Privacy Policy

The data controller is:
travelite GmbH + Co. KG
Merkurring 70-72
22143 Hamburg

Email: info@travelite.de

We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below, we provide you with detailed information on how we handle your data.

1. Access data and hosting

You can visit our websites without providing any personal details. Each time a webpage is accessed, the web server merely automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, date and time of access, transmitted data volume and the requesting provider (access data), and documents the access. This access data is analysed solely for the purpose of ensuring the website operates without disruption and for improving our service. This serves to safeguard our overriding legitimate interests, which prevail within the framework of a balancing of interests, in the correct presentation of our services in accordance with Article 6(1) sentence 1 point (f) GDPR. All access data will be deleted no later than seven days after the end of your visit to the site .

Hosting

The services for hosting and displaying the website are partly provided by our service providers as part of processing on our behalf. Unless otherwise stated in this Privacy Policy, all access data and all data collected in the designated forms on this website are processed on their servers. If you have questions about our service providers and the basis of our cooperation with them, please use the contact option described in this Privacy Policy.
Our service providers are based and/or use servers in the following countries, for which the European Commission has determined by decision an adequate level of data protection : the United Kingdom, Canada, USA. 
There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the respective service provider is certified. Until certification by our service providers, data transfer continues to be based on this basis: European Commission Standard Data Protection Clauses Our service providers are based and/or use servers in these countries: Australia. For these countries, there is no adequacy decision by the European Commission . Our cooperation with them is based on these safeguards: European Commission Standard Data Protection Clauses.

2. Data processing for contract handling and for contacting us

2.1 Data processing for contract handling

For the purpose of contract handling (including enquiries about and handling of any existing warranty and service disruption claims, as well as any statutory updating obligations) in accordance with Article 6(1) sentence 1 point (b) GDPR, we collect personal data if you provide it to us voluntarily as part of your order. Mandatory fields are marked as such, as in these cases we require the data compulsorily for contract handling and without this information we cannot send the order. Which data is collected can be seen from the respective input forms.

Further information on the processing of your data, in particular on disclosure to our service providers for the purpose of order, payment and shipping handling, can be found in the following sections of this Privacy Policy. After complete handling of the contract, your data will be restricted for further processing and deleted after expiry of the tax and commercial retention periods in accordance with Article 6(1) sentence 1 point (c) GDPR, unless you have expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point (a) GDPR or we reserve the right to any further use of data permitted by law and about which we inform you in this policy.

Merchandise management system

For order and contract handling, we use merchandise management systems of external service providers. Our service providers act for us within the framework of processing on our behalf. If you have questions about our service providers and the basis of our cooperation with them, please use the contact option described in this Privacy Policy.

2.2 Customer account

Insofar as you have given your consent pursuant to Article 6(1) sentence 1 point (a) GDPR by deciding to open a customer account, we use your data for the purpose of opening the customer account and for storing your data for further future orders on our website. Deletion of your customer account is possible at any time and can either be done by sending a message to the contact option described in this Privacy Policy or via a function provided for this purpose in the customer account. After deletion of your customer account, your data will be deleted, unless you have expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point (a) GDPR or we reserve the right to any further use of data permitted by law and about which we inform you in this policy.

2.3 Microsoft 365 including Outlook and Microsoft 365 Copilot

We use “Microsoft 365” including Outlook and Microsoft 365 Copilot. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as “Microsoft”).

Microsoft 365 is a platform for communication, collaboration, appointment management, file storage, document editing and organisation of business processes. As part of the use of Microsoft 365, in particular master data, contact data, communication data, content data, email data, file and document contents, appointment and calendar data, contract data, usage data, technical data and metadata may be processed. When using Outlook, in particular names, email addresses, contents of emails, email attachments, subject lines, sending and receiving times as well as further communication metadata may be processed.

We also use Microsoft 365 Copilot to support our work with Microsoft 365. Depending on use, configuration and authorisation concept, Microsoft 365 Copilot may process content from Microsoft 365. This may include in particular emails, calendar information, contacts, files, document contents, meeting contents, chat and communication data as well as further information from Microsoft 365. Processing takes place in particular for searching for information, summarising content, creating and revising texts, preparing work processes and supporting internal organisation. Microsoft 365 Copilot processes content within the framework of the configured authorisation concept and in principle can only take into account content to which the respective user may have access.

The processing of personal data may also take place in third countries, in particular in the USA. This may be the case in particular for support services, security and error analyses, telemetry, the use of subprocessors or depending on the configuration of individual Microsoft services. With Microsoft 365 Copilot, depending on settings and availability of functions, individual processing operations, in particular processing by large language models, may also take place outside the EU Data Boundary. In this respect, Microsoft describes for EU and EFTA customers the possibility of so-called Flex Routing, in which LLM inferencing may take place outside the EU Data Boundary under certain conditions.

Insofar as personal data is transferred to Microsoft in the USA or processed there, Microsoft bases the data transfer to the USA on the European Commission’s EU-U.S. Data Privacy Framework. Insofar as Microsoft transfers personal data to further third countries or has it processed by subprocessors in further third countries, Microsoft states that it additionally bases these transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Article 46 GDPR.

Processing takes place, insofar as it is necessary for carrying out pre-contractual measures or a contract with you, on the basis of Article 6(1) point (b) GDPR. Insofar as processing takes place for safeguarding our legitimate interests, it takes place on the basis of Article 6(1) point (f) GDPR. Our legitimate interests lie in efficient communication, secure organisation of our business processes, structured collaboration, documentation of business transactions, handling of enquiries as well as supporting our employees in handling business tasks. Insofar as we are legally obliged to retain certain communication, documents or business transactions, processing takes place on the basis of Article 6(1) point (c) GDPR. Insofar as special categories of personal data are processed in individual cases, this only takes place if there is a legal basis for this under Article 9 GDPR.

Microsoft processes personal data, insofar as this processing takes place on our behalf for the provision and operation of Microsoft 365 including Outlook and Microsoft 365 Copilot, as a processor within the meaning of Article 4 no. 8 GDPR. We have concluded a data processing agreement with Microsoft within the meaning of Article 28(3) GDPR. In this, Microsoft undertakes in particular to process personal data only in accordance with our instructions and for providing the agreed services, to implement suitable technical and organisational protective measures and to use subprocessors only in accordance with the contractual provisions.

Further information on data processing by Microsoft can be found at https://www.microsoft.com/de-de/privacy/privacystatement . Further information on the Microsoft Products and Services Data Protection Addendum can be found at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA

2.4 Contacting us

As part of customer communication, we collect personal data for processing your enquiries in accordance with Article 6(1) sentence 1 point (b) GDPR if you voluntarily provide this to us when contacting us (e.g. via contact form or email). Mandatory fields are marked as such, as in these cases we compulsorily require the data for processing your contact request. Which data is collected can be seen from the respective input forms. After your enquiry has been fully processed, your data will be deleted, unless you have expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point (a) GDPR or we reserve the right to any further use of data permitted by law and about which we inform you in this policy.

3. Data processing for the purpose of shipping handling

For contract fulfilment in accordance with Article 6(1) sentence 1 point (b) GDPR, we pass on your data to the shipping service provider commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods.

Transfer of data to shipping service providers for the purpose of shipping notification

If you have given us your express consent for this during or after your order, we will, on this basis and in accordance with Article 6(1) sentence 1 point (a) GDPR, pass on your email address to the selected shipping service provider so that they can contact you before delivery for the purpose of delivery notification or coordination.
Consent can be revoked at any time by sending a message to the contact option described in this Privacy Policy or directly to the shipping service provider at the contact address listed below. After revocation we will delete your data provided for this purpose, unless you have expressly consented to further use of your data or we reserve the right to any further use of data permitted by law and about which we inform you in this policy.

DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany

DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany

4. Data processing for payment handling

When processing payments in our online shop, we work with these partners: technical service providers, credit institutions, payment service providers.

4.1 Data processing for transaction handling

Depending on the selected payment method, we pass on the data necessary for handling the payment transaction to our technical service providers, who act for us within the framework of processing on our behalf, or to the commissioned credit institutions or to the selected payment service provider, insofar as this is necessary for handling the payment. This serves the fulfilment of the contract in accordance with Article 6(1) sentence 1 point (b) GDPR. In some cases, the payment service providers themselves collect the data required for handling the payment , e.g. on their own website or via technical integration in the order process. In this respect, the Privacy Policy of the respective payment service provider applies.
If you have questions about our partners for payment handling and the basis of our cooperation with them, please use the contact option described in this Privacy Policy.

4.2 Data processing for the purpose of fraud prevention and optimisation of our payment processes

If necessary, we provide our service providers with further data, which they use together with the data required for handling the payment as our processors for the purpose of fraud prevention and optimisation of our payment processes (e.g. invoicing, handling of disputed payments, support for accounting). This serves, in accordance with Article 6 (1) sentence 1 point (f) GDPR, to safeguard our overriding legitimate interests within the framework of a balancing of interests in protecting ourselves against fraud or in efficient payment management.

