PRIVACY POLICY

1) Introduction and contact details of the responsible person

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data is any data that can be used to identify you personally.

1.2 The responsible party for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Anakena GmbH & Co. KG, Ulrich-Corti-Str. 10, 81249 Munich, Germany, Tel.: +49 (0)89 32309601, e-mail: info@anakena.de. The controller of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

2) Data collection when visiting our website

2.1 During the mere informational use of our website, i.e. if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to the page server (so-called "server log files"). When you call up our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/reference from which you reached the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f DSGVO on the basis of our legitimate interest in improving the stability and functionality of our website. A transfer or other use of the data does not take place. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.

2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the person responsible). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.

3) Cookies

In order to make visiting our website more attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your end device. In some cases, these cookies are automatically deleted again after closing the browser (so-called "session cookies"), in other cases, these cookies remain on your end device for longer and allow page settings to be saved (so-called "persistent cookies"). In the latter case, you can find the storage period in the overview of the cookie settings of your web browser.

If personal data is also processed by individual cookies used by us, the processing is carried out in accordance with Art. 6 para. 1 lit. b DSGVO either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a DSGVO in the case of consent given, or in accordance with Art. 6 para. 1 lit. f DSGVO to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.

You can set your browser in such a way that you are informed about the setting of cookies and can decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general.

Please note that if you do not accept cookies, the functionality of our website may be limited.

4) Contacting

4.1 WhatsApp Business

We offer visitors to our website the opportunity to contact us via the messaging service WhatsApp of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For this purpose, we use the so-called "business version" of WhatsApp.

If you contact us via WhatsApp on the occasion of a specific transaction (for example, an order placed), we store and use the mobile phone number you use on WhatsApp and - if provided - your first and last name pursuant to Art. 6 para. 1 lit. b. DSGVO to process and respond to your request. On the basis of the same legal basis, we may ask you to provide further data (order number, customer number, address or email address) via WhatsApp in order to be able to assign your request to a specific process.

If you use our WhatsApp contact for general inquiries (such as about the range of services, availability or our website), we store and use the mobile phone number you use on WhatsApp and - if provided - your first name and surname in accordance with Art. 6 (1) lit. f DSGVO based on our legitimate interest in the efficient and timely provision of the requested information.

Your data will only be used to respond to your request via WhatsApp. A transfer to third parties does not take place.

Please note that WhatsApp Business obtains access to the address book of the mobile device we use for this purpose and automatically transfers phone numbers stored in the address book to a server of the parent company Meta Platforms Inc. in the USA. For the operation of our WhatsApp Business account, we use a mobile device in whose address book only the WhatsApp contact data of those users who have also contacted us via WhatsApp are stored.

This ensures that each person whose WhatsApp contact data is stored in our address book has already consented to the transmission of his WhatsApp telephone number from the address books of his chat contacts pursuant to Art. 6 (1) lit. a DSGVO when using the app on his device for the first time by accepting the WhatsApp terms of use. A transmission of data of such users who do not use WhatsApp and/or have not contacted us via WhatsApp is excluded in this respect.

For the purpose and scope of the data collection and the further processing and use of the data by WhatsApp, as well as your rights in this regard and setting options for protecting your privacy, please refer to WhatsApp's privacy policy: https://www.whatsapp.com/legal/?eea=1#privacy-policy

In the course of the above-mentioned processing, data may be transferred to servers of Meta Platforms Inc. in the USA.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

4.2 When contacting us (e.g. via contact form or e-mail), personal data is processed - exclusively for the purpose of processing and responding to your request and only to the extent necessary for this purpose.

The legal basis for the processing of this data is our legitimate interest in responding to your request pursuant to Art. 6 (1) lit. f DSGVO. If your contact is aimed at a contract, the additional legal basis for the processing is Art. 6 (1) lit. b DSGVO. Your data will be deleted when the circumstances indicate that the matter in question has been conclusively clarified and provided that there are no statutory retention obligations to the contrary.

5) Use of customer data for direct marketing purposes

Subscribe to our e-mail newsletter

If you subscribe to our e-mail newsletter, we will send you regular information about our offers. The only mandatory information for sending the newsletter is your e-mail address. The provision of further data is voluntary and is used to address you personally. We use the so-called double opt-in procedure for sending the newsletter, which ensures that you only receive newsletters if you have expressly confirmed your consent to receive the newsletter by clicking on a verification link sent to the email address provided.

