Privacy Policy
1) Introduction and Contact Details of the Responsible Party
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data is any data that can be used to identify you personally.
1.2 The responsible party for data processing on this website in accordance with the General Data Protection Regulation (GDPR) is GUA-VITA, a brand of Oh Nu! Premium Nutrition GmbH i.G, Dorotheenstrasse 48, 22301 Hamburg, Germany, Tel.: +49 40 650 555 31, Email: info@gua-vita.com. Der the party responsible for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.3 The controller has appointed a data protection officer, who can be reached as follows: "Herting Oberbeck, Datenschutz GmbH, Hallerstr. 76, 20146, Hamburg, datenschutzbeauftragter@godirect.de, www.datenschutzkanzlei.de"
2) Data collection when visiting our website
2.1 When using our website for informational purposes only, that is, if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to the server (so-called "server log files").When you access our website, we collect the following data that is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the time of access
- Amount of data sent in bytes
- Source/reference from which you accessed the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. There will be no transfer or other use of the data. However, we reserve the right to review the server log files retrospectively should there be concrete indications of unlawful use.
2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (z.B. orders or inquiries to the responsible party). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser's address bar.
3) Hosting & Content Delivery Network
Shopify
For hosting our website and displaying the page content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")
Data is also transmitted to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada
All data collected on our website is processed on the provider's servers.We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
In the case of data transfer to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
4) Cookies
To make your visit to our website attractive and to enable the use of certain functions, we use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device for a longer period and allow the storage of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of the cookie settings of your web browser.
If individual cookies used by us also process personal data, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the case of granted consent, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the site visit.
You can configure your browser to be informed about the setting of cookies and to decide individually on their acceptance or to exclude the acceptance of cookies for specific cases or in general.
Please note that if cookies are not accepted, the functionality of our website may be limited.
5) Contact
5.1 Judge.me
For review reminders, we use the services of the following provider: Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom
Exclusively based on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, we will transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder via email.
You can revoke your consent at any time with effect for the future to us or the provider.
We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
When transmitting data to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
5.2 In the context of contacting us (z.B. via contact form or email), personal data will be processed – solely for the purpose of processing and responding to your request and only to the extent necessary for that purpose.
The legal basis for the processing of this data is our legitimate interest in responding to your request in accordance with Art. 6 para. 1 lit. f GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no legal retention obligations to the contrary.
6) Data processing when opening a customer account
According to Art. 6 para. 1 lit.In accordance with the GDPR, personal data will continue to be collected and processed to the necessary extent when you provide us with this information upon opening a customer account. You can find out which data is required for account opening from the input mask of the corresponding form on our website.
Deleting your customer account is possible at any time and can be done by sending a message to the o.g. address of the responsible party. After the deletion of your customer account, your data will be deleted, provided that all contracts concluded in this regard have been fully settled, no legal retention periods are opposed, and we have no legitimate interest in further storage.
7) Use of customer data for direct marketing
7.1 Registration for our email newsletter
If you register for our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. Providing additional data is voluntary and will be used to address you personally. For the newsletter dispatch, we use the so-called double opt-in procedure, which ensures that you will only receive the newsletter after you have explicitly confirmed your consent to receive the newsletter by clicking on a verification link sent to the provided email address.
By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6 para. 1 lit. a GDPR.We store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration in order to trace any potential misuse of your email address at a later time. The data we collect during the newsletter registration is used strictly for its intended purpose.
You can unsubscribe from the newsletter at any time via the designated link in the newsletter or by sending a corresponding message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve a further use of data that is legally permitted and of which we inform you in this statement.
7.2 Klaviyo
The dispatch of our email newsletters and other promotional email communications is carried out by this provider: Klaviyo, Inc., 125 Summer St., Ste 600, Boston, MA 02110, USA
Based on our legitimate interest in effective and user-friendly email marketing, we share the data you provided during registration in accordance with Art. 6 para. 1 lit. f GDPR with this provider, so that they can handle the email dispatch on our behalf.
Subject to your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the provider also conducts a statistical success evaluation of email campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the content of the newsletter. Device information is also collected (z.B. The time of the call, IP address, browser type, and operating system) are collected and evaluated, but not merged with other data sets.
