Data protection information for Horando Germany

We – Horando Deutschland GmbH (“Horando” or “we”) – would like to inform you about our processing of your personal data in accordance with the General Data Protection Regulation (“GDPR”).

Our privacy policy has a modular structure. It consists of general information for all processing of personal data and processing situations (I.) and specific information, the content of which only applies to the processing situation specified therein (II. ff.). To find the relevant sections, please follow the structure below:

1. General information

2. Additional information regarding data processing when visiting the website

3. Additional information for users of our online shop

4. Additional information regarding communication with us

5. Additional information for contractual partners

6. Additional information for applicants

{"type":"root","children":[{"type":"heading","children":[{"type":"text","value":"1. General Information"}],"level":2},{"type":"heading","children":[{"type":"text","value":"\n\n1.1. Data Controller"}],"level":3},{"type":"paragraph","children":[{"type":"text","value":"\n\nController within the meaning of the GDPR and other national data protection laws of the Member States, as well as other data protection laws."}]},{"type":"paragraph","children":[{"type":"text","value":"important provisions is"}]},{"type":"paragraph","children":[{"type":"text","value":"Horando Deutschland GmbH"}]},{"type":"paragraph","children":[{"type":"text","value":"Georgstr. 38"}]},{"type":"paragraph","children":[{"type":"text","value":"30159 Hannover"}]},{"type":"paragraph","children":[{"type":"text","value":"Mail: contact@horando.de"}]},{"type":"paragraph","children":[{"type":"text","value":"Webseite: www.horando.de"}]},{"type":"paragraph","children":[{"type":"text","value":"1.2. Legal basis for the processing of personal data\n\nWe process some of your personal data on the basis of the following legal bases:\n\n1.2.1. Consent of the data subject\n\nIf we obtain the consent of the data subject for specific purposes, Art. 6 (1) (a) GDPR is the legal basis.\n\n1.2.2. Fulfillment of contractual obligations\n\nIf processing is necessary to fulfill a contract to which you are a party, Art. 6 (1) (b) GDPR is the legal basis. This also applies to processing operations required to carry out pre-contractual measures.\n\n1.2.3. Legal requirements and obligations\n\nIf processing is necessary to fulfill a legal obligation to which we are subject, Art. 6 (1) (c) GDPR is the legal basis.\n\n1.2.4. Protection of legitimate interests\n\nTo the extent that processing is necessary to protect our legitimate interests or those of a third party, and your interests, fundamental rights, and freedoms do not override the aforementioned interest, Art. 6 (1) (f) GDPR serves as the legal basis.\n\n1.3. Storage period and deletion of personal data\n\nPersonal data will be deleted or blocked as soon as there is no longer a legal basis for processing.\n\n1.4. Recipients of personal data\n\nInternally, only those departments that need it to fulfill their processing purposes process personal data. This also applies to the processors, service providers, and vicarious agents we employ. All departments and persons who work with personal data are obliged to maintain data confidentiality and are informed of the sensitive handling of such data.\n\nPersonal data will only be passed on to third parties if this is in compliance with data protection regulations. In particular, persons employed to carry out our business operations (e.g., banks, tax consultants, IT service providers) as well as government agencies/authorities may receive your personal data if this is necessary to fulfill a legal obligation.\n\n1.5. Data processing in third countries\n\nSome of our services require the processing of personal data in countries outside the EU/EEA (\"third countries\") by our processors. If personal data is processed and there is no data protection level corresponding to European standards in the country, which has been confirmed by an adequacy decision pursuant to Art. 45 (3) GDPR by the EU Commission, we have concluded EU standard contractual clauses with the processors concerned to establish appropriate safeguards within the meaning of Art. 46 GDPR. A copy of the EU standard contractual clauses can be found here:\n\nIf processing takes place in third countries, we will point this out below.\n\n1.6. Rights of data subjects\n\nIf your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis us as the controller:"}]},{"type":"list","listType":"ordered","children":[{"type":"list-item","children":[{"type":"text","value":"Information about the purposes of processing,"}]},{"type":"list-item","children":[{"type":"text","value":"the category of data,"}]},{"type":"list-item","children":[{"type":"text","value":"the categories of recipients to whom your data have been or will be disclosed and information as to whether the personal data will be transferred to a third country or to an international organization (in this context, you may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR),"}]},{"type":"list-item","children":[{"type":"text","value":"the planned storage period,"}]},{"type":"list-item","children":[{"type":"text","value":" the existence of a right to rectification, erasure, restriction of processing or objection,"}]},{"type":"list-item","children":[{"type":"text","value":" the existence of a right to complain, the origin of your data, if it was not collected from us,"}]},{"type":"list-item","children":[{"type":"text","value":" as well as about the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR and – at least in these cases – meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject."}]}]},{"type":"paragraph","children":[{"type":"text","value":"1.6.2 Right to rectification"}]},{"type":"paragraph","children":[{"type":"text","value":"Pursuant to Art. 16 GDPR, you have the right to have your personal data rectified and/or completed if it is incorrect or incomplete. We must carry out the rectification immediately."}]},{"type":"paragraph","children":[{"type":"text","value":"1.6.3 Right to restriction of processing"}]},{"type":"paragraph","children":[{"type":"text","value":"1.6.3. Right to Restriction of Processing\n\nAccording to Art. 18 GDPR, you have the right to request the restriction of the processing of your data if you contest the accuracy of the data or if the processing is unlawful.\n\nIf the restriction of processing has been restricted, we will inform you before the restriction is lifted.\n\n1.6.4. Right to Erasure\n\nAccording to Art. 17 GDPR, you have the right to have your personal data erased, unless processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest, or to assert, exercise, or defend legal claims.\n\n1.6.5. Right to information\n\nIf you have asserted your right to rectification, erasure, or restriction of processing against us, we are obliged to inform all recipients to whom the personal data was disclosed of the rectification, erasure, or restriction of processing, unless doing so proves impossible or involves disproportionate effort.\n\n1.6.6. Right to data portability\n\nAccording to Art. 20 GDPR, you have the right to receive your personal data that you have provided to us in a structured, common, and machine-readable format or to request that it be transmitted to another controller.\n\n1.6.7. Right of objection\n\nAccording to Art. 21 GDPR, you have the right to object to processing if the processing is based on Art. 6 (1) (e) or (f) GDPR.\n\n1.6.8. Right to revoke the declaration of consent under data protection law\n\nAccording to Art. 7 (3) GDPR, you have the right to revoke your declaration of consent under data protection law at any time. Revoking your consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.\n\n1.6.9. Right to lodge a complaint with a supervisory authority\n\nAccording to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data."}]},{"type":"paragraph","children":[{"type":"text","value":"2. Additional information on data processing when visiting the website\n\nWe are responsible for our website and its subpages (\"website\"). Personal data is processed when you use our website. Below, we provide detailed information about the data processing that takes place.\n\n2.1. Provision of the website and creation of log files\n\nWhen you visit our website, we automatically collect data and information from the user's device (so-called log files).\n\n2.2. Processors\n\nTo provide our website, we use the Rocketspace service of the processor ZooBrotghers UG (Siegfriedstraße 49-60, 10365 Berlin), with whom we have concluded a data processing agreement and who processes the personal data exclusively on our behalf.\n\n2.2.1. Information & Duration of Processing\n\nThe following information is processed when you visit our website:"}]},{"type":"list","listType":"ordered","children":[{"type":"list-item","children":[{"type":"text","value":"Information about the browser type and version used"}]},{"type":"list-item","children":[{"type":"text","value":"The operating system of the device"}]},{"type":"list-item","children":[{"type":"text","value":"The user's Internet service provider"}]},{"type":"list-item","children":[{"type":"text","value":"The IP address of the end device"}]},{"type":"list-item","children":[{"type":"text","value":" Name and URL of the retrieved file"}]},{"type":"list-item","children":[{"type":"text","value":" Referrer-URL"}]},{"type":"list-item","children":[{"type":"text","value":" Status code and amount of data transferred"}]},{"type":"list-item","children":[{"type":"text","value":" Date and time of access"}]}]},{"type":"paragraph","children":[{"type":"text","value":"The log files will be deleted within seven days at the latest."}]},{"type":"paragraph","children":[{"type":"text","value":""}]},{"type":"paragraph","children":[{"type":"text","value":"2.2.2. Purpose of processing & legal basis"}]},{"type":"paragraph","children":[{"type":"text","value":"The data is required to display the website on the user's device, to ensure its functionality, and to analyze any malfunctions. We also use the data to optimize the website and ensure the security of our information technology systems."}]},{"type":"paragraph","children":[{"type":"text","value":"The legal basis is Art. 6 (1) (f) GDPR. The collection of log files is mandatory for the operation of the website. Therefore, the user has no right to object."}]},{"type":"heading","level":3,"children":[{"type":"text","value":"2.3. Use of cookies"}]},{"type":"paragraph","children":[{"type":"text","value":"We use cookies on our website. These are text files that are stored in or by the internet browser on the user's device when visiting a website. Each cookie contains a characteristic string of characters that allows the browser to be uniquely identified the next time the website is accessed, and thus the respective user's device."