By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6 para. 1 lit. a DSGVO. In doing so, we store your IP address entered by the Internet service provider (ISP) as well as the date and time of registration in order to be able to track any possible misuse of your e-mail address at a later date. The data we collect when you register for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a corresponding message to the responsible person named at the beginning. After unsubscribing, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data or we reserve the right to use your data in a manner that goes beyond this, which is permitted by law and about which we inform you in this declaration.

6) Data processing for order processing

6.1 Insofar as necessary for the processing of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 Para. 1 lit. b DSGVO.

If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we will process the contact data (name, address, e-mail address) provided by you when placing the order in order to inform you personally about upcoming updates within the legally stipulated period of time within the scope of our legal information obligations pursuant to Art. 6 (1) lit. c DSGVO by suitable means of communication (e.g. by mail or e-mail). Your contact data will be used strictly for the purpose of informing you about updates owed by us and will only be processed by us for this purpose to the extent necessary for the respective information.

In order to process your order, we also work together with the service provider(s) listed below, who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.

6.2 Transfer of personal data to shipping service providers

- DHL

We use the following provider as transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany

We will pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 Para. 1 lit. a DSGVO prior to delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent for this in the ordering process. Otherwise, we will only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 Para. 1 lit. b DSGVO. The disclosure is made only to the extent necessary for the delivery of goods. In this case, a prior coordination of the delivery date with the provider or the delivery notice is not possible.

The consent can be revoked at any time with effect for the future vis-à-vis the responsible person named above or vis-à-vis the provider.

6.3 Use of payment service providers (payment services)

- Paypal

One or more online payment methods of the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

If you select a payment method of the provider, where you make an advance payment, your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 para. 1 lit. b DSGVO. In this case, your data will be passed on exclusively for the purpose of payment processing with the provider and only insofar as it is necessary for this purpose.

If you select a payment method for which we make advance payments, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, e-mail address, telephone number, and, if applicable, data on an alternative means of payment) during the order process.

In order to protect our legitimate interest in determining your solvency in such cases, this data will be forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 (1) lit. f DSGVO. The provider checks on the basis of the personal data provided by you as well as other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option selected by you can be granted with regard to payment and/or bad debt risks.

The credit report may contain probability values (score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual processing of payments.

7) Online marketing

HubSpot

This website uses the software-based marketing service of the following provider for the provision and synchronization of various customer management services: HubSpot Ireland Ltd, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland.

The service enables the automated processing of feed activities, the control of advertising in deployed marketing channels and the success analysis of marketing measures, as well as central e-mail marketing and contact management.

To fulfill the various functions, cookies are used, i.e. small text files that are stored locally in the cache of your web browser on your terminal device and enable an analysis of your use of the website by us. In doing so, the cookies collect certain information, such as the IP address, the location, the time of the page view.

All processing described above, in particular the setting of cookies for reading out information on the end device used, will only be carried out if you have given us your express consent to do so in accordance with Art. 6 (1) a DSGVO. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

Other legal bases for data processing that apply in the context of specific service functions (such as the need for explicit consent pursuant to Art.6 para. 1 lit. a DSGVO when sending newsletters) remain unaffected.

We have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

8) Web analytics services

8.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, Google Analytics sets 4 cookies when you visit the website, which are stored as small text modules on your end device and collect certain information. The scope of this information also includes your IP address, which is, however, shortened by Google by the last digits in order to exclude a direct personal reference.

The information is transferred to Google servers and processed there. In the process, transfers to Google LLC, based in the USA, are also possible.

Google uses the information collected on our behalf to evaluate your use of the website, to compile reports on website activity for us and to provide other services related to website activity and internet usage. The IP address transmitted and shortened by your browser as part of Google Analytics will not be merged with other data from Google. The data collected in the context of the use of Google Analytics 4 will be stored for a period of two months and then deleted.

All processing described above, in particular the setting of cookies on the terminal device used, will only be carried out if you have given us your express consent for this in accordance with Art. 6 (1) lit. a DSGVO.
Without your consent, Google Analytics 4 will not be used during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service via the "Cookie Consent Tool" provided on the website.

We have concluded an order processing agreement with Google, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

You can find further legal information on Google Analytics 4 at https://policies.google.com/privacy?hl=en&gl=en and under https://policies.google.com/technologies/partner-sites

Demographic characteristics
Google Analytics 4 uses the special function "demographic characteristics" and can use it to create statistics that make statements about the age, gender and interests of site visitors. This is done by analyzing advertising and information from third-party providers. This allows target groups to be identified for marketing activities. However, the collected data cannot be assigned to a specific person and is deleted after being stored for a period of two months.