4.3 Identity and credit check when selecting purchase on account via PayOne

If you choose the payment method purchase on account (offered via PayOne GmbH, Lyoner Str. 9, 60528 Frankfurt a. M., Germany (hereinafter PayOne)), we ask for your consent in accordance with Article 6(1) sentence 1 point (a) GDPR that we may transfer the data necessary for handling the payment and an identity and credit check to PayOne. In Germany, for the identity and credit check, the credit agencies named in the Privacy Policy of PayOne may be used. PayOne uses the information received about the statistical probability of payment default for a balanced decision on the establishment, implementation or termination of the contractual relationship. You can revoke your consent at any time by sending a message to the contact option named in this Privacy Policy . This may result in us no longer being able to offer you certain payment options.

5. Advertising by email

5.1 Email newsletter with registration, newsletter tracking with separate consent

If you subscribe to our newsletter, we use the data required for this or separately provided by you in order to send you our regular email newsletter on the basis of your consent in accordance with Article 6(1) sentence 1 point (a) GDPR. Unsubscribing from the newsletter is possible at any time and can either be done by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After unsubscribing, we will delete your email address from the recipient list, unless you have not expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point (a) GDPR or we reserve the right to any further use of data permitted by law and about which we inform you in this policy.

If you have additionally given us your consent in accordance with Article 6(1) sentence 1 point (a) GDPR to analyse our newsletter, we also analyse your handling of our newsletter by measuring, storing and evaluating opening rates and click rates for the purpose of designing future newsletter campaigns (“newsletter tracking”).

For this evaluation, the emails sent contain single-pixel technologies (e.g. so-called web beacons, tracking pixels), which are stored on our website. For the evaluations, we link in particular the following “newsletter data”

  • the page from which the page was requested (so-called referrer URL),
  • the date and time of the access,
  • the description of the type of web browser used,
  • the IP address of the requesting computer,
  • the email address,
  • the date and time of registration and confirmation

and the single-pixel technologies with your email address or your IP address and, if applicable, an individual ID. Links contained in the newsletter may also contain this ID.

Unsubscribing from newsletter tracking is possible at any time and can either be done by sending a message to the described contact option or via a link provided for this purpose in the newsletter.

The information is stored as long as you have subscribed to the newsletter.

5.2 Email advertising without newsletter registration and your right to object

If we receive your email address in connection with the sale of a good or service and you have not objected to this, we reserve the right to send you regular vouchers or offers from our range. You can object to this use of your email address at any time by sending a message to the contact option described below or via a link provided for this purpose in the advertising email, without incurring any costs other than the transmission costs according to the basic rates.

5.3 Newsletter dispatch

The newsletter and the newsletter tracking presented above are possibly also sent by our service providers as part of processing on our behalf. If you have questions about our service providers and the basis of our cooperation with them, please use the contact option described in this Privacy Policy.

5.4 Sending review requests by email

If you have given us your express consent for this during or after your order in accordance with Article 6(1) sentence 1 point (a) GDPR, we use your email address for the request to submit a review of your order via the review system used by us. This consent can be revoked at any time by sending a message to the contact option described in this Privacy Policy or via a link provided for this purpose in the review request.

The review requests may also be sent by our service provider Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne (Trusted Shops) .

In the process, as part of sending review requests, we receive information on the respective status from Trusted Shops (e.g. whether the review request was sent and whether it was received). This takes place in accordance with Article 6(1) sentence 1 point (f) GDPR for fulfilment of our legitimate interest in receiving information about the review invitations so that optimisations can be made on this basis if necessary, as well as for fulfilment of the legitimate interest of Trusted Shops in being able to offer this service.

For the sending of review requests and for the collection and display of review and status information, we are jointly responsible with Trusted Shops .

Within the framework of the joint responsibility existing between us and Trusted Shops GmbH, please contact Trusted Shops GmbH first if you have data protection questions and for asserting your rights; their contact options can be found here . Further information on data protection can be found at the following link here . Regardless of this, you can also always contact us using the contact option described in this Privacy Policy. Your enquiry will then , if necessary, be forwarded to the other controller for response.

6. Cookies and other technologies

6.1 General information

To make visiting our website attractive and to enable the use of certain functions, we use on various pages technologies including so-called cookies. Cookies are small text files that are automatically stored on your end device. Some of the cookies we use are deleted again after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognise your browser on the next visit (persistent cookies).

Privacy protection for end devices
When using our online offer, we use technologies that are absolutely necessary in order to provide the telemedia service expressly requested . The storage of information on your end device or access to information already stored on your end device does not require consent in this respect.

For functions that are not absolutely necessary, the storage of information on your end device or access to information already stored on your end device requires your consent. We would like to point out to you that if consent is not given, parts of the website may not be fully usable. Any consent you may have given remains in place until you adjust or reset the respective settings in your end device.

Any downstream data processing by cookies and other technologies
We use such technologies that are absolutely necessary for the use of certain functions of our website (e.g. shopping basket function). Through these technologies, IP address, time of the visit, device and browser information as well as information about your use of our website (e. g. information on the contents of the shopping basket) are collected and processed. This serves overriding legitimate interests within the framework of a balancing of interests in an optimised presentation of our offer in accordance with Article 6(1) sentence 1 point (f) GDPR.

In addition, we use technologies to fulfil the legal obligations to which we are subject (e.g. to be able to prove consents to the processing of your personal data) as well as for web analysis and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this Privacy Policy. Where applicable, we also use technologies that are not individually listed in this Privacy Policy . More detailed information on these technologies including the respective legal basis for data processing can be found on the Usercentrics platform. You can reach this by clicking the fingerprint button in the lower right or left corner of the page.

You can find the cookie settings for your browser at the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™

If you have consented to the use of the technologies in accordance with Article 6(1) sentence 1 point (a) GDPR, you can revoke your consent at any time by sending a message to the contact option described in the Privacy Policy . Alternatively, you can click the fingerprint button in the lower right or left corner of the page. If cookies are not accepted, the functionality of our website may be limited.

6.2 Consent Manager Platform (CMP)

On our website, we use a consent management service (“Consent Manager Platform (CMP)”) in order to inform you about the cookies and the other technologies that we use on our website, as well as to obtain, manage and document your consent to the processing of your personal data by these technologies where necessary. This is necessary in accordance with Article 6(1) sentence 1 point (c) GDPR to fulfil our legal obligation pursuant to Article 7(1) GDPR to be able to prove your consent to the processing of your personal data, to which we are subject. 

The Consent Manager Platform (CMP) used is a service of ACRIS E-Commerce GmbH, Am Pfenningberg 60, 4040 Linz, Austria, which processes your data on our behalf. After submitting your cookie declaration on our website, the web server stores the following data: IP address, device information, browser information, set language, website accessed or its URL, date and time of your declaration of consent as well as information on your consent behaviour. In addition, the following technologies are used, which contains / contain information on your consent behaviour: cookies The data is stored exclusively on the end device; no transfer of personal data to the provider of the Consent Manager Platform (CMP) takes place. 

Your data will be deleted after 30 days, unless you have not expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point (a) GDPR or we reserve the right to any further use of data permitted by law and about which we inform you in this policy .

6.3  Information on third-country transfer (data transfer to third countries)
We use technologies from service providers on our website whose registered office and/or server locations may be in third countries outside the EU or the EEA, . If there is no adequacy decision of the EU Commission for this country, an adequate level of data protection must be ensured by means of other suitable safeguards. 
Suitable safeguards in the form of contractually agreed standard contractual clauses of the EU Commission or binding internal data protection rules (Binding Corporate Rules) are generally possible, but require prior review by the contracting parties as to whether an adequate level of protection can be ensured. According to the case law of the ECJ, this may require taking additional protective measures.
As a matter of principle, we have agreed the standard data protection clauses issued by the EU Commission with the technology providers used by us that process personal data in a third country. Where possible, we also agree additional safeguards intended to ensure that sufficient data protection is guaranteed in third countries without an adequacy decision.  
Regardless of this, it may happen that despite all contractual and technical measures, the level of data protection in the third country does not correspond to that of the EU. For these cases, if necessary, as part of the cookie consent, we ask for your consent pursuant to Article 49(1) point (a) GDPR to the transfer of your personal data to a third country. In particular, there is the risk that local authorities of the third country may, from a European data protection perspective, possibly obtain insufficiently restricted access rights to your personal data, without us as data exporter or you as the data subject noticing this and/or you possibly also not having sufficient legal remedies available to prevent this and/or take action against such access.  
In particular, the following countries currently count among the third countries without an adequacy decision of the EU Commission (example list):  China,  Russia,  Taiwan 
 You can find out to which third countries data is transferred by us in the data protection notices for the respective tool used and/or the consent management service / Consent Manager Platform (CMP) used by us. 

