to their user behaviour. To do this, Google DoubleClick uses cookies and technologies to recognise users and creates pseudonymised user profiles based on the data collected.
You can disable this personalised advertising in your personal Google account at policies.google.com/technologies/ads and adssettings.google.com/authenticated.
Legal basis
When using Google DoubleClick, we rely on Article 6(1)(f) of the GDPR as the legal basis, as we have a legitimate interest in analysing the use of our website. This enables us to optimise our online presence and offerings for you. If you have previously given your consent to data processing by Google DoubleClick on this website, the processing of your data takes place on the legal basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG. You may withdraw your consent at any time.
Google API
On our website, we use the services and functions of Google APIs, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
Google APIs allow us to access additional services and data from Google. When using these services, your IP address is transmitted to Google Ireland Limited. Please note that we provide specific information in our privacy policy for each additional Google service that we use. Further information on Google APIs and data protection can be found in Google’s privacy policy: policies.google.com/privacy.
Legal basis
We use Google APIs based on our legitimate interests (i.e. the interest in optimising our online offering), in accordance with Article 6(1)(f) of the GDPR. Where we seek consent (e.g. consent to the storage of cookies), data processing takes place exclusively on the basis of Article 6(1)(a) of the GDPR; you may withdraw this consent at any time.
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Gstatic
On this website, we use functions provided by Gstatic, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
Gstatic is a service provided by Google to speed up the loading of web pages. Gstatic stores website resources such as images, CSS and JavaScript files on its servers in order to deliver them to the user more quickly when the page is visited again. During this data processing, technical information, such as your IP address and technical details of your browser, is transmitted to Gstatic.
The user profiles created by Gstatic are pseudonymised and cannot be traced directly back to you as an individual.
Further information on this can be found in Google’s privacy policy: policies.google.com/privacy.
Legal basis
The use of Gstatic on this website is based on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG. You have the right to withdraw your consent at any time.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: www.dataprivacyframework.gov/s/participant-search/participant-detail
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Google Fonts
Nature and scope of data processing
This website uses web fonts to ensure consistent display of fonts provided by Google. When you visit the page, your browser loads the required web fonts into your browser cache so that text and fonts are displayed correctly. To do this, the browser you are using at establishes a connection to Google’s servers. As a result, Google becomes aware of your IP address.
Legal basis
The use of Google Web Fonts is based on our legitimate interest in ensuring a consistent display of the typography on our website (Art. 6(1)(f) GDPR). If consent has been requested (e.g. consent to the storage of cookies), the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. If your browser does not support Web Fonts, a standard font from your computer will be used. Further information on Google Web Fonts can be found here: developers.google.com/fonts/faq. Google’s privacy policy can be found here: policies.google.com/privacy.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: www.dataprivacyframework.gov/s/participant-search/participant-detail
Hotjar
Our website uses services and features provided by Hotjar, an analytics tool operated by Hotjar Limited, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe.
Nature and scope of data processing
With the help of Hotjar, we are able to analyse user behaviour on our website. This analysis records the mouse actions you perform, how long you view certain content, and other interactions. Hotjar then creates ‘heatmaps’ that show us which areas of the website are visited most frequently by visitors.
In addition, Hotjar provides us with information on how long you stay on a page, when you leave it, and when you abandon your entries in a contact form. As a visitor to our website, you also have the option to provide direct feedback on the website. Hotjar uses technologies (such as cookies or fingerprinting systems) to recognise website visitors on repeat visits.
Legal basis
The processing of personal data is carried out on the basis of Article 6(1)(f) of the GDPR, as we have a legitimate interest in analysing website usage in order to optimise our online presence and offerings. If you have given your consent to data processing by Hotjar on this website, processing takes place on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. You may withdraw your consent at any time.
Disabling Hotjar
If you object to the processing of your personal data by Hotjar, you can deactivate tracking. Please note that this must be done separately for each browser or device. You can find detailed instructions on how to do this at www.hotjar.com/opt-out. Further information on the processing of your user data can be found in Hotjar’s privacy policy at www.hotjar.com/privacy.
Data processing
To ensure that personal data is processed in accordance with our guidelines and in compliance with the GDPR, we have entered into a Data Processing Agreement (DPA) with Hotjar.