Google Signals
As an extension to Google Analytics 4, Google Signals can be used on this website to generate cross-device reports. If you have activated personalized ads and linked your devices to your Google account, Google may, subject to your consent to the use of Google Analytics pursuant to Art. 6 (1) lit. a DSGVO, analyze your usage behavior across devices and create database models, including on cross-device conversions. We do not receive any personal data from Google, only statistics. If you want to stop the cross-device analysis, you can deactivate the "Personalized advertising" function in the settings of your Google account. To do so, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=en You can find more information about Google Signals at the following link: https://support.google.com/analytics/answer/7532985?hl=en

UserIDs
As an extension to Google Analytics 4, the "UserIDs" function can be used on this website. If you have consented to the use of Google Analytics 4 pursuant to Art. 6 (1) lit. a DSGVO, have set up an account on this website and log in with this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

8.2 Google Tag Manager

This website uses the "Google Tag Manager", a service of the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").

Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analysis services, and for calibrating, controlling, and attaching conditions to them via a uniform user interface. Google Tag Manager itself does not store any information on user end devices or read them. The service also does not perform any independent data analyses. However, the Google Tag Manager transmits your IP address to Google when you visit a page and may store it there. Also a transmission to servers of Google LLC. In the USA is possible.

This processing is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) a DSGVO. Without this consent, Google Tag Manager will not be used during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

We have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

9) Retargeting/ Remarketing and Conversion Tracking

Meta Pixel

Within our online offering, we use the "Meta Pixel" service of the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Meta")

If a user clicks on an advertisement placed by us on Facebook and/or Instagram, a parameter is added to the URL of our linked page with the help of "meta pixels". This URL parameter is then entered in the user's browser after redirection by a cookie that our linked page sets itself.

On the one hand, this makes it possible for Meta to determine the visitors to our online offering as a target group for the display of advertisements (so-called "ads"). Accordingly, we use the service to display the Facebook and/or Instagram ads placed by us only to those users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited), which we transmit to Meta (so-called "custom audiences").

On the other hand, the "Meta Pixel" can be used to track whether users have been redirected to our website after clicking on an advertisement and what actions they take there (so-called "conversion tracking").

The data collected is anonymous to us, so it does not allow us to draw any conclusions about the identity of the user. However, the data is stored and processed by Meta so that a connection to the respective user profile is possible and Meta can use the data for its own advertising purposes.

All processing described above, in particular the setting of cookies for reading out information on the end device used, will only be carried out if you have given us your express consent to do so in accordance with Art. 6 (1) a DSGVO. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

The information generated by Meta is usually transmitted to a Meta server and stored there; in this context, it may also be transmitted to Meta Platforms Inc. servers in the USA.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10) Page functionalities

10.1 Facebook plugins

Plugins of the social network of the following provider are used on our website: Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

These plugins allow direct interactions with content on the social network.

In order to increase the protection of your data when visiting our website, the plugins are initially deactivated by means of so-called "2-click" or "Shariff" solution integrated into the page.

This integration ensures that when a page of our website containing such plugins is called up, no connection is yet established with the provider's servers.

Only when you activate the plugins and thus give your consent to the data transfer in accordance with Art. 6 (1) a DSGVO, your browser establishes a direct connection to the provider's servers. Here, regardless of a login to an existing user profile, information about your used end device (including your IP address), your browser and your page history is transmitted to the provider to a certain extent and processed there if necessary.

If you are logged into an existing user profile on the provider's social network, information about interactions completed via the plugins will also be published there and displayed to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking on it again. However, the revocation does not affect the data that has already been transferred to the provider.

Data may also be transferred to: Meta Platforms Inc, USA

We have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10.2 Instagram plugins

Plugins of the social network of the following provider are used on our website: Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland

These plugins allow direct interactions with content on the social network.

In order to increase the protection of your data when visiting our website, the plugins are initially deactivated by means of so-called "2-click" or "Shariff" solution integrated into the page.

This integration ensures that when a page of our website containing such plugins is called up, no connection is yet established with the provider's servers.

Only when you activate the plugins and thus give your consent to the data transfer in accordance with Art. 6 (1) a DSGVO, your browser establishes a direct connection to the provider's servers. Here, regardless of a login to an existing user profile, information about your used end device (including your IP address), your browser and your page history is transmitted to the provider to a certain extent and processed there if necessary.

If you are logged into an existing user profile on the provider's social network, information about interactions completed via the plugins will also be published there and displayed to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking on it again. However, the revocation does not affect the data that has already been transferred to the provider.