}]},{"type":"paragraph","children":[{"type":"text","value":"2.3.1. Technically Necessary Cookies\n\nSome functions of our website cannot function without the use of cookies. For example, it may be necessary to use so-called counting cookies to prevent overloading the website. Session cookies may also be required to retain the selected language setting for future visits or to detect malicious bot requests. Furthermore, mandatory cookies also allow our system to recognize whether the user has consented to the placement of cookies in their browser or has restricted this (so-called opt-out cookies). These technically necessary cookies are not used to determine the user's identity or to create user profiles. The necessary cookies are deleted after the session ends.\n\nThe legal basis for storing mandatory cookies is Section 25 (2) No. 2 of the German Telemedia Act (TTDSG).\n\nThe legal basis for processing the resulting personal data is Article 6 (1) (f) GDPR.\n\nThe use of these cookies is essential for the operation of the website. Consequently, the user has no option to object.\n\n2.3.2. Optional Cookies\n\nWe use optional cookies on our website. These are used for functional, analytical, or marketing purposes. The use of these cookies is based on the user's consent, which they grant us when they first visit the website. This includes the storage and retrieval of cookies as such, as well as the processing of the personal data generated in this process. The legal basis for the storage and retrieval of analysis cookies is Section 25 (1) TTDSG; for the processing of the personal data generated in this process, Article 6 (1) (a) GDPR applies. You can revoke your consent at any time by changing the settings in the Consent Manager, which is accessible in the footer of our website. There you will also find all information about the cookies used, their purpose, the respective storage period, and the recipients of the data processed by the cookies. The legality of the processing carried out on the basis of the consent until the revocation remains unaffected.\n\nTo provide the Consent Manager, we use the processor Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich (\"Usercentric\"), with whom we have concluded a data processing agreement and who processes user settings exclusively on our behalf. For any data processing on servers in the USA, Usercentric has taken appropriate safeguards in accordance with Art. 46 GDPR.\n\n2.4. Google Services\n\nWe use several Google services. Our contractual partner is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (\"Google\"). Recipients of your data may be:\n\nGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as processor pursuant to Art. 28 GDPR)\n\nGoogle LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.\n\nTo the extent that Google processes data outside the EU/EEA and no data protection level corresponding to European standards exists, Google Ireland Limited has concluded appropriate safeguards pursuant to Art. 46 GDPR. A copy of the contractual clauses can be found here: . Furthermore, Google LLC is certified under the EU-U.S. Data Privacy Framework. Further information can be found at:"}]},{"type":"paragraph","children":[{"type":"text","value":"2.4.1. Google Tag Manager\n\nIf you have given your consent, Google Tag Manager is used on this website.\n\nGoogle Tag Manager is generally used to deploy other tools. Instead of loading a tool directly, it is loaded by Google Tag Manager. Google Tag Manager uses administrator cookies and transfers cookies associated with Tag Manager to Google. The information collected via cookies about your use of this website is usually transferred to a Google server in the USA and stored there.\n\nDue to the server connections between your internet connection and Google's servers, your IP address and network data such as the following are also processed:\n\nApproximate location (region)\n\nTechnical information about the browser and the devices used (e.g., language settings, screen resolution)\n\nInternet provider\n\nThe referrer URL (via which website/advertising medium users came to this website)\n\nThe legal basis for data processing by Google Tag Manager is your consent in accordance with Section 25 (1) TTDSG in conjunction with Article 6 (1) (a) GDPR.\n\nYou can revoke your consent at any time with future effect by accessing the settings in the Consent Manager and changing your selection there. This does not affect the legality of the processing carried out on the basis of your consent until the revocation. The data collected via Tag Manager will otherwise be processed until your consent is revoked.\n\n2.4.2. Google Analytics\n\nIf you have given your consent, the web analysis service Google Analytics 4 is used on this website.\n\nGoogle Analytics uses cookies that enable an analysis of your use of our website. The information collected through cookies about your use of this website is usually transferred to a Google server in the USA and stored there.\n\nIn Google Analytics 4, IP address anonymization is activated by default. Due to IP anonymization, your IP address will be shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. According to Google, the IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.\n\nDuring your website visit, your user behavior is recorded in the form of \"events.