Roeye CDN
Nature and scope of processing
We use the Content Delivery Network (“Roeye CDN”) provided by Roeye, operated by Roeye, San Francisco, CA, USA, to deliver certain content on our website (e.g. scripts or other technical resources) more quickly and reliably via distributed servers. When this content is accessed, your IP address and technical information about your browser and device are processed and logged in server log files. Roeye may use cookies or similar technologies for this purpose to technically route requests and ensure the delivery and security of the services.
Purpose, legal basis and transfer to third countries
The purpose of the processing is to improve the performance, stability and security of our website. Insofar as only technically necessary data is processed, this is done on the basis of Article 6(1)(f) of the GDPR (legitimate interest in the secure and efficient provision of our online services). Where Roeye CDN uses cookies or comparable technologies that go beyond purely technical operation, this is based on your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG, which you may withdraw at any time via our consent/cookie tool.
The use of Roeye CDN involves the transfer of data to the USA; where necessary, we rely on appropriate safeguards in accordance with Article 44 et seq. of the GDPR (e.g. EU Standard Contractual Clauses).
Further information on data processing can be found in Roeye’s privacy policy
TikTok Analytics
Nature and scope of processing
We use TikTok Analytics from Beijing Bytedance Technology Ltd., Beijing, China, to analyse the use of our online offering and to obtain statistical analyses of the reach, interactions and performance of our content. To this end, TikTok Analytics processes, in particular, information about the content you access, how you interact with our content (e.g. views, clicks, time spent on the site), as well as technical data relating to your device and browser. TikTok uses cookies and similar technologies for this purpose, which enable the use of our online offering to be recorded and attributed to pseudonymous users or user groups.
Purpose and legal basis
The purpose of the processing is to analyse and improve our online offering, as well as to optimise our content and marketing activities on TikTok and any linked services. The use of TikTok Analytics is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the use of cookies or similar technologies falls under these provisions. You may withdraw your consent at any time with future effect via our consent/cookie management tool.
Retention period
The specific retention period for the processed data is determined by TikTok Technology Limited and is beyond our direct control. For further information on the processing of personal data in connection with TikTok services and your rights, please refer to TikTok’s Privacy Policy at: www.tiktok.com/legal/privacy-policy.
AWIN
Nature and scope of processing
We participate in affiliate partner programmes. The operator of the affiliate network is AWIN AG, Otto-Ostrowski Straße 1A, 10249 Berlin (hereinafter: “AWIN”). If you click on an advertisement for our website and then make a purchase, we receive money from the companies that advertise with us. For this to work, our advertising partners must be able to track that you clicked on an advertisement and then purchased the product. They do this using cookies or similar technologies.
Purpose and legal basis
The storage and analysis of data is carried out on the basis of Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in the correct calculation of its affiliate remuneration. If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; consent may be withdrawn at any time.
We are jointly responsible with AWIN and, where applicable, with the advertiser for data processing in connection with the affiliate programme. We have concluded a joint processing agreement with the provider, under which you, as the data subject, may contact any of the controllers with your enquiry. This agreement is available in AWIN’s Terms and Conditions at the following link: s3.amazonaws.com/docs.awin.com/Legal/Publisher+Terms/2020/DE+Publisher+Terms+GDPR+Annex.pdf.
AppNexus
Nature and scope of processing
We have integrated AppNexus into our website. AppNexus is a service provided by AppNexus Inc. to display targeted advertising to users. AppNexus uses cookies and other browser technologies to analyse user behaviour and recognise users.
AppNexus collects information about visitor behaviour on various websites. This information is used to optimise the relevance of the advertising. Furthermore, AppNexus delivers targeted advertising based on behavioural profiles and geographical location. Your IP address and other identifying characteristics, such as your user agent, are transmitted to the provider.
In this case, your data is passed on to the operator of AppNexus, AppNexus Inc.
Purpose and legal basis
The use of AppNexus is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Retention period
We have no influence over the specific storage period of the processed data; this is determined by AppNexus Inc. Further information can be found in the AppNexus privacy policy: www.appnexus.com/de/platform-privacy-policy.
Fast Fonts
We use Fast Fonts from Monotype Imaging Inc., 600 Unicorn Park Drive, Woburn, Massachusetts 01801 USA, as a service for providing fonts for our online offering. To access these fonts, a connection is established with Monotype Imaging Inc.’s servers, during which your IP address is transmitted.