7. Use of cookies and other technologies

If you have given your consent for this in accordance with Article 6(1) sentence 1 point (a) GDPR , we use the following cookies and other technologies from third-party providers on our website. Once the purpose no longer applies and the use of the respective technology by us has ended, the data collected in this context will be deleted. You can revoke your consent at any time with effect for the future. Further information on your revocation options can be found in the section "Cookies and other technologies". Further information including the basis of our cooperation with the individual providers can be found with the individual technologies. If you have questions about the providers and the basis of our cooperation with them, please use the contact option described in this Privacy Policy.

Adcell Retargeting
Through the advertising partner Firstlead GmbH, Rosenfelder Str. 15-16, 10315 Berlin (“adcell”), we advertise this website in search results as well as on third-party websites. When visiting our website, a retargeting cookie is automatically set by adcell or its partners, which by means of a pseudonymous cookie ID and based on the pages visited by you enables interest-based advertising. Data processing takes place on the basis of an agreement between joint controllers pursuant to Article 26 GDPR. We determine the parameters of the respective advertising campaign. adcell is responsible for the precise implementation (e.g. the decision on the placement of the individual advertisements). The data automatically collected by adcell (IP address, time of the visit, device and browser information as well as information on your use of our website) may possibly be combined by adcell with information from other sources and transmitted to adcell advertising partners.

advanced store Retargeting
Through the advertising partner advanced store GmbH, Alte Jakobstr. 79/80, 10179 Berlin (“advanced store”), we advertise this website in search results as well as on third-party websites. When visiting our website, a retargeting cookie is automatically set by advanced store or its partners, which by means of a pseudonymous cookie ID and based on the pages visited by you enables interest-based advertising. Data processing takes place on the basis of an agreement between joint controllers pursuant to Article 26 GDPR. We determine the parameters of the respective advertising campaign. advanced store is responsible for the precise implementation (e.g. the decision on the placement of the individual advertisements). The data automatically collected by advanced store (IP address, time of the visit, device and browser information as well as information on your use of our website) may possibly be combined by advanced store with information from other sources and transmitted to advanced store advertising partners.

Customa
On this website, technologies from customa are used to collect and store data for marketing and optimisation purposes. The provider of this technology is trust in dialog Services GmbH, Merkurring 33-35, 22143 Hamburg, https://www.customa.de. Cookies may be used for this purpose. Cookies are text files that are stored locally in the cache of the internet browser of the site visitor. The cookies enable the internet browser to be recognised.

7.1 Use of Google services

We use the technologies presented below of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by the Google technologies about your use of our website is generally transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there . For the USA, there is no adequacy decision of the European Commission. Our cooperation with them is based on European Commission Standard Data Protection Clauses.  If your IP address is collected via the Google technologies, it will be shortened before storage on Google's servers by activating IP anonymisation . Only in exceptional cases will the full IP address be transmitted to a server of Google and shortened there. Unless otherwise stated for the individual technologies , data processing takes place on the basis of an agreement concluded for the respective technology between joint controllers pursuant to Article 26 GDPR. Further information on data processing by Google can be found in the Google Privacy Policy.

Our service providers are based and/or use servers in countries outside the EU and the EEA, for which the European Commission has by decision determined an adequate level of data protection. Our service providers are based and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission. Our cooperation with them is based on European Commission Standard Data Protection Clauses.   

Google Analytics
For the purpose of website analysis, data (IP address, time of the visit, device and browser information as well as information on your use of our website) is automatically collected and stored by Google Analytics, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Your IP address is generally not combined with other Google data. The data processing takes place on the basis of an agreement on processing on behalf by Google.

Google Ads
For advertising purposes in Google search results as well as on third-party websites , when visiting our website the so-called Google Remarketing cookie is set, which automatically through the collection and processing of data (IP address, time of the visit, device and browser information as well as information on your use of our website) and by means of a pseudonymous cookie ID and based on the pages visited by you enables interest-based advertising. Any further data processing only takes place if you have activated the setting “personalised advertising” in your Google account. If you are in this case logged in to Google during your visit to our website, Google uses your data together with Google Analytics data to create and define target group lists for cross-device remarketing.

For website analysis and event tracking, via Google Ads Conversion Tracking we measure your subsequent user behaviour, if you arrived at our website via a Google Ads advertisement. Cookies may be used for this purpose and data (IP address, time of the visit, device and browser information as well as information on your use of our website on the basis of events specified by us such as e.g. visit to a website or newsletter registration) may be collected, from which usage profiles are created using pseudonyms.

Google Maps
For the visual display of geographical information, by Google Maps data about your use of the maps functions, in particular the IP address as well as location data, are collected, transmitted to Google and subsequently processed by Google. We have no influence on this subsequent data processing.

Google Fonts
For uniform presentation of the contents on our website, by the script code “Google Fonts” data (IP address, time of the visit, device and browser information) are collected, transmitted to Google and subsequently processed by Google. We have no influence on this subsequent data processing.

Google Tag Manager
Through Google Tag Manager, we can manage various codes and services on our website. When implementing the individual tags, Google may under certain circumstances also process personal data (e.g. IP address, online identifiers (including cookies)). Data processing takes place on the basis of an agreement on processing on behalf by Google.

By using Google Tag Manager, integration of various services/technologies can be achieved.
If you do not wish to use individual tracking services and have therefore deactivated them, the deactivation remains in place for all affected tracking tags integrated by Google Tag Manager.

YouTube Video Plugin
For integrating third-party content, via the YouTube Video Plugin in the enhanced privacy mode used by us data (IP address, time of the visit, device and browser information) are collected, transmitted to Google and subsequently processed by Google, only if you play a video.

7.2 Use of Facebook services

Use of Facebook Pixel
We use Facebook Pixel as part of the technologies presented below of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Facebook (by Meta)” or “Meta Platforms Ireland”). With Facebook Pixel, data (IP address, time of the visit, device and browser information as well as information on your use of our website based on events specified by us such as e.g. visit to a website or newsletter registration) is automatically collected and stored, from which usage profiles are created using pseudonyms. For this purpose, when visiting our website, a cookie is automatically set by Facebook Pixel, which automatically by means of a pseudonymous cookie ID enables recognition of your browser when visiting other websites . Facebook (by Meta) will combine this information with further data from your Facebook account and use it to compile reports on website activities and to provide further services connected with website use , in particular personalised and group-based advertising .

The information automatically collected by Facebook (by Meta) technologies about your use of our website is generally transferred to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA and stored there. For the USA there is no adequacy decision of the European Commission. Insofar as the data transfer to the USA falls within our responsibility, our cooperation is based on European Commission Standard Data Protection Clauses. Further information on data processing by Facebook can be found in the Privacy Policy of Facebook (by Meta).

Our service providers are based and/or use servers in the following countries, for which the European Commission has determined by decision an adequate level of data protection : USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina. There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the respective service provider is certified.A certification is in place. Our service providers are based and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. For these countries, there is no adequacy decision by the European Commission . Our cooperation with them is based on these safeguards:  European Commission Standard Data Protection Clauses.

Facebook Ads (Ads Manager)
Through Facebook Ads, we advertise this website on Facebook (by Meta) as well as on other platforms. We determine the parameters of the respective advertising campaign. For the precise implementation, in particular the decision on the placement of the advertisements with individual users, Facebook (by Meta) is responsible. Unless otherwise stated for the individual technologies , data processing takes place on the basis of an agreement between joint controllers pursuant to Article 26 GDPR. Joint responsibility is limited to the collection of the data and its transmission to Meta Platforms Ireland. The subsequent data processing by Meta Platforms Ireland is not covered by this.

7.3 Other providers of web analysis and online marketing services

Use of AdCell Retargeting for online marketing
Through the advertising partner Firstlead GmbH, Rosenfelder Str. 15-16, 10315 Berlin (“adcell”), we advertise this website in search results as well as on third-party websites. When visiting our website, a retargeting cookie is automatically set by adcell or its partners, which by means of a pseudonymous cookie ID and based on the pages visited by you enables interest-based advertising. Data processing takes place on the basis of an agreement between joint controllers pursuant to Article 26 GDPR. We determine the parameters of the respective advertising campaign. For the precise implementation (e.g. the decision on the placement of the individual advertisements) adcell is responsible. The data automatically collected by adcell (IP address, time of the visit, device and browser information as well as information on your use of our website) may possibly be combined by adcell with information from other sources and transmitted to adcell advertising partners.