You can revoke your consent to mail tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider that protects the data of our site visitors and prohibits disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.
7.3 Shopping Cart Reminders via Email
If you abandon your shopping with us before completing your order, you have the option to receive a one-time email reminder of the contents of your virtual shopping cart.
The only mandatory information for sending this reminder is your email address. Providing additional data is voluntary and may be used to address you personally. For sending emails, we use the so-called Double Opt-in procedure, which ensures that you will only receive a notification once you have explicitly confirmed your consent by clicking on a verification link sent to the provided email address.
By activating the confirmation link, you grant us your consent for the use of your personal data in accordance with Art. 6 para. 1 lit. a GDPR for the purpose of sending a shopping cart reminder.Here we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration to trace any potential misuse of your email address at a later time. The data we collect during your registration for our email notification service will be used strictly for the intended purpose.
You can unsubscribe from the cart reminders at any time by sending a corresponding message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly deleted from our designated distribution list, unless you have expressly consented to further use of your data or we reserve a further use of data that is legally permitted and of which we inform you in this statement.
8) Data processing for order processing
8.1 As far as necessary for the processing of the contract for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR.
If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we will process the contact details you provided during the order to inform you personally in accordance with our legal information obligations under Art. 6 para. 1 lit. c GDPR. Your contact details will be used strictly for the purpose of communicating updates owed by us and will only be processed by us to the extent necessary for the respective information.
To process your order, we also work with the service provider(s) listed below, who assist us in whole or in part with the execution of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.
8.2 Use of Payment Service Providers (Payment Services)
- Apple Pay
If you choose the payment method "Apple Pay" from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, the payment processing will be carried out through the "Apple Pay" function of your device operating on iOS, watchOS, or macOS by charging a payment card registered with "Apple Pay." Apple Pay uses security features that are integrated into the hardware and software of your device to protect your transactions.To authorize a payment, you must enter a code that you have previously set, as well as verify using the "Face ID" or "Touch ID" function of your device.
For the purpose of processing the payment, the information you provided during the ordering process, along with the information about your order, is transmitted in encrypted form to Apple. Apple then re-encrypts this data with a developer-specific key before transmitting the data to the payment service provider of the payment card stored in Apple Pay for processing the payment. The encryption ensures that only the website through which the purchase was made can access the payment data. After the payment has been made, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the success of the payment.
If personal data is processed in the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Apple stores anonymized transaction data, including the approximate purchase amount, the approximate date and time, as well as an indication of whether the transaction was successfully completed. Anonymization completely excludes any personal reference. Apple uses the anonymized data to improve "Apple Pay" and other Apple products and services.
If you use Apple Pay on the iPhone or Apple Watch to complete a purchase made through Safari on the Mac, the Mac and the authorization device communicate over an encrypted channel on Apple servers.Apple does not process or store any of this information in a format that can identify you. You can disable the option to use Apple Pay on your Mac in the settings of your iPhone. Go to "Wallet & Apple Pay" and disable "Allow payments on Mac".
For more information on privacy regarding Apple Pay, please visit the following website: https://support.apple.com/en-gb/HT203027
- Google Pay
If you choose the payment method "Google Pay" from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), the payment processing will be done through the "Google Pay" application on your mobile device, which must be operated with at least Android 4.4 ("KitKat") and have an NFC function, by charging a payment card stored in Google Pay or a verified payment system there (z.B. PayPal). To authorize a payment via Google Pay of more than €25, it is necessary to unlock your mobile device using the respective verification method set up (such as facial recognition, password, fingerprint, or pattern).
For the purpose of processing payments, the information you provide during the ordering process, along with the information about your order, will be shared with Google. Google then transmits your payment information stored in Google Pay in the form of a one-time transaction number to the originating website, which verifies that a payment has been made. This transaction number does not contain any information about the actual payment data of your payment methods stored in Google Pay, but is created and transmitted as a uniquely valid numerical token. In all transactions via Google Pay, Google acts solely as an intermediary for processing the payment transaction.The execution of the transaction takes place exclusively between the user and the originating website by charging the payment method stored with Google Pay.