Purpose and legal basis
The use of Fast Fonts is based on your consent in accordance with Article 6(1)(a) of the GDPR.
The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
Retention period
We have no influence over the specific retention period of the processed data; this is determined by Monotype Imaging Inc. Further information can be found in the privacy policy for Fast Fonts: www.monotype.com/legal/privacy-policy.
ID5
Nature and scope of processing
We use the ID5 service provided by ID5 Technology, Ltd., 199 Bishopsgate, London EC2M 3TY, United Kingdom, to display specific and relevant advertisements to user groups using targeting technologies.
Web tracking technologies are used to create pseudonymised user profiles. These profiles cannot generally be linked to you as a natural person, but are used, for example, for segmentation when displaying advertisements.
Purpose and legal basis
The use of ID5 is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Retention period
We have no influence over the specific retention period of the processed data; this is determined by ID5 Technology, Ltd. Further information can be found in the ID5 privacy policy: trg.de/datenschutzerklarung/.
Matomo
Our website uses services and functions of the open-source web analytics service Matomo (formerly Piwik) to analyse the user behaviour of our website visitors.
Nature and scope of data processing
With the help of Matomo, we can, for example, determine at what times and from where visitors have viewed specific pages. We also collect and store data such as IP addresses, browsers used and operating systems. This information helps us understand what actions you have taken on our website (e.g. clicked on specific pages, made purchases, etc.). Matomo uses technologies (such as cookies or fingerprinting systems) to recognise visitors when they return to our website. The information collected by Matomo regarding the use of this website is stored on our server. Your IP address is anonymised before it is stored.
Legal basis
The processing of personal data is carried out on the basis of Article 6(1)(f) of the GDPR and Section 25(1) of the TDDDG, as we have a legitimate interest in analysing website usage in order to optimise our online presence and services. If you have given your consent to data processing by Matomo on this website, the processing of your data takes place on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time.
IP anonymisation
When using Matomo on this website, we employ a function that truncates your IP address prior to analysis. As a result, it can no longer be uniquely attributed to you.
Hosting
The data collected through the analysis is not passed on to third parties, as we host Matomo exclusively on our own servers.
PayPal
Nature and scope of processing
We have integrated PayPal components into our website. PayPal is a service provided by PayPal Pte. Ltd. and offers online payment solutions worldwide.
If you choose PayPal as your payment method, the data required for the payment transaction will be automatically transmitted to PayPal Pte. Ltd., San Jose, California, USA.
In this context, the following data is generally collected: name, address, company (if applicable), email address, telephone and mobile numbers, and IP address.
Purpose and legal basis
Use of the service is based on the performance of a contract, i.e. for the processing of payment transactions in accordance with Article 6(1)(b) of the GDPR.
Retention period
We have no influence over the specific retention period of the processed data; this is determined by PayPal Pte. Ltd. Further information can be found in PayPal’s privacy policy: www.paypal.com/de/webapps/mpp/ua/privacy-full.
On this website, we use the service of the online price comparison portal billiger.de, operated by solute GmbH, Zeppelinstraße 15, 76185 Karlsruhe, Germany.
We use billiger.de to present you with suitable offers and price comparisons on our website. When you visit a page integrated with billiger.de, a connection is established with the provider’s servers. In the process, information about your user behaviour, such as product pages visited, offers clicked on and, where applicable, orders placed, is collected.
Purpose and legal basis
For the use of billiger.de, we rely on Article 6(1)(f) of the GDPR as the legal basis for tracking and analysing advertising performance, as there is a legitimate interest in the efficient marketing of our online offering. If you have previously given your consent to data processing by billiger.de on this website, the processing of your data is based solely on Article 6(1)(a) of the GDPR. You may withdraw your consent at any time.
Retention period
billiger.de stores the collected data for the attribution of advertising results and remunerated sales for a maximum of the period required for technical and contractual purposes (e.g. up to 30 days for commission tracking, cookies up to 2 years where applicable). The data is subsequently deleted or anonymised. Further information can be found in the privacy policy of billiger.de: www.billiger.de/info/legal/datenschutz
Data processing
solute GmbH may use data processors and appropriate data protection mechanisms to ensure the secure processing of your data. Personal data will only be transferred outside the EU in compliance with legal requirements and appropriate safeguards.