Use of Vimeo Video Plugin for integrating third-party content
For integrating third-party content, via the video plugin of Vimeo LLC, 555 West 18th Street, New York 10011, USA (“Vimeo”) data (IP address, time of the visit, device and browser information) are collected, transmitted to Vimeo and subsequently processed by Vimeo. Data processing takes place on the basis of an agreement between joint controllers pursuant to Article 26 GDPR. Google Analytics is automatically integrated in the Vimeo Video Plugin. For the purpose of website analysis, with Google Analytics data (IP address, time of the visit, device and browser information as well as information on your use of our website) is automatically collected and stored, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Google Analytics is a service of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google about your use of our website is generally transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there . Your IP address will be shortened before storage on the servers of Google by activating IP anonymisation. Only in exceptional cases will the full IP address be transferred to a server of Google in the USA and shortened there. We have no influence and access to the data processing by Vimeo including the settings and the results of Google Analytics. For the USA there is no adequacy decision of the European Commission. Our cooperation with them is based on European Commission Standard Data Protection Clauses. 

8. Integration of the Trusted Shops Trustbadge/ other widgets

If you have given your consent for this pursuant to Article 6(1) sentence 1 point (a) GDPR, Trusted Shops widgets are integrated on this website to display the Trusted Shops services (e.g. trustmark, collected reviews) as well as to offer the Trusted Shops products for buyers after an order. The Trustbadge and the services advertised with it are a service of Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are jointly responsible under data protection law pursuant to Article 26 GDPR. We inform you below as part of this Privacy Policy about the essential contractual contents pursuant to Article 26(2) GDPR. Within the framework of the joint responsibility existing between us and Trusted Shops AG, please preferably contact Trusted Shops using the contact options stated in the data protection information if you have data protection questions and for asserting your rights. Regardless of this , however, you can always contact the controller of your choice. Your enquiry will then, if necessary, be forwarded to the other controller for response.

8.1 Data processing when integrating the Trustbadge/ other widgets

The Trustbadge is provided by a US CDN provider (Content-DeliveryNetwork). An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which for the USA can be accessed here. Service providers used from the USA are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information is available here. If service providers used are not certified under the DPF, standard contractual clauses have been concluded as an appropriate safeguard. When the Trustbadge is called up, the web server automatically stores a so-called server log file, which also contains your IP address, date and time of access, transmitted data volume and the requesting provider (access data) and documents the access . The IP address is anonymised immediately after collection, so that the stored data cannot be assigned to your person. The anonymised data is used in particular for statistical purposes and for error analysis.

8.2 Data processing after completion of the order

If you have given your consent, after completion of the order the Trustbadge accesses order information stored on your end device (order total, order number, if applicable purchased product) as well as email address and your email address is hashed by means of a cryptological one-way function. The hash value is then transmitted to Trusted Shops together with the order information pursuant to Article 6(1) sentence 1 point (a) GDPR. This serves to check whether you are already registered for Trusted Shops services . If this is the case, further processing takes place in accordance with the contractual agreement made between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will then have the opportunity to manually register for use of the services or conclude the protection within the framework of your existing user contract, if applicable.
For this purpose, after completion of your order the Trustbadge accesses the following information stored on the end device used by you: order total, order number and email address. This is necessary so that we can offer you buyer protection. Transmission of the data to Trusted Shops only takes place once you actively choose to conclude buyer protection by clicking the correspondingly designated button in the so-called Trustcard . If you decide to use the services, the further processing is governed by the contractual agreement with Trusted Shops pursuant to Article 6(1) point (b) GDPR, in order to complete your registration for buyer protection and secure the order and, if applicable, to be able subsequently to send you review invitations by email. 
Trusted Shops uses service providers in the areas of hosting, monitoring and logging . The legal basis is Article 6(1) point (f) GDPR for the purpose of ensuring trouble-free operation. Processing in third countries (USA and Israel) may take place in this context. An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which for the USA here and for Israel here can be accessed. Service providers used from the USA are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information is available here. If service providers used are not certified under the DPF, standard contractual clauses have been concluded as an appropriate safeguard.

9. Social media

9.1 Social plugins from Facebook (by Meta), Instagram (by Meta)

Social buttons from social networks are used on our website. These are merely integrated into the page as HTML links, so that when our website is called up no connection with the servers of the respective provider is yet established. If you click one of the buttons, the website of the respective social network opens in a new window of your browser. There you can e.g. press the Like or Share button .

9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), Youtube, Pinterest, LinkedIn, Xing

If you have given your consent for this in accordance with Article 6(1) sentence 1 point (a) GDPR to the respective social media operator, when visiting our online presences on the above-mentioned social media your data is automatically collected and stored for market research and advertising purposes, from which usage profiles are created using pseudonyms. These can be used to place e.g. advertisements within and outside the platforms that presumably correspond to your interests . Cookies are generally used for this purpose. The detailed information on the processing and use of the data by the respective social media operator as well as a contact option and your related rights and setting options for protecting your privacy can be found in the providers' Privacy Policies linked below. Should you still need help in this regard, you can contact us.

Facebook (by Meta) is a service of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland about your use of our online presence on Facebook (by Meta) is generally transferred to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA and stored there. For the USA there is no adequacy decision of the European Commission . Our cooperation with them is based on European Commission Standard Data Protection Clauses.  Data processing within the framework of visiting a Facebook (by Meta) fan page takes place on the basis of an agreement between joint controllers pursuant to Article 26 GDPR. Further information (information on Insights data) can be found here.

Our service providers are based and/or use servers in the following countries, for which the European Commission has determined by decision an adequate level of data protection : USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina. There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the respective service provider is certified. A certification is in place. Our service providers are based and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. For these countries, there is no adequacy decision by the European Commission . Our cooperation with them is based on these safeguards:  European Commission Standard Data Protection Clauses.


Instagram (by Meta) is a service of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Meta Platforms Ireland”) The information automatically collected by Meta Platforms Ireland about your use of our online presence on Instagram is generally transferred to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA and stored there. For the USA there is no adequacy decision of the European Commission. Our cooperation with them is based on European Commission Standard Data Protection Clauses .  Data processing within the framework of visiting an Instagram (by Meta) fan page takes place on the basis of an agreement between joint controllers pursuant to Article 26 GDPR. Further information (information on Insights data) can be found here.
Our service providers are based and/or use servers in the following countries, for which the European Commission has determined by decision an adequate level of data protection : USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina. There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the respective service provider is certified. A certification is in place. Our service providers are based and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. For these countries, there is no adequacy decision by the European Commission . Our cooperation with them is based on these safeguards: European Commission Standard Data Protection Clauses.

YouTube is a service of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google about your use of our online presence on YouTube is generally transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. 
Our service providers are based and/or use servers in countries outside the EU and the EEA, for which the European Commission has by decision determined an adequate level of data protection. Our service providers are based and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission. Our cooperation with them is based on European Commission Standard Data Protection Clauses. 

Pinterest is a service of Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (“Pinterest”). The information automatically collected by Pinterest about your use of our online presence on Pinterest is generally transferred to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA and stored there. 
Our service providers are based and/or use servers in countries outside the EU and the EEA, for which the European Commission has by decision determined an adequate level of data protection. Our service providers are based and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission. Our cooperation with them is based on European Commission Standard Data Protection Clauses. 

LinkedIn is a service of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information automatically collected by LinkedIn about your use of our online presence on LinkedIn is generally transferred to a server of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA and stored there. 
Our service providers are based and/or use servers in the following countries, for which the European Commission has determined by decision an adequate level of data protection : USA. There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the respective service provider is certified. Until certification by our service providers, data transfer continues to be based on this basis: European Commission Standard Data Protection Clauses.

Xing is a service of New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.

10. Contact options and your rights

10.1 Your rights

As a data subject, you have the following rights:

  • in accordance with Article 15 GDPR, the right to request information about your personal data processed by us within the scope specified there;
  • in accordance with Article 16 GDPR, the right to request without undue delay the correction of inaccurate or completion of your personal data stored by us;
  • in accordance with Article 17 GDPR, the right to request the deletion of your personal data stored by us, insofar as further processing is not
    • for exercising the right to freedom of expression and information;
    • for fulfilment of a legal obligation;
    • for reasons of public interest or
    • for the establishment, exercise or defence of legal claims is necessary;
  • in accordance with Article 18 GDPR, the right to request restriction of the processing of your personal data, insofar as
    • the accuracy of the data is disputed by you;
    • the processing is unlawful but you oppose its deletion;
    • we no longer need the data, but you need it for the establishment, exercise or defence of legal claims or
    • you have objected pursuant to Article 21 GDPR to the processing;
  • in accordance with Article 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller;
  • in accordance with Article 77 GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.

Right to object

Insofar as we process personal data as explained above to safeguard our overriding legitimate interests within the framework of a balancing of interests , you can object to this processing with effect for the future. If processing is carried out for purposes of direct marketing, you can exercise this right at any time as described above . Insofar as processing is carried out for other purposes, you only have a right to object if there are grounds arising from your particular situation.

After exercising your right to object, we will not continue to process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or if the processing serves the establishment, exercise or defence of legal claims.

This does not apply if processing is carried out for purposes of direct marketing . In that case, we will not continue to process your personal data for this purpose.