If personal data is processed in the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Google reserves the right to collect, store, and evaluate certain transaction-specific information for each transaction made via Google Pay. This includes the date, time, and amount of the transaction, merchant location and description, a description of the purchased goods or services provided by the merchant, photos you have attached to the transaction, the name and email address of the seller and buyer, respectively.the sender and recipient, the payment method used, your description for the reason for the transaction, as well as any offer associated with the transaction.
According to Google, this processing is carried out exclusively in accordance with Art. 6 para. 1 lit. f GDPR based on the legitimate interest in proper accounting, verification of transaction data, and optimization and maintenance of the Google Pay service.
Google also reserves the right to combine the processed transaction data with other information collected and stored by Google when using additional Google services.
The terms of use for Google Pay can be found here:
https://payments.google.com/payments/apis-secure/u/0/get_legal_document? ldo=0&ldt=googlepaytos&ldl=en
Further information on data protection with Google Pay can be found at the following internet address:
https://payments.google.com/payments/apis-secure/get_legal_document? ldo=0&ldt=privacynotice&ldl=en
- Klarna
This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden
When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be transmitted to them in accordance with Art.6 para. 1 lit. b GDPR is passed on. The transfer of your data takes place in this case exclusively for the purpose of payment processing with the provider and only to the extent that it is necessary for this purpose.
If you choose a payment method where the provider advances the payment (such as invoice or installment purchase or direct debit), you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data for an alternative payment method) during the ordering process.
In order to safeguard our legitimate interest in assessing the creditworthiness of our customers, this data will be forwarded to the provider for the purpose of a credit check in accordance with Art. 6 para. 1 lit. f GDPR. The provider checks based on the personal data you have provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences) whether the payment option you have selected can be granted in terms of payment and/or default risks.
For the decision in the context of the application review, in addition to internal criteria according to Art. 6 para. 1 lit. f GDPR, identity and credit information from the following credit agencies may also be included:
https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies
The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure.The calculation of the score values includes, among other things, but is not limited to, address data.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Paypal
This website offers one or more online payment methods from the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A. , 22-24 Boulevard Royal, L-2449 Luxembourg
If you choose a payment method from the provider where you make an advance payment, your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be transmitted to them in accordance with Art. 6 para. 1 lit.b GDPR transmitted. The transfer of your data in this case occurs exclusively for the purpose of payment processing with the provider and only to the extent that it is necessary for this purpose.
If you choose a payment method where we advance the payment, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data for an alternative payment method) during the ordering process.
In such cases, to uphold our legitimate interest in assessing your creditworthiness, this data will be forwarded to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks based on the personal data you have provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences) whether the payment option you have selected can be granted in terms of payment and/or default risks.
The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but is not limited to, address data.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Paypal Checkout
This website uses PayPal Checkout, an online payment system from PayPal, which consists of PayPal's own payment methods and local payment methods from third parties.
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "Pay Later" via PayPal, we will pass your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A. , 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as "PayPal") as part of the payment processing. The transfer is carried out in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for the payment processing.
PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "Pay Later" via PayPal. For this purpose, your payment data may be processed in accordance with Art. 6 para. 1 lit.f GDPR based on PayPal's legitimate interest in determining your creditworthiness to credit agencies. The result of the credit check regarding the statistical probability of payment default is used by PayPal for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). To the extent that score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but is not limited to, address data. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
If the PayPal payment method "Invoice Purchase" is available and selected, your payment data will initially be transmitted to PayPal to prepare the payment, after which PayPal forwards this data to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin ("Ratepay") for the execution of the payment. The legal basis is Art. 6 para. 1 lit. b GDPR. In this case, RatePay conducts an identity and credit check in its own name to determine creditworthiness according to the principle mentioned above and forwards your payment data to credit agencies based on the legitimate interest in determining creditworthiness in accordance with Art. 6 para. 1 lit. f GDPR. A list of credit agencies that Ratepay can rely on can be found here: https://www.ratepay.com/legal-payment-creditagencies/
When using the payment method of a local third-party provider, your payment data will initially be shared with PayPal in accordance with Art. 6 para. 1 lit. b GDPR for the preparation of the payment. Depending on your selection of an available local payment method, PayPal will then transmit your payment data to the corresponding provider for the execution of the payment in accordance with Art. 6 para. 1 lit. b GDPR:
- Apple Pay (Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
- Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)
- iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
- bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
- blik (Polski Standard Płatności sp. z o.o. , ul.Czerniakowska 87A, 00-718 Warsaw, Poland)
- eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2
1200 Vienna, Austria)
- MyBank (PRETA S.A.S, 40 Rue de Courcelles, F-75008 Paris, France)
- Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)
For further data protection information, please refer to the privacy policy of PayPal: https://www.paypal.com/en/legalhub/paypal/privacy-full
- Shopify Payments
This website offers one or more online payment methods from the following provider: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
When selecting a payment method from the provider where you pay in advance (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be transmitted to them in accordance with Art.6 para. 1 lit. b GDPR is passed on. The transfer of your data takes place in this case exclusively for the purpose of payment processing with the provider and only to the extent that it is necessary for this purpose.