Further information on data processing can be found in the privacy policy of billiger.de at: merch.billiger.de/datenschutz
ausgezeichnet.org seal
Nature and scope of processing
We have integrated components from ausgezeichnet.org Seal on our website. ausgezeichnet.org Seal is a rating service that enables users to rate our services. If you rate our services, data regarding the service used may be transmitted to AUBII GmbH to verify authenticity. ausgezeichnet.org Siegel enables us to obtain content such as ratings directly from AUBII GmbH and display it on our website. To this end, your current IP address is usually transmitted to the service.
Furthermore, ausgezeichnet.org Siegel stores information using cookies to determine which online services have been visited. In this case, your data is transferred to the operator of ausgezeichnet.org Siegel, AUBII GmbH, Alsterufer 34, 20354 Hamburg, Germany.
Purpose and legal basis
The use of the ausgezeichnet.org seal is based on Article 6(1)(f) of the GDPR, to inform users about the quality of our services. If the user consents to the processing of their data, the legal basis for the processing is Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Retention period
We have no influence over the specific retention period of the processed data; this is determined by AUBII GmbH. Further information can be found in the privacy policy for the ausgezeichnet.org seal: www.ausgezeichnet.org/datenschutz/.
hCaptcha
Nature and scope of processing
We have integrated components from hCaptcha into our website. hCaptcha is a service provided by Intuition Machines, Inc. and enables us to distinguish whether a contact request originates from a natural person or is generated automatically by a programme. When you access this content, you establish a connection to servers operated by Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, United States, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. Furthermore, hCaptcha records the user’s dwell time and mouse movements in order to distinguish automated requests from human ones. This data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of hCaptcha.
Purpose and legal basis
The use of hCaptcha is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Retention period
We have no influence over the specific retention period of the processed data; this is determined by Intuition Machines, Inc. Further information can be found in the privacy policy for hCaptcha: www.hcaptcha.com/privacy.
trbo (including trbo CDN)
Nature and scope of processing
We use the services of trbo GmbH, Leopoldstraße 41–42, 80802 Munich, Germany (“trbo”), to personalise the content of our website in real time, carry out A/B testing and evaluate the use of our online offering. To this end, trbo uses, among other things, a Content Delivery Network (CDN) through which scripts and other technical resources are delivered. When using trbo, information about your usage behaviour (e.g. pages visited, clicks, time spent on site), technical data about your device and browser, and your IP address are processed. trbo uses cookies and similar technologies for this purpose to recognise returning users, create segments and display personalised content.
Purpose and legal basis
The purpose of the processing is to optimise and personalise our online offering, to carry out tests, and to improve the user experience and conversion rates. Insofar as cookies or comparable technologies are used for this purpose, the use of trbo is based on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You may withdraw your consent at any time with future effect via our consent/cookie management tool. Insofar as trbo also processes only technically necessary data for the delivery of content via the CDN, this is done on the basis of Article 6(1)(f) of the GDPR; our legitimate interest lies in the secure and efficient provision of our online offering.
Further information on data processing by trbo and on your rights as a data subject can be found in trbo GmbH’s privacy policy at www.trbo.com/datenschutz/.
Zenloop
On this website, we use services and functions provided by Zenloop, which are offered by Zenloop GmbH, Habersaathstraße 58, 10115 Berlin, Germany.
We use Zenloop, a business-to-business Software-as-a-Service platform, for customer surveys and product reviews. We pass on your email address to the provider so that they can send you an invitation to the survey. When you use the feedback tool, Zenloop collects data about your location, your device and your browser, as well as the website you came from. Zenloop also uses cookies and similar technologies to collect data about users in general. Furthermore, Zenloop stores your survey responses.
When using zenloop, we rely on your consent in accordance with Article 6(1)(a) of the GDPR as the legal basis for the processing and disclosure of your personal data. You may withdraw your consent at any time.
Further information on data processing can be found in zenloop’s privacy policy at www.zenloop.com/de/legal/privacy.
Data processing
We have entered into a data processing agreement (DPA) with zenloop for the processing of data. The agreement guarantees that zenloop will process the data collected through the analysis only in accordance with our instructions and in compliance with the provisions of the General Data Protection Regulation (GDPR).