Data may also be transferred: Meta Platforms Inc., USA

We have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10.3 LinkedIn plugins

Plugins of the social network of the following provider are used on our website: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland

These plugins allow direct interactions with content on the social network.

In order to increase the protection of your data when visiting our website, the plugins are initially deactivated by means of so-called "2-click" or "Shariff" solution integrated into the page.

This integration ensures that when a page of our website containing such plugins is called up, no connection is yet established with the provider's servers.

Only when you activate the plugins and thus give your consent to the data transfer in accordance with Art. 6 (1) a DSGVO, your browser establishes a direct connection to the provider's servers. Here, regardless of a login to an existing user profile, information about your used end device (including your IP address), your browser and your page history is transmitted to the provider to a certain extent and processed there if necessary.

If you are logged into an existing user profile on the provider's social network, information about interactions completed via the plugins will also be published there and displayed to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking on it again. However, the revocation does not affect the data that has already been transferred to the provider.

Data may also be transferred to: LinkedIn Inc., USA

We have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For the transfer of data to the USA, the provider invokes standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.

10.4 Youtube

This website uses plugins to display and play videos from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

Data may also be transmitted to: Google LLC., USA

When you call up a page of our website that contains such a plugin, your browser establishes a direct connection to the provider's servers in order to load the plugin. In this process, certain information, including your IP address, is transmitted to the provider.

If the playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, create playback statistics and prevent abusive behavior.

If you are logged into a user account with the provider during your visit to the site, your data will be directly assigned to your account when you click on a video. If you do not want the assignment to your account, you must log out before pressing the play button.

All of the aforementioned processing, in particular the setting of cookies for the reading of information on the end device used, will only take place if you have given us your express consent to do so in accordance with Art. 6 (1) lit. a DSGVO. You can revoke your consent at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10.5 Google Maps

This website uses an online map service provided by the following provider: Google Maps (API) by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").

Google Maps is a web service for displaying interactive (land) maps to visually display geographical information. By using this service, our location will be displayed to you and a possible approach will be facilitated.

Already when calling up those sub-pages in which the map of Google Maps is integrated, information about your use of our website (such as your IP address) is transmitted to Google servers and stored there, this may also result in a transmission to the servers of Google LLC. in the USA. This occurs regardless of whether Google provides a user account through which you are logged in or whether a user account exists. If you are logged in to Google, your data will be directly assigned to your account. If you do not want the assignment with your profile at Google, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates them.

The collection, storage and analysis are carried out in accordance with Art. 6 (1) f DSGVO on the basis of Google's legitimate interest in the display of personalized advertising, market research and / or the design of Google websites. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right. If you do not agree to the future transmission of your data to Google in the context of the use of Google Maps, you also have the option of completely deactivating the Google Maps web service by turning off the JavaScript application in your browser. Google Maps and thus also the map display on this website can then not be used.

As far as legally required, we have obtained your consent for the processing of your data as described above in accordance with Art. 6 para. 1 lit. a DSGVO. You can revoke your consent at any time with effect for the future. To exercise your revocation, please follow the option described above to make an objection.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10.6 Google Web Fonts

This site uses so-called web fonts of the following provider for the uniform display of fonts: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

When you call up a page, your browser loads the required web fonts into its browser cache in order to display texts and fonts correctly and establishes a direct connection to the provider's servers. In the process, certain browser information, including your IP address, is transmitted to the provider.

Data may also be transmitted to: Google LLC, USA

The processing of personal data in the course of establishing a connection with the provider of the fonts is only carried out if you have given us your express consent to do so in accordance with Art. 6 (1) a DSGVO. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website. If your browser does not support web fonts, a default font will be used by your computer.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10.7 Google Customer Reviews (formerly Google Certified Merchant Program)

We work with Google as part of the "Google Customer Reviews" program. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This program gives us the opportunity to collect customer reviews from users of our website. In doing so, you will be asked after a purchase on our website whether you would like to participate in an e-mail survey by Google.

If you give your consent in accordance with Art. 6 (1) lit. a DSGVO, we will transmit your email address to Google. You will receive an email from Google Customer Reviews asking you to rate the purchase experience on our website. The rating you provide will then be aggregated with our other ratings and displayed in our Google Customer Reviews logo and in our Merchant Center dashboard. In addition, your review will be used for Google Seller Reviews. As part of the use of Google Customer Reviews, there may also be a transmission of personal data to the servers of Google LLC. in the USA.

You may withdraw your consent at any time by sending a message to the data controller or to Google.