10.2 Contact options

If you have questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data as well as revocation of granted consents or objection to a specific use of data, please contact us directly via the contact data in our legal notice.

Data Protection Officer:
SHIELD GmbH Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Germany

info@shield-datenschutz.de

Privacy Policy created with the Trusted Shops Legal Text Generator

Privacy Policy

The data controller is:
travelite GmbH + Co. KG
Merkurring 70-72
22143 Hamburg

Email: info@travelite.de

We are delighted that you are interested in our online shop. Protecting your privacy is very important to us. Below, we provide you with detailed information on how we handle your data.

1. Access data and hosting

You can visit our websites without providing any personal details. Each time you access a webpage, the web server merely automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, the date and time of access, the volume of data transmitted and the requesting provider (access data), and documents the access. This access data is analyzed solely for the purpose of ensuring the smooth operation of the site and improving our services. This serves to safeguard our overriding legitimate interests in the correct presentation of our services in accordance with Article 6(1) sentence 1 point f GDPR following a balancing of interests. All access data is deleted no later than seven days after the end of your visit to the site.

Hosting

The services for hosting and displaying the website are partly provided by our service providers as part of processing on our behalf. Unless otherwise stated in this privacy policy, all access data and all data collected in the forms provided for this purpose on this website are processed on their servers. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact details described in this privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has, by decision, determined an adequate level of data protection: the United Kingdom, Canada, the USA.
There is a decision by the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the relevant service provider is certified. Pending certification by our service providers, data transfer will continue to be based on the following: Standard Data Protection Clauses of the European Commission Our service providers are based in and/or use servers in these countries: Australia. For these countries, there is no adequacy decision of the European Commission. Our cooperation with them is based on these safeguards: Standard Data Protection Clauses of the European Commission.

2. Data processing for contract fulfilment and for establishing contact

2.1 Data processing for contract fulfilment

For the purpose of contract fulfilment (including enquiries regarding and fulfilment of any warranty claims and claims due to performance disruptions that may exist, as well as any statutory updating obligations) in accordance with Article 6(1) sentence 1 point b GDPR, we collect personal data if you voluntarily provide it to us in the context of your order. Mandatory fields are marked as such because in these cases we absolutely require the data for contract fulfilment and we cannot dispatch the order without it. The data collected can be seen in the respective input forms.

Further information on the processing of your data, in particular on disclosure to our service providers for the purposes of order, payment and dispatch processing, can be found in the following sections of this privacy policy. After complete fulfilment of the contract, your data will be restricted for further processing and deleted after expiry of the retention periods under tax and commercial law in accordance with Article 6(1) sentence 1 point c GDPR, unless you have expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point a GDPR or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this policy.

Merchandise management system

We use merchandise management systems of external service providers for order and contract processing. Our service providers act for us within the framework of processing on our behalf. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.

2.2 Customer account

Provided that you have given your consent in accordance with Article 6(1) sentence 1 point a GDPR by choosing to open a customer account, we use your data for the purpose of opening the customer account and for storing your data for future orders on our website. Deletion of your customer account is possible at any time and can either be done by sending a message to the contact option described in this privacy policy or via a function provided for this purpose in the customer account. After deletion of your customer account, your data will be deleted unless you have expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point a GDPR or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this policy.

2.3 Microsoft 365 including Outlook and Microsoft 365 Copilot

We use “Microsoft 365” including Outlook and Microsoft 365 Copilot. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (hereinafter referred to as “Microsoft”).

Microsoft 365 is a platform for communication, collaboration, appointment management, file storage, document editing and organisation of business processes. In the context of using Microsoft 365, in particular master data, contact data, communication data, content data, email data, file and document contents, appointment and calendar data, contract data, usage data, technical data and metadata may be processed. When using Outlook, in particular names, email addresses, contents of emails, email attachments, subject lines, sending and receiving times as well as other communication metadata may be processed.

We also use Microsoft 365 Copilot to support our work with Microsoft 365. Depending on use, configuration and authorisation concept, Microsoft 365 Copilot may process content from Microsoft 365. This may include in particular emails, calendar information, contacts, files, document contents, meeting contents, chat and communication data as well as other information from Microsoft 365. Processing is carried out in particular to search for information, to summarise content, to create and revise texts, to prepare work processes and to support internal organisation. Microsoft 365 Copilot processes content within the framework of the configured authorisation concept and can in principle only take into account content to which the respective user may have access.

The processing of personal data may also take place in third countries, in particular in the USA. This may be the case in particular in connection with support services, security and error analyses, telemetry, the use of sub-processors or depending on the configuration of individual Microsoft services. In the case of Microsoft 365 Copilot, depending on settings and availability of functions, it may also occur that individual processing operations, in particular processing by large language models, take place outside the EU Data Boundary. In this respect, Microsoft describes for EU and EFTA customers the possibility of so-called Flex Routing, in which LLM inferencing may take place outside the EU Data Boundary under certain conditions.

Insofar as personal data is transferred to Microsoft in the USA or processed there, Microsoft bases the data transfer to the USA on the EU-U.S. Data Privacy Framework of the European Commission. Insofar as Microsoft transfers personal data to further third countries or has it processed by sub-processors in further third countries, Microsoft states that it additionally bases these transfers on appropriate safeguards, in particular standard contractual clauses within the meaning of Article 46 GDPR.

Processing is carried out, insofar as it is necessary for the implementation of pre-contractual measures or a contract with you, on the basis of Article 6(1) point b GDPR. Insofar as processing is carried out to safeguard our legitimate interests, it is carried out on the basis of Article 6(1) point f GDPR. Our legitimate interests lie in efficient communication, secure organisation of our business processes, structured collaboration, documentation of business transactions, processing of enquiries as well as supporting our employees in processing business tasks. Insofar as we are legally obliged to retain certain communication, documents or business transactions, processing is carried out on the basis of Article 6(1) point c GDPR. Insofar as special categories of personal data are processed in individual cases, this is only done if there is a legal basis for this under Article 9 GDPR.

Insofar as such processing for the provision and operation of Microsoft 365 including Outlook and Microsoft 365 Copilot is carried out on our behalf, Microsoft processes personal data as a processor within the meaning of Article 4 No. 8 GDPR. We have concluded a data processing agreement with Microsoft within the meaning of Article 28(3) GDPR. In this, Microsoft undertakes in particular to process personal data only in accordance with our instructions and for the provision of the agreed services, to implement appropriate technical and organisational protective measures and to use sub-processors only in accordance with the contractual provisions.

Further information on data processing by Microsoft can be found at https://www.microsoft.com/de-de/privacy/privacystatement . Further information on the Microsoft Products and Services Data Protection Addendum can be found at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA

2.4 Contact

As part of customer communication, we collect personal data to process your enquiries in accordance with Article 6(1) sentence 1 point b GDPR if you voluntarily provide it to us when contacting us (e.g. via contact form or email). Mandatory fields are marked as such, because in these cases we absolutely require the data to process your contact request. The data collected can be seen from the respective input forms. After complete processing of your enquiry, your data will be deleted unless you have expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point a GDPR or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this policy.

3. Data processing for the purpose of dispatch processing

For the fulfilment of the contract in accordance with Article 6(1) sentence 1 point b GDPR, we pass on your data to the shipping service provider commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods.

Data transfer to shipping service providers for the purpose of dispatch notification

Insofar as you have given us your express consent for this during or after your order, we will on this basis in accordance with Article 6(1) sentence 1 point a GDPR pass on your email address to the selected shipping service provider so that they can contact you before delivery for the purpose of delivery notification or coordination.
Consent can be withdrawn at any time by sending a message to the contact option described in this privacy policy or directly to the shipping service provider at the contact address listed below. After withdrawal we delete the data you provided for this purpose, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this policy.

DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany

DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany

4. Data processing for payment processing

When processing payments in our online shop, we work with these partners: technical service providers, credit institutions, payment service providers.

4.1 Data processing for transaction processing

Depending on the selected payment method, we pass on the data necessary for processing the payment transaction to our technical service providers, who act for us within the framework of processing on our behalf, or to the commissioned credit institutions or to the selected payment service provider, insofar as this is necessary for processing the payment. This serves the fulfilment of the contract in accordance with Article 6(1) sentence 1 point b GDPR. In some cases, the payment service providers collect the data required for processing the payment themselves, e.g. on their own website or via a technical integration in the order process. In this respect, the privacy policy of the respective payment service provider applies.
If you have any questions regarding our partners for payment processing and the basis of our cooperation with them, please use the contact option described in this privacy policy.

4.2 Data processing for the purpose of fraud prevention and optimisation of our payment processes

If necessary, we provide our service providers with further data, which they use together with the data required for processing the payment as our processors for the purpose of fraud prevention and optimisation of our payment processes (e.g. invoicing, handling of disputed payments, support for accounting). This serves in accordance with Article 6 (1) sentence 1 point f GDPR to safeguard our overriding legitimate interests in protecting ourselves against fraud and in efficient payment management following a balancing of interests.