\" Events can be:"}]},{"type":"list","listType":"ordered","children":[{"type":"list-item","children":[{"type":"text","value":"Page views"}]},{"type":"list-item","children":[{"type":"text","value":"First time visiting the website"}]},{"type":"list-item","children":[{"type":"text","value":"Start of the session"}]},{"type":"list-item","children":[{"type":"text","value":"Your “click path”, interaction with the website"}]},{"type":"list-item","children":[{"type":"text","value":"Scrolls (whenever a user scrolls to the end of the page (90%))"}]},{"type":"list-item","children":[{"type":"text","value":"Clicks on external links"}]},{"type":"list-item","children":[{"type":"text","value":"internal search queries"}]},{"type":"list-item","children":[{"type":"text","value":"Interaction with videos"}]},{"type":"list-item","children":[{"type":"text","value":" Dateidownloads"}]},{"type":"list-item","children":[{"type":"text","value":" ads viewed / clicked"}]},{"type":"list-item","children":[{"type":"text","value":" Language setting"}]}]},{"type":"paragraph","children":[{"type":"text","value":""}]},{"type":"paragraph","children":[{"type":"text","value":"Also recorded: Your approximate location (region) Your IP address (in abbreviated form) Technical information about your browser and the devices you use (e.g. language settings, screen resolution) Your internet provider The referrer URL (via which website/advertising medium you came to this website)"}]},{"type":"paragraph","children":[{"type":"text","value":"Google will use this information on our behalf to evaluate your pseudonymous use of the website and to compile reports on website activity. The reports provided by Google Analytics are used to analyze the performance of our website."}]},{"type":"paragraph","children":[{"type":"text","value":"Data whose retention period has been reached is automatically deleted once a month.\n\nThe legal basis for this data processing is your consent in accordance with Section 25 (1) TTDSG in conjunction with Article 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by accessing the cookie settings in the Consent Manager and changing your selection there. There you will also find information about the cookies processed. The legality of the processing carried out on the basis of the consent until the revocation remains unaffected.\n\nYou can also prevent cookies from being saved in the first place by setting your browser software accordingly. However, if you configure your browser to reject all cookies, this may limit the functionality of this and other websites. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by:\n\nrefusing to consent to the setting of cookies or by downloading and installing the browser add-on to deactivate Google Analytics. Further information on the terms of use of Google Analytics and Google's privacy policy can be found at https://tools.google.com/dlpage/gaoptout?hl=en and https://tools.google.com/dlpage/gaoptout?hl=en.\n\n2.4.3. Google Marketing Platform\n\nIf you have given your consent, we use services from the Google Marketing Platform (formerly \"DoubleClick\"). These services use cookies to display ads that are relevant to users, to improve campaign performance reports, or to prevent a user from receiving ads more than once. Campaign Manager 360 allows us to run ad campaigns and measure their performance. Display & Video 360 helps us manage display and video campaigns. Search Ads 360 is used to manage search campaigns across various search engines.\n\nGoogle uses a cookie ID to determine which ads are displayed in which browser and can thus prevent them from being displayed more than once. Google can also use cookie IDs to track conversions, i.e., whether a user sees an ad and later visits the advertiser's website to make a purchase. These cookies do not contain any personal information.\n\nYour browser automatically establishes a direct connection to the Google server. According to Google, by integrating these services, Google receives the information that you have accessed the corresponding part of our website or clicked on one of our ads. If you are registered with a Google service, Google can associate the visit with your user account. Even if you are not registered with Google or have not logged in, it is possible for the provider to learn and store your IP address.\n\nFurthermore, we can use cookies to track whether you perform certain actions on our website after seeing or clicking on one of our ads on Google or on another platform (conversion tracking) (\"floodlight\"). Google uses this cookie to understand the content you have interacted with on our websites so that we can later send you targeted advertising.\n\nThe legal basis for this data processing is your consent in accordance with Section 25 (1) TTDSG in conjunction with Article 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by accessing the cookie settings in the consent manager and changing your selection there. There you will also find information about the cookies processed. The legality of the processing carried out on the basis of the consent until the revocation remains unaffected.\n\nIn addition to being able to give or withdraw your consent to the use of analytics and/or marketing cookies generally via the settings at the top of this policy, you can prevent tracking by changing your browser software settings (e.g., disabling third-party cookies), disabling conversion tracking cookies by blocking cookies from the domain in your browser settings, and with regard to interest-based ads from providers who are part of the About Ads self-regulatory campaign by clicking on the link or the link. Please note that if you do this, you may not be able to use all of the website's functions to their full extent."}]},{"type":"paragraph","children":[{"type":"text","value":"2.5. Meta Business Tools\n\nWe use the Meta Business Tools Meta Pixel and Conversion API from Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland.\n\nIf you have given your consent, we process the following personal data: page views and interactions (events), IP address, date/time, user agent, referrer URL, and, if applicable, parameters (e.g., order value, product IDs). If the Advanced Matching/Conversions API is activated, hashed contact information (e.g., email address) may also be transmitted.\n\nThe purpose of this processing is to analyze the use of our website, display interest-based advertisements on Meta services (Facebook, Instagram), and measure campaign success.\n\nWe only store the event data for as long as necessary for the stated purposes. Information on the storage period at Meta can be found in Meta's information:\n\nThe legal basis for processing is your consent; The setting of the pixel and activation of the Conversion API is based on Section 25 (1) TTDSG (German Telemedia Act), and the personal data processed in this process is based on Article 6 (1) (a) GDPR (consent). Consent can be revoked at any time with future effect in the cookie settings (Consent Manager in the website footer) and in the advertising preferences of your Meta account.\n\nWe and Meta are joint controllers for the collection/transmission of certain data via the Meta Business Tools. The allocation of roles is determined by the Meta Business Tools Terms, including the Joint Controller Addendum:\n\nMeta processes data, among other things, in Ireland and may transfer data to third countries (in particular the USA). The basis for data transfer to the USA is the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework (DPF), with which the parent company Meta Platforms Inc. is certified."}]},{"type":"paragraph","children":[{"type":"text","value":"2.6. Newsletter\n\nIf you would like to receive our newsletter, we require an email address from you as well as information that allows us to verify that you are the owner of the specified email address and that you agree to receive the newsletter. You can revoke your consent to the storage of your data, your email address, and their use for sending the newsletter at any time, for example, via the \"Unsubscribe\" link in the newsletter. The legality of any data processing already carried out remains unaffected by this revocation.\n\nThe data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted after you unsubscribe. The legal basis for data processing is your consent (Art. 6 (1) (a) GDPR).\n\nThe newsletter is sent via the Klaviyo service of our processor Klaviyo Inc., 125 Summer St. Ste 600, Boston, MA 02110, USA (hereinafter \"Klaviyo\"), with whom we have concluded a data processing agreement containing the EU standard contractual clauses. Klaviyo is also certified under the EU-U.S. Data Privacy Framework. Further information can be found at\n\n3. Online presence on social media\n\nWe maintain online presences on social networks and platforms in order to communicate with customers, interested parties, and users active there and to inform them about our services.\n\nWe have provided a link to the Facebook and Instagram websites, which are operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. No further data exchange with Meta takes place on our site.\n\nWe have provided a link to the website of X (formerly \"Twitter\"), which is operated by Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland (\"X\"). No further data exchange with X takes place on our site.\n\nWe have provided a link to the website of \"LinkedIn\", which is operated by LinkedIn, Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (\"LinkedIn\"). No further data exchange with LinkedIn takes place on our site.\n\nWe have provided a link to the website of \"YouTube\", which is operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (\"YouTube\"). No further data exchange with YouTube takes place on our site.\n\nWhen you access the respective networks and platforms, the terms and conditions and data processing guidelines of their respective operators apply. Unless otherwise stated in our privacy policy, we process users' data when they communicate with us via social networks and platforms, e.g., by posting on our online presence or sending us messages.\n\n4. Additional information for users of our online shop\n\nWe are responsible for the services available through our online shop. Using these services results in the processing of personal data. Below, we provide detailed information about the data processing that takes place.\n\n4.1. Purchase Process\n\nWe, as the controller of the online shop, process the following personal data when you purchase a product:"}]},{"type":"list","listType":"ordered","children":[{"type":"list-item","children":[{"type":"text","value":"Email address"}]},{"type":"list-item","children":[{"type":"text","value":"First name Name"}]},{"type":"list-item","children":[{"type":"text","value":"Firma (optional)"}]},{"type":"list-item","children":[{"type":"text","value":"Address (incl. Land)"}]},{"type":"list-item","children":[{"type":"text","value":"Different delivery address (optional)"}]},{"type":"list-item","children":[{"type":"text","value":"Apartment, room, etc. (optional)"}]},{"type":"list-item","children":[{"type":"text","value":"Product information about the purchased item"}]},{"type":"list-item","children":[{"type":"text","value":"Telephone"}]}]},{"type":"paragraph","children":[{"type":"text","value":"Billing data\n\nThe purpose of the processing is to provide our contractually agreed services to users. The legal basis for the processing is the purchase contract; Art. 6 (1) (b) GDPR. The data will be processed for the duration of the user agreement, unless you have given us your consent for permanent storage or there is no purpose and legal basis for longer storage. This includes the statutory retention periods (Art. 6 (1) (c) GDPR) and storage for the assertion or defense of civil law claims based on overriding legitimate interests (Art. 6 (1) (f) GDPR)."