For data transfers to the USA, the Provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

11) Tools and other

11.1 Cookie Consent Tool

This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users when they access the website in the form of an interactive user interface, on which consent for certain cookies and/or cookie-based applications can be given by ticking a box. By using the tool, all cookies/services requiring consent are only loaded if the respective user gives the corresponding consent by ticking the box. This ensures that such cookies are only set on the user's end device if consent has been granted.

The tool sets technically necessary cookies to save your cookie preferences. Personal user data is not processed in this process.

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 (1) f DSGVO on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.

Further legal basis for the processing is Art. 6 para. 1 lit. c DSGVO. As the responsible party, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user consent.

Where necessary, we have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

You can find more information about the operator and the setting options of the cookie consent tool directly in the corresponding user interface on our website.

11.2 Wordfence

For security purposes, this website uses the service of the following provider: Defiant Inc, 800 5th Ave Ste 4100, Seattle, WA 98104, USA.

The provider protects the website and the associated IT infrastructure against unauthorized third-party access, cyber attacks and viruses and malware. The provider collects the IP addresses of users and, if necessary, other data about their behavior on our website (in particular URLs called up and header information) in order to detect and prevent illegitimate page accesses and threats. In the process, the captured IP address is compared with a list of known attackers. If the captured IP address is identified as a security risk, the provider can automatically block it from accessing the site. The information collected in this way is transferred to a server of the provider and stored there.

The described data processing is carried out pursuant to Art. 6 (1) lit. f DSGVO on the basis of our legitimate interests in protecting the website from harmful cyber attacks and in maintaining structural and data integrity and security.

If visitors to the website have login rights, the provider also sets cookies (= small text files) on the end device used by the visitor. With the help of the cookies, certain location and device information can be read, which enables an assessment of whether the login-authorized access originates from a legitimate person. At the same time, access rights can be evaluated via the cookies and released via a site-internal firewall according to the authorization level. Finally, the cookies are used to register irregular access by site administrators from new devices or new locations and to notify other administrators about this.
These cookies are only set if a user has login rights. The provider does not set cookies for site visitors without login authorization.
If personal data is processed via the cookies, the processing is carried out in accordance with Art. 6 para.1 lit f. DSGVO on the basis of our legitimate interest in preventing illegitimate access to the site administration and defense against unauthorized administrator access.

We have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For the transfer of data to the USA, the provider invokes standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.

12) Rights of the data subject

12.1 The applicable data protection law grants you the following data subject rights (rights of information and intervention) vis-à-vis the controller with regard to the processing of your personal data, whereby reference is made to the stated legal basis for the respective exercise prerequisites:

  • Right to information according to Art. 15 DSGVO;
  • Right to rectification pursuant to Art. 16 DSGVO;
  • Right to erasure according to Art. 17 DSGVO;
  • Right to restriction of processing pursuant to Art. 18 DSGVO;
  • Right to information pursuant to Art. 19 GDPR;
  • Right to data portability according to Art. 20 DSGVO;
  • Right to revoke consent given in accordance with Art. 7 (3) DSGVO;
  • Right to lodge a complaint pursuant to Article 77 of the GDPR.

12.2 RIGHT OF OBJECTION

IF WE PROCESS YOUR PERSONAL DATA IN THE CONTEXT OF A BALANCING OF INTERESTS ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE AT ANY TIME ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO CONTINUE PROCESSING IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING IS FOR THE PURPOSE OF ASSERTING, EXERCISING OR DEFENDING LEGAL CLAIMS.

IF WE PROCESS YOUR PERSONAL DATA FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH MARKETING. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

13) Duration of the storage of personal data

The duration of the storage of personal data is determined on the basis of the respective legal basis, the purpose of processing and - if relevant - additionally on the basis of the respective statutory retention period (e.g. retention periods under commercial and tax law).

When processing personal data on the basis of explicit consent pursuant to Art. 6 (1) a DSGVO, the data concerned will be stored until you revoke your consent.

If there are legal retention periods for data that is processed within the scope of legal business or similar obligations on the basis of Art. 6 Para. 1 lit. b DSGVO, this data will be routinely deleted after the retention periods have expired, provided that it is no longer required for the fulfillment of the contract or the initiation of the contract and/or there is no legitimate interest on our part to continue storing it.

When processing personal data on the basis of Art. 6(1)(f) DSGVO, this data will be stored until you exercise your right to object pursuant to Art. 21(1) DSGVO, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

When processing personal data for the purpose of direct marketing based on Art. 6 (1) lit. f DSGVO, this data will be stored until you exercise your right to object according to Art. 21 (2) DSGVO.

Unless otherwise stated in the other information in this statement about specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.