Política de privacidad
1. Data protection at a glance
General notes
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on data protection can be found in our privacy policy listed below this text.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the section "Notice of the responsible party" in this privacy policy.
How do we collect your data?
Your data is collected partly by you providing it to us. This can be, for example, data you enter into a contact form.
Other data is automatically collected or collected with your consent when visiting the website by our IT systems. These are mainly technical data (e.g., internet browser, operating system, or time of page access). The collection of this data takes place automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right at any time to receive free information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have the right to request the restriction of the processing of your personal data under certain circumstances. Additionally, you have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this or any other questions about data protection.
Analytics tools and third-party tools
When visiting this website, your browsing behavior may be statistically analyzed. This is mainly done using so-called analytics programs.
Detailed information about these analytics programs can be found in the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
Shopify
The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter "Shopify").
Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address as well as information about the device and browser you use. Shopify also analyzes visitor numbers, visitor sources, and customer behavior, and creates user statistics. If you make a purchase on our website, Shopify also collects your name, email address, shipping and billing addresses, payment data, and other data related to the purchase (e.g., phone number, amount of purchases made, etc.). For the analyses, Shopify stores cookies in your browser.
For details, please refer to Shopify's privacy policy: https://www.shopify.de/legal/datenschutz.
The use of Shopify is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the most reliable presentation of our website possible. If a corresponding consent has been obtained, processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
3. General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations as well as this privacy policy.
When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. This privacy policy explains which data we collect and how we use it. It also explains how and for what purpose this happens.
Please note that data transmission over the Internet (e.g., when communicating via email) can have security vulnerabilities. Complete protection of data from access by third parties is not possible.
Notice regarding the responsible entity
The entity responsible for data processing on this website is:
ACTIVLINE Autozubehör GmbH & Co. KG
represented by Titian Freiherr von Wendt
Johann-Philipp-Reis-Straße 4
55469 Simmern
Phone: Tel. 06761/90940
Email: info@activline.de
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, or similar).
Storage Duration
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will occur after these reasons no longer apply.
General Information on the Legal Bases for Data Processing on this Website
If you have consented to data processing, we process your personal data based on Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, if special categories of data according to Art. 9 para. 1 GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing also takes place on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or to access information on your device (e.g., via device fingerprinting), data processing also takes place on the basis of § 25 para. 1 TTDSG. Consent can be revoked at any time. If your data is necessary for contract fulfillment or to carry out pre-contractual measures, we process your data based on Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if it is necessary to fulfill a legal obligation based on Art. 6 para. 1 lit. c GDPR. Data processing can also be based on our legitimate interest according to Art. 6 para. 1 lit. f GDPR. The relevant legal bases in each individual case are explained in the following paragraphs of this privacy policy.
Recipients of Personal Data
As part of our business activities, we cooperate with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only transfer personal data to external parties if this is necessary for the fulfillment of a contract, if we are legally obliged to do so (e.g., transfer of data to tax authorities), if we have a legitimate interest in the transfer according to Art. 6 Para. 1 lit. f GDPR, or if another legal basis permits the data transfer. When using processors, we only transfer personal data of our customers based on a valid contract for order processing. In the case of joint processing, a contract on joint processing is concluded.
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke consent already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases as well as to direct marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. YOU CAN FIND THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR THE PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION ACCORDING TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION ACCORDING TO ART. 21 PARA. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In case of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, especially in the member state of their habitual residence, workplace, or the location of the alleged violation. This right to complain exists without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract, either to yourself or to a third party, in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
Information, correction, and deletion
Within the framework of applicable legal provisions, you have the right at any time to free information about your stored personal data, their origin and recipients, and the purpose of data processing, and, if applicable, a right to correction or deletion of this data. You can contact us at any time for this purpose and for further questions regarding personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. During the verification period, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you require it for the exercise, defense, or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection under Art. 21 para. 1 GDPR, a balance must be struck between your interests and ours. As long as it is not yet clear whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data – apart from its storage – may only be processed with your consent or for the assertion, exercise, or defense of legal claims or to protect the rights of another natural or legal person or for reasons of an important public interest of the European Union or a member state.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator, this page uses SSL or TLS encryption. You can recognize an encrypted connection by the browser's address line changing from "http://" to "https://" and by the lock symbol in your browser bar.
When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If there is an obligation to provide us with your payment data (e.g., account number for direct debit authorization) after concluding a paid contract, this data is required for payment processing.
Payment transactions using common payment methods (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the browser's address line changing from "http://" to "https://" and by the lock symbol in your browser bar.
With encrypted communication, your payment data that you transmit to us cannot be read by third parties.
Objection to advertising emails
The use of contact details published as part of the imprint obligation for sending unsolicited advertising and informational materials is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
4. Data collection on this website
Cookies
Our websites use so-called "cookies." Cookies are small data packages and do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted after your visit ends. Persistent cookies remain stored on your device until you delete them yourself or an automatic deletion occurs through your web browser.