Use of Yotpo for product reviews
We use the Yotpo tool on our platform, provided by Yotpo Ltd., 33 West 19th Street, 5th Floor, New York, NY 10011, USA. This service enables users of our platform to submit and view product reviews and testimonials. This allows us to present our range of services transparently and helps other users make informed purchasing and usage decisions.
Purpose and legal basis
The processing of data provided in the context of reviews is based on the fulfilment of contractual obligations within the meaning of Article 6(1)(b) of the GDPR, as the use of the review tool forms part of the contractual service provision on our platform. Without the processing of this data, it would not be possible to create and publish reviews.
Yotpo stores and processes the review details provided by the user (e.g. name, review text, and any additional information provided) on the provider’s servers. Data is only disclosed to third parties in connection with the provision and publication of the reviews.
Please note that this may involve the transfer of personal data to the USA. The company is certified under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
The transfer of your personal data to the USA is based on the EU Commission’s Standard Contractual Clauses.
Right of withdrawal and objection:
Users have the right at any time to withdraw their consent to the publication of a submitted review with effect for the future or to object to the further processing of their data (Art. 21 GDPR). In this case, the review in question will be deleted or further processing of the personal data will be discontinued, provided there are no compelling legitimate grounds for the processing. The withdrawal or objection may be submitted informally to the contact details provided in the legal notice or to our Data Protection Officer.
Further information on the purpose and scope of data collection, as well as on further processing by Yotpo, can be found in Yotpo’s privacy policy at: www.yotpo.com/privacy-policy.
Mediavine
We use Mediavine technologies on our website. The provider is Mediavine, Inc., 160 W. Camino Real #504, Boca Raton, Florida 33432, USA.
Mediavine is an advertising tool that enables us to display targeted and personalised advertising to our users. To do this, we use cookies and similar technologies that analyse user behaviour and recognise users on our site.
The information collected by these technologies helps us to optimise the relevance of the advertisements we display.
The use of Mediavine is based on Article 6(1)(f) of the GDPR, as we have a legitimate interest in continuously improving our online offering and our advertisements. If you have consented to data processing by Mediavine, the processing is carried out on the legal basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG. You may withdraw your consent at any time.
Further information on data processing can be found in Mediavine’s privacy policy at www.mediavine.com/privacy-policy/.
Wayvia
On this website, we use the analytics and commerce enablement solutions provided by Wayvia, 20 Pacifica, Suite 250, Irvine, CA 92618, USA.
Wayvia helps us to record and analyse usage behaviour and purchasing decisions at affiliated retailers. When you visit a page with an integrated Wayvia module, a connection is established with Wayvia’s servers. In the process, information such as your browser type, your operating system, product pages visited, offers clicked on, and an anonymous user ID may be collected. The IP address is stored for a maximum of 14 days solely for IT security purposes and is subsequently deleted.
Purpose and legal basis
The Wayvia module is used to better understand buyer interests and to optimise referrals to retailers and points of sale. The processing of personal data is carried out exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR, which you can give via our consent/cookie banner. You may withdraw your consent at any time with effect for the future.
Retention period
Personal data such as IP addresses are deleted by Wayvia after 14 days at the latest. Aggregated usage data and anonymous identifiers are retained for trend analysis and statistics, but are not used for personal identification.
Data processing and data transfer
The processing of the collected data is carried out by Wayvia in the USA. For the transfer of personal data outside the EU/EEA, Wayvia uses the European Commission’s Standard Contractual Clauses as a safeguard.
Further information on data processing can be found in Wayvia’s privacy policy: wayvia.com/privacy-police
RecoBounce
On this website, we use the service and conversion tool RecoBounce from RecoBounce GmbH, Meerkamp 61, 26133 Oldenburg, Germany.
RecoBounce helps us to win back users who have left the site and convert them into orders by displaying targeted dynamic content. When you visit a page with the RecoBounce module, a connection is established with the provider’s servers. In doing so, technical information such as your IP address (truncated/anonymised), browser information, pages visited and interaction data may be collected and evaluated in pseudonymised form.