4.3 Identity and credit check when selecting purchase on account via PayOne

If you choose the payment method purchase on account (offered via PayOne GmbH, Lyoner Str. 9, 60528 Frankfurt a. M., Germany (hereinafter PayOne)), we ask for your consent in accordance with Article 6(1) sentence 1 point a GDPR that we may transmit the data necessary for processing the payment and for an identity and credit check to PayOne. In Germany, the credit agencies named in the PayOne Privacy Policy may be used for the identity and credit check. PayOne uses the information received on the statistical probability of a payment default for a balanced decision on the establishment, implementation or termination of the contractual relationship. You can withdraw your consent at any time by sending a message to the contact option stated in this privacy policy. This may result in us no longer being able to offer you certain payment options.

5. Advertising by email

5.1 Email newsletter with registration, newsletter tracking with separate consent

If you subscribe to our newsletter, we use the data required for this purpose or separately provided by you to send you our email newsletter regularly on the basis of your consent in accordance with Article 6(1) sentence 1 point a GDPR. Unsubscribing from the newsletter is possible at any time and can either be done by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After unsubscribing, we delete your email address from the list of recipients, unless you have not expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point a GDPR or unless we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this policy.

If you have additionally given us your consent in accordance with Article 6(1) sentence 1 point a GDPR for the analysis of our newsletters, we also analyse your handling of our newsletter by measuring, storing and evaluating open rates and click rates for the purpose of designing future newsletter campaigns (“newsletter tracking”).

For this evaluation, the emails sent contain single-pixel technologies (e.g. so-called web beacons, tracking pixels), which are stored on our website. For the evaluations, we link in particular the following “newsletter data”

  • the page from which the page was requested (so-called referrer URL),
  • the date and time of the access,
  • the description of the type of web browser used,
  • the IP address of the requesting computer,
  • the email address,
  • the date and time of registration and confirmation

and the single-pixel technologies with your email address or your IP address and, if applicable, an individual ID. Links also contained in the newsletter may contain this ID.

Unsubscribing from newsletter tracking is possible at any time and can either be done by sending a message to the described contact option or via a link provided for this purpose in the newsletter.

The information will be stored for as long as you have subscribed to the newsletter.

5.2 Email advertising without newsletter registration and your right to object

If we receive your email address in connection with the sale of a product or service and you have not objected to this, we reserve the right to send you regular vouchers or offers from our range. You can object to this use of your email address at any time by sending a message to the contact option described below or via a link provided for this purpose in the advertising email, without incurring any costs other than the transmission costs according to the basic rates.

5.3 Newsletter dispatch

The newsletter and the newsletter tracking described above may also be sent by our service providers within the framework of processing on our behalf. If you have any questions regarding our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.

5.4 Sending review requests by email

If you have given us your express consent for this during or after your order in accordance with Article 6(1) sentence 1 point a GDPR, we use your email address for the request to submit a review of your order via the review system we use. This consent can be withdrawn at any time by sending a message to the contact option described in this privacy policy or via a link provided for this purpose in the review request.

The review requests may also be sent by our service provider Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne (Trusted Shops) .

In the context of sending review requests we receive information from Trusted Shops on the respective status (e.g. whether the review request was sent and whether it arrived). This is done in accordance with Article 6(1) sentence 1 point f GDPR to fulfil our legitimate interest in receiving information about the review invitations so that optimisations can be made on this basis if necessary, as well as to fulfil the legitimate interest of Trusted Shops in being able to offer this service.

For the sending of review requests and for the collection and display of review or status information, we are jointly responsible with Trusted Shops.

Within the framework of the joint responsibility existing between us and Trusted Shops GmbH, for data protection questions and for asserting your rights, please preferably contact Trusted Shops GmbH, whose contact options you can find here. Further information on data protection can be found at the following link here. Regardless of this, you can also always contact us using the contact option described in this privacy policy. Your enquiry will then, if necessary, be passed on to the other controller for response.

6. Cookies and other technologies

6.1 General information

In order to make visiting our website attractive and to enable the use of certain functions, we use technologies on various pages including so-called cookies. Cookies are small text files that are automatically stored on your end device. Some of the cookies we use are deleted again after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognise your browser on the next visit (persistent cookies).

Protection of privacy on end devices
When using our online offering, we use technologies that are strictly necessary in order to be able to provide the telemedia service expressly requested. The storage of information in your end device or access to information that is already stored in your end device does not require consent in this respect.

For functions that are not strictly necessary, the storage of information in your end device or access to information that is already stored in your end device requires your consent. We would like to point out to you that if consent is not granted, parts of the website may possibly not be fully usable. Any consents you may have granted remain in place until you adjust or reset the relevant settings in your end device.

Any downstream data processing by cookies and further technologies
We use such technologies that are absolutely necessary for the use of certain functions of our website (e.g. shopping basket function). Through these technologies, IP address, time of visit, device and browser information as well as information on your use of our website (e. g. information on the contents of the shopping basket) are collected and processed. This serves overriding legitimate interests in an optimised presentation of our offering in accordance with Article 6(1) sentence 1 point f GDPR following a balancing of interests.

In addition, we use technologies to fulfil the legal obligations to which we are subject (e.g. in order to be able to prove consents to the processing of your personal data) as well as for web analysis and online marketing. Further information on this including the respective legal basis for data processing can be found in the following sections of this privacy policy. Where applicable, we also use technologies that are not individually listed in this privacy policy. More detailed information on these technologies including the respective legal basis for data processing can be found on the Usercentrics platform. You can reach this by clicking on the fingerprint button in the lower right or lower left corner of the page.

The cookie settings for your browser can be found under the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™

Insofar as you have consented to the use of the technologies in accordance with Article 6(1) sentence 1 point a GDPR, you can withdraw your consent at any time by sending a message to the contact option described in the privacy policy. Alternatively, you can click on the fingerprint button in the lower right or lower left corner of the page. If cookies are not accepted, the functionality of our website may be restricted.

6.2 Consent Manager Platform (CMP)

On our website we use a consent management service (“Consent Manager Platform (CMP)”) in order to inform you about the cookies and the other technologies that we use on our website, as well as to obtain, manage and document your consent, where required, to the processing of your personal data by these technologies. This is necessary in accordance with Article 6(1) sentence 1 point c GDPR to fulfil our legal obligation in accordance with Article 7(1) GDPR to be able to prove your consent to the processing of your personal data, to which we are subject. 

The Consent Manager Platform (CMP) used is an offer from ACRIS E-Commerce GmbH, Am Pfenningberg 60, 4040 Linz, Austria, which processes your data on our behalf. After submitting your cookie declaration on our website, the web server stores the following data: IP address, device information, browser information, selected language, accessed website or its URL, date and time of your declaration of consent as well as information on your consent behaviour. In addition, the following technologies are used, which contains/ contain information on your consent behaviour: cookies The data is stored exclusively on the end device, a transfer of personal data to the provider of the Consent Manager Platform (CMP) does not take place. 

Your data is deleted after 30 days unless you have not expressly consented to further use of your data in accordance with Article 6(1) sentence 1 point a GDPR or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this policy.

6.3 Information on third-country transfer (data transfer to third countries)
We use technologies from service providers on our website whose registered office and/or server locations may be in third countries outside the EU or the EEA. If there is no adequacy decision of the EU Commission for this country, an appropriate level of data protection must be ensured by other suitable safeguards. 
Suitable safeguards in the form of contractually agreed standard contractual clauses of the EU Commission or binding internal data protection rules (Binding Corporate Rules) are in principle possible, but require prior review by the contracting parties as to whether an adequate level of protection can be ensured. According to the case law of the ECJ, it may be necessary to take additional protective measures for this purpose.
As a matter of principle, we have agreed with the technology providers used by us who process personal data in a third country the standard data protection clauses issued by the EU Commission. Where possible, we also agree additional safeguards intended to ensure that sufficient data protection is guaranteed in the third countries without an adequacy decision.  
Notwithstanding this, it may occur that despite all contractual and technical measures, the level of data protection in the third country does not correspond to that of the EU. In these cases, we ask you, if necessary, in the context of cookie consent, for your consent in accordance with Article 49(1) point a GDPR to transfer your personal data to a third country. In particular, there is a risk here that local authorities of the third country may from a European data protection perspective obtain access rights that may not be sufficiently restricted to your personal data, without us as data exporter or you as data subject becoming aware of this and/or you possibly also having no sufficient legal remedies available to you to prevent this and/or to take action against such access.  
In particular, the following countries currently count as third countries without an adequacy decision of the EU Commission (example list):  China,  Russia,  Taiwan 
 You can find out to which third countries data is transferred by us in the data protection notices for the respective tool used and/or the consent management service used by us/ Consent Manager Platform (CMP). 