}]},{"type":"paragraph","children":[{"type":"text","value":"4.2. Processors\n\nTo provide our services, we use the shop system of our processor Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (\"Shopify\") for the purpose of hosting and displaying the online shop, with whom we have concluded a data processing agreement. All data collected on our website is processed on Shopify's servers. As part of the aforementioned Shopify services, data may also be transferred to Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc., or Shopify (USA) Inc. for further processing on our behalf. In the event of data being transferred to Shopify Inc. in Canada, an appropriate level of data protection is guaranteed by the European Commission's adequacy decision. Further information on Shopify's data protection can be found on the following website: Further processing on servers other than those mentioned above by Shopify only takes place within the framework stated below.\n\n4.3. Trusted Shop\n\nTrusted Shops widgets are integrated into this website to display Trusted Shops services (e.g., seal of approval, collected reviews) and to offer Trusted Shops products to buyers after an order. This serves to protect our legitimate interests, which prevail within the context of a balancing of interests, in optimal marketing by enabling secure shopping in accordance with Art. 6 (1) (f) GDPR. The Trustbadge and the services advertised with it are offered by Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne (\"Trusted Shops\"), with whom we are jointly responsible for data protection pursuant to Art. 26 GDPR. Within the scope of this privacy policy, we will inform you below about the essential contractual content pursuant to Art. 26 (2) GDPR.\n\nIn accordance with the joint responsibility existing between us and Trusted Shops, please contact Trusted Shops for data protection questions and to assert your rights using the contact options provided. Regardless of this, you can always contact the responsible party of your choice. Your request will then, if necessary, be forwarded to the other responsible party for response.\n\n4.3.1. Data processing when integrating the Trustbadge / other widgets\n\nWhen you access the Trustbadge, the web server automatically saves a so-called server log file, which also contains your IP address, the date and time of access, the amount of data transferred, and the requesting provider (access data), and documents the access. The IP address is anonymized immediately after collection so that the stored data cannot be assigned to you personally. The anonymized data is used primarily for statistical purposes and error analysis.\n\n4.3.2. Data processing after order completion\n\nAfter the order has been completed, order information (order total, order number, and any purchased product) as well as your email address, which has been hashed using a cryptographic one-way function, are transmitted to Trusted Shops. The legal basis is Art. 6 (1) (f) GDPR. This serves to verify whether you are already registered for Trusted Shops services and is therefore necessary to fulfill our and Trusted Shops' overriding legitimate interests in providing the buyer protection linked to the specific order and the transactional evaluation services pursuant to Art. 6 (1) (f) GDPR. If this is the case, further processing will take place in accordance with the contractual agreement concluded between you and Trusted Shops. If you are not yet registered for the services, you will then be given the opportunity to do so for the first time. Further processing after registration is also governed by the contractual agreement with Trusted Shops. If you do not register, all submitted data will be automatically deleted by Trusted Shops, and personal identification will no longer be possible.\n\n4.3.3. Third-country processing\n\nThe Trustbadge is provided by a US CDN (Content Delivery Network) provider. Trusted Shops also uses service providers in the areas of hosting, monitoring, and logging. The legal basis is Art. 6 (1) (f) GDPR for the purpose of ensuring uninterrupted operation. Processing may take place in third countries (USA and Israel)."}]},{"type":"paragraph","children":[{"type":"text","value":"An appropriate level of data protection is ensured by an adequacy decision of the EU Commission, which is available for the USA here: and for Israel here: https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32011D0061. Service providers used in the USA are generally certified under the EU-U.S. Data Privacy Framework. If service providers used are not certified under the DPF, the EU standard contractual clauses have been concluded as an appropriate safeguard."}]},{"type":"paragraph","children":[{"type":"text","value":"4.4. Payment service providers\n\nWe use the following payment service providers to process payments initiated through our website:"}]},{"type":"list","listType":"ordered","children":[{"type":"list-item","children":[{"type":"text","value":"Credit card company (the respective financial services company that issues your card for Mastercard, VISA, AMEX)"}]},{"type":"list-item","children":[{"type":"text","value":"PayPal, PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg)"}]},{"type":"list-item","children":[{"type":"text","value":"Apple Pay, Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA"}]},{"type":"list-item","children":[{"type":"text","value":"Klarna, Klarna Bank AB (publ.), Chausseestrasse 117, 10115 Berlin"}]},{"type":"list-item","children":[{"type":"text","value":"BitPay Inc., 1201 W Peachtree St NW Ste 2625, PMB 91017, Atlanta, USA"}]}]},{"type":"paragraph","children":[{"type":"text","value":"If these companies provide services as payment service providers (PSPs), they are themselves responsible for the processing of payment data within the meaning of the GDPR. Payments via credit card are processed directly by the respective providers. We do not process this data for our own purposes.