Purpose and legal basis
Personal data is processed to improve the user experience, analyse exit behaviour and optimise our online shop. Data processing is carried out exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR, which you provide via our consent/cookie banner. You may withdraw your consent at any time.
Retention period
The data collected by RecoBounce will be deleted or anonymised once the purpose for which it was collected no longer applies or upon withdrawal of your consent. Cookies and similar technologies have a technically limited lifespan and will be deleted upon withdrawal of consent.
Data processing
We have entered into a data processing agreement with RecoBounce GmbH in accordance with Article 28 of the GDPR, which ensures the protection of your data. Processing takes place exclusively within Germany or the EU in accordance with applicable data protection regulations under the GDPR.
Further information can be found in RecoBounce’s privacy policy at: recobounce.com/datenschutz/
Sovendus
On this website, we use the services of Sovendus GmbH, Bahnhofplatz 12, 76137 Karlsruhe, Germany.
Sovendus enables us to display voucher and promotional offers, as well as checkout, mailing and conversion marketing solutions, in order to reward our customers in a targeted manner, generate additional revenue and improve the customer experience. When you visit our website or click on voucher offers, Sovendus processes pseudonymised usage data such as session ID, order number, order value, voucher code, timestamp and hashed email address. Your IP address is collected solely for data security purposes and is usually anonymised after seven days.
Purpose and legal basis
The processing of personal data is carried out for the purpose of successfully facilitating voucher offers and optimising conversion processes on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR and, where necessary, your consent pursuant to Article 6(1)(a) of the GDPR. You may object to the use and analysis of your data at any time or withdraw any consent you have given.
Retention period
Personal data such as IP addresses are anonymised by Sovendus within seven days at the latest. Further data relating to voucher processing, such as order values or coupon codes, are stored exclusively in pseudonymised form and deleted once the purpose has been fulfilled.
Data processing and data security
We have a data processing agreement with Sovendus in accordance with Article 28 of the GDPR.
Further information can be found in Sovendus’ privacy policy at: online.sovendus.com/online-datenschutzhinweise/
DYMATRIX (formerly econda)
On this website, we use the data protection-compliant analytics and marketing solutions provided by DYMATRIX GmbH, Lautenschlagerstraße 2, 70173 Stuttgart, Germany.
DYMATRIX enables us to carry out technical and statistical analysis of your user behaviour, as well as to optimise and personalise our online offering. When you visit pages containing DYMATRIX components, a connection is established with the provider’s servers. In the process, your IP address (truncated/anonymised), device and browser information, pages visited, interactions and click paths, amongst other things, may be collected and stored in pseudonymous user profiles.
Purpose and legal basis
Data processing is carried out exclusively on the basis of your explicit consent in accordance with Article 6(1)(a) of the GDPR via our consent/cookie banner. You may withdraw your consent at any time with effect for the future. The data is not used for personal identification and is not merged with other data.
Retention period
The data collected within the framework of DYMATRIX is anonymised or deleted when the purpose for which it was collected no longer applies or you withdraw your consent. Cookies and similar technologies used for usage analysis have a technically limited duration and are deleted upon withdrawal of consent.
Data processing
A data processing agreement in accordance with Article 28 of the GDPR has been concluded with DYMATRIX GmbH, which ensures the protection of your data. Your data is processed exclusively within Germany or the EU.
Further information on data processing by DYMATRIX can be found in the provider’s privacy policy at: www.dymatrix.de/de/datenschutz
Improve Digital
We use “Improve Digital”, a service provided by Azerion Services B.V, Boeing Avenue 30, 1119 PE SCHIPHOL-RIJK, Netherlands (hereinafter referred to as: “Improve Digital”).
Nature and scope of processing
We use Improve Digital for marketing and optimisation purposes, in particular to analyse the use of our website and to continuously improve individual functions and offers as well as the user experience. By statistically evaluating user behaviour, we can improve our offering and make it more interesting for you as a user.
Purpose and legal basis
The use of Improve Digital is based on Article 6(1)(f) of the GDPR, as we have a legitimate interest in continuously improving our online offering and our advertisements. If you have consented to data processing by Improve Digital, the processing is carried out on the legal basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG. You may withdraw your consent at any time.
Further information on data processing can be found at improvedigital.com/platform-privacy-policy/.
Last updated on: 16 June 2026