7. Use of cookies and other technologies

Insofar as you have given your consent for this in accordance with Article 6(1) sentence 1 point a GDPR, we use the following cookies and other technologies from third-party providers on our website. Once the purpose no longer applies and the use of the respective technology by us ends, the data collected in this context will be deleted. You can withdraw your consent at any time with effect for the future. Further information on your withdrawal options can be found in the section "Cookies and further technologies". Further information including the basis of our cooperation with the individual providers can be found with the individual technologies. If you have questions regarding the providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.

Adcell Retargeting
Through the advertising partner Firstlead GmbH, Rosenfelder Str. 15-16, 10315 Berlin (“adcell”), we advertise this website in search results as well as on the websites of third parties. When you visit our website, a retargeting cookie from adcell or its partners is automatically set, which by means of a pseudonymous cookie ID and on the basis of the pages you visited enables interest-based advertising. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 GDPR. We determine the parameters of the respective advertising campaign. For the exact implementation (e.g. the decision on the placement of the individual adverts) adcell is responsible. The data automatically collected by adcell (IP address, time of visit, device and browser information as well as information on your use of our website) may possibly be combined by adcell with information from other sources and transmitted to adcell advertising partners.

advanced store Retargeting
Through the advertising partner advanced store GmbH, Alte Jakobstr. 79/80, 10179 Berlin (“advanced store”), we advertise this website in search results as well as on the websites of third parties. When you visit our website, a retargeting cookie from advanced store or its partners is automatically set, which by means of a pseudonymous cookie ID and on the basis of the pages you visited enables interest-based advertising. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 GDPR. We determine the parameters of the respective advertising campaign. For the exact implementation (e.g. the decision on the placement of the individual adverts), advanced store is responsible. The data automatically collected by advanced store (IP address, time of visit, device and browser information as well as information on your use of our website) may possibly be combined by advanced store with information from other sources and transmitted to advanced store advertising partners.

Customa
On this website, technologies from customa are used to collect and store data for marketing and optimisation purposes. The provider of this technology is trust in dialog Services GmbH, Merkurring 33-35, 22143 Hamburg, https://www.customa.de. Cookies may be used for this purpose. Cookies are text files that are stored locally in the cache of the visitor’s internet browser. The cookies enable the internet browser to be recognised.

7.1 Use of Google services

We use the technologies described below of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by the Google technologies about your use of our website is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. There is no adequacy decision of the European Commission for the USA. Our cooperation with them is based on Standard Data Protection Clauses of the European Commission.  Insofar as your IP address is collected via the Google technologies, it is shortened before storage on Google’s servers by activating IP anonymisation. Only in exceptional cases is the full IP address transmitted to a server of Google and shortened there. Unless otherwise specified for the individual technologies, data processing is carried out on the basis of an agreement concluded for the respective technology between joint controllers in accordance with Article 26 GDPR. Further information on data processing by Google can be found in the Google privacy notice.

Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has by decision determined an adequate level of data protection. Our service providers are based in and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission. Our cooperation with them is based on Standard Data Protection Clauses of the European Commission.   

Google Analytics
For the purpose of website analysis, data (IP address, time of visit, device and browser information as well as information on your use of our website) is automatically collected and stored by Google Analytics, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Your IP address is generally not combined with other data of Google. Data processing is carried out on the basis of an agreement on processing on behalf by Google.

Google Ads
For advertising purposes in the Google search results as well as on the websites of third parties, when you visit our website, the so-called Google Remarketing cookie is set, which automatically, through the collection and processing of data (IP address, time of visit, device and browser information as well as information on your use of our website) and by means of a pseudonymous cookie ID and on the basis of the pages you visited, enables interest-based advertising. Any further data processing only takes place insofar as you have activated the setting “personalised advertising” in your Google account. If in this case during the visit to our website you are logged in to Google, Google uses your data together with Google Analytics data to create and define target group lists for cross-device remarketing.

For website analysis and event tracking, via Google Ads Conversion Tracking we measure your subsequent usage behaviour if you arrived at our website via a Google Ads advertisement. Cookies may be used for this purpose and data (IP address, time of visit, device and browser information as well as information on your use of our website on the basis of events specified by us such as e.g. visit of a website or newsletter registration) may be collected, from which usage profiles are created using pseudonyms.

Google Maps
For the visual representation of geographical information, data about your use of the Maps functions, in particular the IP address as well as location data, is collected by Google Maps, transmitted to Google and then processed by Google. We have no influence on this subsequent data processing.

Google Fonts
For the uniform presentation of the contents on our website, data (IP address, time of visit, device and browser information) is collected by the script code “Google Fonts”, transmitted to Google and then processed by Google. We have no influence on this subsequent data processing.

Google Tag Manager
Through Google Tag Manager we can manage various codes and services on our website. When implementing the individual tags, Google may also process personal data (e.g. IP address, online identifiers (including cookies)). Data processing is carried out on the basis of an agreement on processing on behalf by Google.

By using Google Tag Manager, integration of various services/technologies can be achieved.
If you do not wish the use of individual tracking services and have therefore deactivated them, the deactivation remains in place for all affected tracking tags that are integrated via Google Tag Manager.

YouTube Video Plugin
For the integration of third-party content, data (IP address, time of visit, device and browser information) is collected via the YouTube Video Plugin in the enhanced privacy mode used by us, transmitted to Google and then processed by Google, only if you play a video.

7.2 Use of Facebook services

Use of Facebook Pixel
We use the Facebook Pixel as part of the technologies presented below of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Facebook (by Meta)” or “Meta Platforms Ireland”). With Facebook Pixel, data (IP address, time of visit, device and browser information as well as information on your use of our website on the basis of events specified by us such as e.g. visit of a website or newsletter registration) is automatically collected and stored, from which usage profiles are created using pseudonyms. For this purpose, when you visit our website, the Facebook Pixel automatically sets a cookie which automatically by means of a pseudonymous cookie ID enables your browser to be recognised when visiting other websites. Facebook (by Meta) will combine this information with further data from your Facebook account and use it to compile reports on website activities and to provide further services connected with website use, in particular personalised and group-based advertising.

The information automatically collected by the Facebook (by Meta) technologies about your use of our website is generally transmitted to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA and stored there. For the USA there is no adequacy decision of the European Commission. Insofar as the data transfer to the USA falls within our responsibility, our cooperation is based on Standard Data Protection Clauses of the European Commission. Further information on data processing by Facebook can be found in the privacy notices of Facebook (by Meta).

Our service providers are based in and/or use servers in the following countries, for which the European Commission has by decision determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina. There is a decision of the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the relevant service provider is certified.A certification exists. Our service providers are based in and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. For these countries, there is no adequacy decision of the European Commission in place. Our cooperation with them is based on these safeguards:  Standard Data Protection Clauses of the European Commission.

Facebook Ads (Ads Manager)
Via Facebook Ads, we advertise this website on Facebook (by Meta) as well as on other platforms. We determine the parameters of the respective advertising campaign. Facebook (by Meta) is responsible for the precise implementation, in particular the decision on the placement of the adverts with individual users. Unless otherwise specified for the individual technologies, data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 GDPR. The joint responsibility is limited to the collection of the data and its transfer to Meta Platforms Ireland. The subsequent data processing by Meta Platforms Ireland is not covered by this.

7.3 Other providers of web analysis and online marketing services

Use of AdCell Retargeting for online marketing
Through the advertising partner Firstlead GmbH, Rosenfelder Str. 15-16, 10315 Berlin (“adcell”), we advertise this website in search results as well as on the websites of third parties. When you visit our website, a retargeting cookie from adcell or its partners is automatically set, which by means of a pseudonymous cookie ID and on the basis of the pages you visited enables interest-based advertising. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 GDPR. We determine the parameters of the respective advertising campaign. For the exact implementation (e.g. the decision on the placement of the individual adverts) adcell is responsible. The data automatically collected by adcell (IP address, time of visit, device and browser information as well as information on your use of our website) may possibly be combined by adcell with information from other sources and transmitted to adcell advertising partners.

Use of Vimeo Video Plugin for the integration of third-party content
For the integration of third-party content, data is collected via the Video Plugin of Vimeo LLC, 555 West 18th Street, New York 10011, USA (“Vimeo”) (IP address, time of visit, device and browser information), transmitted to Vimeo and then processed by Vimeo. Data processing is carried out on the basis of an agreement between joint controllers in accordance with Article 26 GDPR. In the Vimeo Video Plugin, Google Analytics is automatically integrated. For the purpose of website analysis, data (IP address, time of visit, device and browser information as well as information on your use of our website) is automatically collected and stored by Google Analytics, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Google Analytics is an offer of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google about your use of our website is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. Your IP address is shortened before storage on the servers of Google by activating IP anonymisation. Only in exceptional cases is the full IP address transmitted to a server of Google in the USA and shortened there. We have no influence and no access to the data processing by Vimeo including the settings and the results of Google Analytics. For the USA there is no adequacy decision of the European Commission. Our cooperation with them is based on Standard Data Protection Clauses of the European Commission. 