\n\nIn some cases, it may be necessary to exchange data related to your respective booking to process payment processing differences between us and the payment service providers. These data transfers are always based on a legitimate interest pursuant to Art. 6 (1) (f) GDPR. Please note that the financial service providers and responsible bodies with regard to the processing of financial transaction data may also transfer your personal data to credit agencies, affiliated companies, and subcontractors, insofar as this is necessary to fulfill contractual obligations or on the basis of a legitimate interest, or if the data is processed on their behalf. It cannot be ruled out that the financial service providers may also transfer personal information to affiliated companies outside the EU or EEA (e.g., in the USA). US (sub)service providers used are generally certified under the EU-U.S. Data Privacy Framework. Further information can be found here: If service providers used are not certified under the DPF, the EU standard contractual clauses have been concluded as a suitable guarantee.\n\nYour data will be transmitted to the financial service providers in encrypted form and processed exclusively by them for the purpose of payment processing. The financial service providers are legally obliged to process and verify this data.\n\nFor further information on data protection in connection with this payment service provider, please refer to the privacy policy of"}]},{"type":"paragraph","children":[{"type":"text","value":""}]},{"type":"paragraph","children":[{"type":"text","value":"Apple Pay: "},{"type":"link","url":"https://www.apple.com/de/legal/privacy/data/de/apple-pay/","title":null,"target":null,"children":[{"type":"text","value":"https://www.apple.com/de/legal/privacy/data/de/apple-pay/","underline":true}]},{"type":"text","value":" "}]},{"type":"paragraph","children":[{"type":"text","value":"Klarna: "},{"type":"link","url":"https://www.klarna.com/de/datenschutz/","title":null,"target":null,"children":[{"type":"text","value":"https://www.klarna.com/de/datenschutz/","underline":true}]},{"type":"text","value":"? "}]},{"type":"paragraph","children":[{"type":"text","value":""}]},{"type":"paragraph","children":[{"type":"text","value":"or from your respective card issuer.\n\nIf you pay for goods or services, we will also pass your data on to our service providers in the areas of banking, taxes, and tax consulting, as well as – within the framework of legal requirements – to the tax authorities.\n\n5. Additional information for communication with us\n\nIf communication takes place within a contractual relationship or another contractual relationship, data processing is also governed by the additional information under V.\n\nIf the communication is aimed at an application to us, data processing is also governed by the additional information under VI.\n\n5.1. Telephone\n\nYou can contact us by telephone.\n\n5.1.1. Information processed & duration of processing\n\nIn addition to your telephone number, we process the personal data you provide to us during the conversation.\n\nThe data will be deleted – unless there is another reason for processing – as soon as the matter has been clarified with you.\n\n5.1.2. Purpose of Processing & Legal Basis\n\nThe personal data will be processed exclusively for the purpose of processing your inquiry and in case of follow-up questions.\n\nIf the communication is aimed at concluding a contract, the legal basis for processing is Art. 6 (1) (b) GDPR.\n\nIn all other cases, Art. 6 (1) (f) GDPR is the legal basis. Your interest does not outweigh our interest in answering your inquiry; since you are writing to us, a response is also in your interest, and you are aware that we must process your personal data to answer your inquiry.\n\n5.2. Email\n\nYou can contact us via email (e.g., via our contact form). We would like to point out that third parties may be able to gain insight into email communications. If it is important to you that the information you provide is not exposed to the risk of illegal access by third parties, we recommend using another communication channel. However, if you contact us via email, we assume that further communication via this channel is in your interest.\n\n5.2.1. Information processed & duration of processing\n\nIn addition to your email address, we process the personal data you provide to us during email communication.\n\nThe data will be deleted – unless there is another reason for processing – once the matter has been resolved with you."}]},{"type":"paragraph","children":[{"type":"text","value":"5.2.2. Purpose of processing & legal basis\n\nThe personal data will be processed exclusively for the purpose of processing the inquiry and in case of follow-up questions.\n\nIf the communication is aimed at concluding a contract, the legal basis for processing is Art. 6 (1) (b) GDPR.