Cookies can come from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g., the shopping cart function or video display). Other cookies can be used to analyze user behavior or for advertising purposes.
Cookies that are necessary for carrying out the electronic communication process, providing certain functions you desire (e.g., for the shopping cart function), or optimizing the website (e.g., cookies for measuring web traffic) (necessary cookies) are stored based on Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent for storing cookies and comparable recognition technologies has been requested, processing takes place exclusively based on this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); consent can be revoked at any time.
You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
Which cookies and services are used on this website can be found in this privacy policy.
GDPR Legal Cookie by Shopify
Our website uses GDPR Legal Cookie by Shopify to obtain your consent for storing certain cookies on your device or for using certain technologies and to document this in compliance with data protection regulations. The provider of this technology is beeclever GmbH, Friedrich-Mohr-Straße 1, 56070 Koblenz (hereinafter "beeclever").
When you enter our website, a connection is established to the servers of the provider beeclever. The provider beeclever thus receives personal data, such as the browser used, the IP address, and a timestamp. A cookie is then stored in your browser to assign the consents given or their withdrawal. The data collected in this way is stored until you request deletion from us, delete the cookie yourself, or the purpose for data storage no longer applies. Mandatory legal retention obligations remain unaffected. Details can be found at: https://apps.shopify.com/gdpr-legal-cookie.
The use of GDPR Legal Cookie by Shopify is to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a legally required contract under data protection law that ensures the service processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
Contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is necessary for pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this was requested; consent can be revoked at any time.
The data you enter in the contact form remains with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been fully processed). Mandatory legal provisions – especially retention periods – remain unaffected.
Inquiry by email, phone, or fax
If you contact us by email, phone, or fax, your inquiry including all personal data arising from it (name, inquiry) will be stored and processed by us for the purpose of handling your request. We do not share this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is necessary for pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this was requested; consent can be revoked at any time.
The data you send to us via contact inquiries remains with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been fully processed). Mandatory legal provisions – especially statutory retention periods – remain unaffected.
Registration on this website
You can register on this website to use additional features on the site. The data entered for this purpose is used only to enable the use of the respective offer or service for which you have registered. The mandatory information requested during registration must be provided completely. Otherwise, we will reject the registration.
For important changes, such as changes in the scope of the offer or technically necessary changes, we use the email address provided during registration to inform you in this way.
The processing of the data entered during registration is carried out for the purpose of executing the user relationship established by the registration and, if applicable, to initiate further contracts (Art. 6 para. 1 lit. b GDPR).
The data collected during registration is stored by us as long as you are registered on this website and is then deleted. Legal retention periods remain unaffected.
5. Analysis Tools and Advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that helps us integrate tracking or statistics tools and other technologies on our website. Google Tag Manager itself does not create user profiles, does not store cookies, and does not perform independent analyses. It only serves to manage and deliver the tools integrated through it. However, Google Tag Manager does collect your IP address, which may also be transferred to Google's parent company in the United States.
The use of Google Tag Manager is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the quick and uncomplicated integration and management of various tools on their website. If the corresponding consent has been obtained, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, as far as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics allows the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, duration of stay, operating systems used, and the user's origin. This data is combined into a user ID and assigned to the respective end device of the website visitor.
Furthermore, with Google Analytics, we can record your mouse and scroll movements and clicks. Additionally, Google Analytics uses various modeling approaches to supplement the collected data sets and employs machine learning technologies in data analysis.
Google Analytics uses technologies that enable the user to be re-identified for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.
The data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
More information about how user data is handled in Google Analytics can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Data Processing Agreement
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Google Analytics E-commerce Measurement
This website uses the "E-commerce Measurement" feature of Google Analytics. With the help of e-commerce measurement, the website operator can analyze the purchasing behavior of website visitors to improve their online marketing campaigns. Information such as orders placed, average order values, shipping costs, and the time from viewing to purchasing a product is recorded. This data can be aggregated by Google under a transaction ID assigned to the respective user or their device.
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads allows us to display advertisements in the Google search engine or on third-party websites when the user enters certain search terms on Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available to Google (e.g., location data and interests) (audience targeting). As the website operator, we can quantitatively evaluate this data by analyzing, for example, which search terms led to the display of our advertisements and how many ads resulted in corresponding clicks.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.
The data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Google Ads Remarketing
This website uses the features of Google Ads Remarketing. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With Google Ads Remarketing, we can assign people who interact with our online offer to specific target groups in order to then show them interest-based advertising in the Google advertising network (remarketing or retargeting).
Furthermore, the advertising audiences created with Google Ads Remarketing can be linked with Google's cross-device features. This way, interest-based, personalized advertising messages tailored to you based on your previous usage and browsing behavior on one device (e.g., mobile phone) can also be displayed on another of your devices (e.g., tablet or PC).