8. Integration of the Trusted Shops Trustbadge/ other widgets

Provided that you have given your consent for this in accordance with Article 6(1) sentence 1 point a GDPR, Trusted Shops widgets are integrated on this website to display the Trusted Shops services (e.g. quality seal, collected reviews) as well as to offer the Trusted Shops products for buyers after an order. The Trustbadge and the services advertised with it are an offer of Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are jointly responsible under data protection law in accordance with Article 26 GDPR. We inform you below within the framework of this privacy notice about the essential contractual contents under Article 26(2) GDPR. Within the framework of the joint responsibility existing between us and Trusted Shops AG, for data protection questions and for asserting your rights, please preferably contact Trusted Shops using the contact options stated in the data protection information. Regardless of this, however, you can always contact the controller of your choice. Your enquiry will then, if necessary, be passed on to the other controller for response.

8.1 Data processing when integrating the Trustbadge/ other widgets

The Trustbadge is provided by a US CDN provider (Content-DeliveryNetwork). An appropriate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which for the USA can be accessed here. Service providers from the USA used are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information is available here. Insofar as service providers used are not certified under the DPF, standard contractual clauses have been concluded as an appropriate safeguard. When the Trustbadge is accessed, the web server automatically stores a so-called server log file, which also contains your IP address, date and time of access, transmitted data volume and the requesting provider (access data) and documents the access. The IP address is anonymised immediately after collection, so that the stored data cannot be assigned to your person. The anonymised data is used in particular for statistical purposes and for error analysis.

8.2 Data processing after order completion

Provided that you have given your consent, the Trustbadge accesses after order completion the order information stored in your end device (order total, order number, if applicable purchased product) as well as email address and your email address is hashed by means of a cryptological one-way function. The hash value is then transmitted to Trusted Shops together with the order information in accordance with Article 6(1) sentence 1 point a GDPR. This serves to verify whether you are already registered for services of Trusted Shops. If this is the case, further processing takes place in accordance with the contractual agreement made between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will subsequently have the option of registering manually for use of the services or concluding the cover within the framework of your existing user contract, if applicable.
For this purpose, after completion of your order, the Trustbadge accesses the following information stored in the end device used by you: order total, order number and email address. This is necessary so that we can offer you buyer protection. Transmission of the data to Trusted Shops only takes place once you actively choose to conclude buyer protection by clicking on the correspondingly designated button in the so-called Trustcard. If you decide to use the services, the further processing is governed by the contractual agreement with Trusted Shops in accordance with Article 6(1) point b GDPR in order to complete your registration for buyer protection and secure the order and, if applicable, to subsequently send you review invitations by email. 
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Article 6(1) point f GDPR for the purpose of ensuring trouble-free operation. Processing may take place in third countries (USA and Israel). An appropriate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which for the USA here and for Israel here can be accessed. Service providers from the USA used are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information is available here. Insofar as service providers used are not certified under the DPF, standard contractual clauses have been concluded as an appropriate safeguard.

9. Social media

9.1 Social plugins from Facebook (by Meta), Instagram (by Meta)

Social buttons from social networks are used on our website. These are merely integrated into the page as HTML links, so that when our website is accessed, no connection to the servers of the respective provider is yet established. If you click one of the buttons, the website of the respective social network opens in a new window of your browser There you can e.g. press the Like or Share button .

9.2 Our online presence on Facebook (by Meta), Instagram (by Meta), Youtube, Pinterest, LinkedIn, Xing

Insofar as you have given your consent for this in accordance with Article 6(1) sentence 1 point a GDPR to the respective social media operator, when visiting our online presences on the social media named above, your data is automatically collected and stored for market research and advertising purposes, from which usage profiles are created using pseudonyms. These can be used, for example, in order to display advertisements within and outside the platforms that are presumed to correspond to your interests. Cookies are regularly used for this purpose. For the detailed information on the processing and use of the data by the respective social media operator as well as a contact option and your related rights and setting options for the protection of your privacy, please refer to the privacy notices of the providers linked below. Should you still need help in this regard, you can contact us.

Facebook (by Meta) is an offer of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland about your use of our online presence on Facebook (by Meta) is generally transmitted to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA and stored there. For the USA there is no adequacy decision of the European Commission in place. Our cooperation with them is based on Standard Data Protection Clauses of the European Commission.  The data processing in the context of visiting a Facebook (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 GDPR. Further information (information on Insights data) can be found here.

Our service providers are based in and/or use servers in the following countries, for which the European Commission has by decision determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina. There is a decision of the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the relevant service provider is certified. A certification exists. Our service providers are based in and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. For these countries, there is no adequacy decision of the European Commission in place. Our cooperation with them is based on these safeguards:  Standard Data Protection Clauses of the European Commission.


Instagram (by Meta) is an offer of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Meta Platforms Ireland”) The information automatically collected by Meta Platforms Ireland about your use of our online presence on Instagram is generally transmitted to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA and stored there. For the USA there is no adequacy decision of the European Commission in place. Our cooperation with them is based on Standard Data Protection Clauses of the European Commission.  The data processing in the context of visiting an Instagram (by Meta) fan page is carried out on the basis of an agreement between joint controllers in accordance with Article 26 GDPR. Further information (information on Insights data) can be found here.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has by decision determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina. There is a decision of the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the relevant service provider is certified. A certification exists. Our service providers are based in and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. For these countries, there is no adequacy decision of the European Commission in place. Our cooperation with them is based on these safeguards: Standard Data Protection Clauses of the European Commission.

YouTube is an offer of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google about your use of our online presence on YouTube is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. 
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has by decision determined an adequate level of data protection. Our service providers are based in and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission in place. Our cooperation with them is based on Standard Data Protection Clauses of the European Commission. 

Pinterest is an offer of Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (“Pinterest”). The information automatically collected by Pinterest about your use of our online presence on Pinterest is generally transmitted to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA and stored there. 
Our service providers are based in and/or use servers in countries outside the EU and the EEA for which the European Commission has by decision determined an adequate level of data protection. Our service providers are based in and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission in place. Our cooperation with them is based on Standard Data Protection Clauses of the European Commission. 

LinkedIn is an offer of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information automatically collected by LinkedIn about your use of our online presence on LinkedIn is generally transmitted to a server of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA and stored there. 
Our service providers are based in and/or use servers in the following countries, for which the European Commission has by decision determined an adequate level of data protection: USA. There is a decision of the European Commission on an adequate level of data protection for the USA as the basis for a transfer to a third country, provided that the relevant service provider is certified. Pending certification by our service providers, data transfer continues to be based on this basis: Standard Data Protection Clauses of the European Commission.

Xing is an offer of New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.

10. Contact options and your rights

10.1 Your rights

As a data subject, you have the following rights:

  • in accordance with Article 15 GDPR, the right to request information about your personal data processed by us to the extent specified therein;
  • in accordance with Article 16 GDPR, the right to request without undue delay the rectification of inaccurate or completion of your personal data stored by us;
  • in accordance with Article 17 GDPR, the right to request the deletion of your personal data stored by us, insofar as further processing is not required
    • for exercising the right to freedom of expression and information;
    • for compliance with a legal obligation;
    • for reasons of public interest or
    • for the establishment, exercise or defence of legal claims;
  • in accordance with Article 18 GDPR, the right to request restriction of the processing of your personal data, insofar as
    • the accuracy of the data is contested by you;
    • the processing is unlawful but you oppose its deletion;
    • we no longer require the data but you need it for the establishment, exercise or defence of legal claims or
    • you have lodged an objection pursuant to Article 21 GDPR against the processing;
  • in accordance with Article 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request transmission to another controller;
  • in accordance with Article 77 GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your habitual place of residence or workplace or of our company headquarters for this purpose.

Right to object

Insofar as we process personal data as explained above in order to safeguard our overriding legitimate interests following a balancing of interests, you can object to this processing with effect for the future. If the processing is carried out for purposes of direct marketing, you can exercise this right at any time as described above . Insofar as the processing is carried out for other purposes, you only have a right to object if there are reasons arising from your particular situation.

After exercising your right to object, we will not continue to process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves the establishment, exercise or defence of legal claims.

This does not apply if the processing is carried out for purposes of direct marketing . In that case, we will no longer process your personal data for this purpose.

10.2 Contact options

If you have questions regarding the collection, processing or use of your personal data, for information, rectification, restriction or deletion of data as well as withdrawal of granted consents or objection to a specific use of data, please contact us directly using the contact data in our legal notice.

Data Protection Officer:
SHIELD GmbH Martin Vogel
Ohlrattweg 5
25497 Prisdorf
Germany

info@shield-datenschutz.de

Privacy Policy created with the Trusted Shops legal text generator