\n\nIn all other cases, Art. 6 (1) (f) GDPR is the legal basis. Your interest does not outweigh our interest in answering your inquiry; since you are writing to us, it is also in your interest to answer it, and you are aware that we must process your personal data to answer your inquiry.\n\n5.3. Video telephony\n\nWe also use video telephony for communication.\n\n5.3.1. Processor\n\nTo conduct video calls, we use the \"Google Meet\" service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) or \"MS Teams\" provided by Microsoft Ireland Operations Ltd., One Microsoft Place East Business Park, Carmanhall and Leopardstown, Dublin, D18 P521, Ireland, as our processor. We have concluded a data processing agreement with the processor. The processor may process personal data in a third country to ensure smooth video calls. We have therefore concluded EU standard contractual clauses with the processor to establish appropriate safeguards within the meaning of Art. 46 GDPR.\n\n5.3.2. Information Processed & Duration of Processing\n\nThe following communication data is processed during video calls:"}]},{"type":"list","listType":"ordered","children":[{"type":"list-item","children":[{"type":"text","value":"Personal data (if you provide it yourself)"}]},{"type":"list-item","children":[{"type":"text","value":"Content of the online meeting (if you appear personally with verbal and/or written contributions)"}]},{"type":"list-item","children":[{"type":"text","value":" Authentication data"}]},{"type":"list-item","children":[{"type":"text","value":" Log files, protocol data"}]},{"type":"list-item","children":[{"type":"text","value":" Metadata (e.g. IP address, time of participation, etc.)"}]},{"type":"list-item","children":[{"type":"text","value":" Profile data (e.g. your user name if you provide it yourself)"}]}]},{"type":"paragraph","children":[{"type":"text","value":"The personal data will be deleted as soon as the matter has been resolved with you and unless there is another reason for processing.\n\n5.3.3. Purpose of processing & legal basis\n\nThe personal data will be processed exclusively for the purpose of processing the inquiry and in case of follow-up questions.\n\nIf the communication is aimed at concluding a contract, the legal basis for processing is Art. 6 (1) (b) GDPR.\n\nIn all other cases, Art. 6 (1) (f) GDPR is the legal basis. Your interest does not outweigh our interest in answering your inquiry; since you are writing to us, a response is also in your interest, and you are aware that we must process your personal data to answer your inquiry.\n\n6. Additional information for contractual partners\n\nThe following information also applies to you if we have a contractual relationship.\n\n6.1. Processed Information & Duration of Processing\n\nWhich of your data is processed depends on the tasks within the contractual relationship. We use the personal information exclusively for the purpose for which it was provided to us. This includes, for example, personal details (name, address, and other contact details, date of birth and place of birth). This may also include order data (e.g., payment orders), data from the fulfillment of our contractual obligations (e.g., sales data in payment transactions), information about your financial situation (e.g., creditworthiness data), advertising and sales data, and other data comparable to the aforementioned categories.\n\nThe personal data will be deleted as soon as the contractual relationship with you has ended and unless another reason for processing exists.\n\n6.2. Purpose of Processing & Legal Basis\n\nThe processing is primarily carried out for the purpose of establishing and implementing the contractual relationship; the legal basis is Art. 6 (1) (b) GDPR.\n\nIn addition, we also process some of your data based on our legitimate interest, namely for the purposes of contact and communication management, efficiency audits, contract and project management, and to ensure the operation of information and telecommunications systems. The legal basis is Art. 6 (1) (f) GDPR.\n\nIn addition, as a company, we are bound by various legal obligations that must be complied with under applicable laws and regulations. The legal basis for processing to fulfill legal requirements and obligations is Art. 6 (1) (c) GDPR. These include, among other things, retention obligations under tax law.\n\n7. Additional Information for Applicants\n\nThe following information also applies to you if you apply to us.\n\n7.1. Information Processed & Duration of Processing\n\nWe process the personal data we receive from you through your application.\n\nThe personal data will be deleted after six months if no employment relationship is established. If an employment relationship is established, the data will continue to be processed for this purpose.\n\n7.2. Purpose of processing & legal basis\n\nWe collect and process applicants' personal data for the purpose of processing the application process.\n\nThe legal basis for processing personal data is Section 26 of the German Federal Data Protection Act (BDSG). If we conclude an employment contract with you, the transmitted data will be further processed for the purpose of administering the employment relationship; in this case, the legal basis remains, in particular, Section 26 of the German Federal Data Protection Act (BDSG).\n\nIf no employment contract is concluded, the application documents will be deleted unless other legitimate interests of the controller conflict with deletion. Other legitimate interests in this sense include, for example, the burden of proof in proceedings under the General Equal Treatment Act (AGG)."}]}]}