If you have a Google account, you can object to personalized advertising at the following link: https://www.google.com/settings/ads/onweb/.
The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.
Further information and the privacy policy can be found in Google's privacy statement at: https://policies.google.com/technologies/ads?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
6. Plugins and Tools
YouTube with extended privacy
This website embeds videos from the YouTube website. The operator of the pages is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in extended privacy mode. According to YouTube, this mode ensures that YouTube does not store any information about visitors to this website before they watch the video. However, the transfer of data to YouTube partners is not necessarily excluded by the extended privacy mode. For example, YouTube establishes a connection to the Google DoubleClick network regardless of whether you watch a video or not.
As soon as you start a YouTube video on this website, a connection to the YouTube servers is established. The YouTube server is informed about which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to directly assign your browsing behavior to your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, YouTube may store various cookies on your device or use comparable recognition technologies (e.g., device fingerprinting) after starting a video. In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to collect video statistics, improve user-friendliness, and prevent fraud attempts.
If applicable, further data processing operations may be triggered after starting a YouTube video, over which we have no control.
The use of YouTube is in the interest of an appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If a corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
For more information about privacy on YouTube, please see their privacy policy at: https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Google Fonts (local hosting)
This site uses so-called Google Fonts for the uniform display of fonts, which are provided by Google. The Google Fonts are installed locally. No connection to Google servers takes place.
For more information about Google Fonts, please visit https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=de.
Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to verify whether data entry on this website (e.g., in a contact form) is made by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, duration of the website visitor's stay on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated scanning and SPAM. If consent has been obtained, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
For more information about Google reCAPTCHA, please refer to the Google Privacy Policy and the Google Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
7. eCommerce and payment providers
Processing of customer and contract data
We collect, process, and use personal customer and contract data to establish, design, and modify our contractual relationships. Personal data about the use of this website (usage data) is collected, processed, and used only to the extent necessary to enable or bill the user for the use of the service. The legal basis for this is Art. 6 para. 1 lit. b GDPR.
The collected customer data will be deleted after the order is completed or the business relationship ends and any applicable statutory retention periods have expired. Statutory retention periods remain unaffected.
Data transfer upon contract conclusion for online shops, merchants, and goods shipping
When you order goods from us, we pass your personal data to the transport company responsible for delivery as well as to the payment service provider responsible for payment processing. Only such data is disclosed as the respective service provider needs to fulfill its task. The legal basis for this is Art. 6 para. 1 lit. b GDPR, which permits the processing of data to fulfill a contract or pre-contractual measures. If you have given corresponding consent according to Art. 6 para. 1 lit. a GDPR, we will pass your email address to the transport company responsible for delivery so that they can inform you by email about the shipping status of your order; you can revoke the consent at any time.
Payment services
We integrate third-party payment services on our website. When you make a purchase with us, your payment data (e.g., name, payment amount, account details, credit card number) is processed by the payment service provider for the purpose of payment processing. The respective contractual and data protection terms of the respective providers apply to these transactions. The use of payment service providers is based on Art. 6 para. 1 lit. b GDPR (contract execution) as well as in the interest of a smooth, comfortable, and secure payment process (Art. 6 para. 1 lit. f GDPR). To the extent that your consent is requested for certain actions, Art. 6 para. 1 lit. a GDPR is the legal basis for data processing; consents can be revoked at any time for the future.
The following payment services / payment service providers are used on this website:
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal").
The data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
Details can be found in the PayPal privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Stripe
The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter "Stripe").
The data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://stripe.com/de/privacy and https://stripe.com/de/guides/general-data-protection-regulation.
Details can be found in the Stripe privacy policy at the following link: https://stripe.com/de/privacy.
Amazon Pay
The provider of this payment service is Amazon Payments Europe S.C.A., 38 avenue J.F. Kennedy, L-1855 Luxembourg.
Details on how your data is handled can be found in the Amazon Pay privacy policy at the following link: https://pay.amazon.de/help/201212490?ld=APDELPADirect.
Shopify Payment
The provider of this payment service in the EU is Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter "Shopify Payment").
Details can be found in the Shopify Payment privacy policy: https://www.shopify.de/legal/datenschutz.
American Express
The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter "American Express").
American Express may transfer data to its parent company in the USA. The data transfer to the USA is based on the Binding Corporate Rules. Details can be found here: https://www.americanexpress.com/en-pl/company/legal/privacy-centre/european-implementing-principles/.
For more information, please refer to the American Express privacy policy: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter "Mastercard").
Mastercard may transfer data to its parent company in the USA. The data transfer to the USA is based on Mastercard's Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
VISA
The provider of this payment service is Visa Europe Services Inc., London branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter "VISA").
The United Kingdom is considered a data protection safe third country. This means that the UK has a level of data protection equivalent to that of the European Union.
VISA may transfer data to its parent company in the USA. The data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.
For more information, please refer to the VISA privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