- Instant Transfer
One or more online payment methods from the following provider are available on this website: Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden
If you select a payment method from the provider where you pay in advance (e.g., credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be passed on in accordance with Art. 6 para. 1 lit. b GDPR. The transfer of your data takes place in this case exclusively for the purpose of payment processing with the provider and only to the extent that it is necessary for this purpose.
- Stripe
One or more online payment methods from the following provider are available on this website: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
If you select a payment method from the provider where you make an advance payment (such as credit card payment), your payment data provided during the ordering process (including name, address, bank and card information, currency, and transaction number) as well as information about the content of your order will be shared in accordance with Art. 6 para. 1 lit. b GDPR. The sharing of your data in this case is solely for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.
If you select a payment method where the provider makes an advance payment (such as invoice or installment purchase orIn the case of direct debit, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and if applicable, data for an alternative payment method) during the ordering process.
To protect our legitimate interest in assessing the creditworthiness of our customers, this data will be forwarded to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. The provider checks based on the personal data you provided as well as other data (such as shopping cart, invoice amount, order history, payment experiences) whether the payment option you selected can be granted in terms of payment and/or default risk.
The credit report may contain probability values (so-called score values).As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but not exclusively, address data.
You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
8.3 Electronic cancellation option for ongoing debt relationships with consumers
Consumers who have entered into contracts for chargeable ongoing debt relationships (such as subscription contracts) on this website have the option to cancel these via an electronic button in accordance with the applicable cancellation periods.
The activation of the button leads to a confirmation page, on which the consumer can provide further details regarding the cancellation, clearly identify themselves, and subsequently declare their cancellation electronically.
The collection of personal data and its transmission to us takes place in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for the proper processing of the cancellation. Also based on Art. 6 para. 1 lit. b GDPR, the provided personal data will be used to confirm the receipt of the cancellation declaration and the cancellation date electronically in text form. Another legal basis for processing is Art. 6 para. 1 lit. c GDPR. We are legally obligated to provide an electronic cancellation option for consumer contracts concluded via electronic commerce regarding paid ongoing obligations.
9) Web Analytics Services
9.1 Hotjar
This website uses the web analytics service of the following provider: Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta
Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used such as the IP address and browser information, in order to evaluate it for statistical analyses of user behavior on our website and to create pseudonymized usage profiles. Among other things, this enables the evaluation of movement patterns (so-called heatmaps), which show the duration of page visits as well as interactions with page content (e.g., text inputs, scrolling, clicks, and mouse-overs). Pseudonymization fundamentally excludes direct personal reference. There is no merging with other collected clear data about you.
All the processing described above, especially reading or storing information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
9.2 Microsoft Clarity
This website uses the web analytics service of the following provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399 USA
Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used such as the IP address and browser information, in order to evaluate it for statistical analyses of user behavior on our website and to create pseudonymized usage profiles. Among other things, this enables the evaluation of movement patterns (so-called heatmaps), which show the duration of page visits as well as interactions with page content (e.g., text inputs, scrolling, clicks, and mouse-overs). Pseudonymization fundamentally excludes direct personal reference. A merging with other collected clear data about you does not take place.
All the processing described above, especially reading or storing information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transmissions to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission. safeguards.
10) Page functionalities
10.1 Youtube
This website uses plugins to display and play videos from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
Data may also be transmitted to: Google LLC., USA
When you access a page of our website that contains such a plugin, your browser establishes a direct connection to the provider's servers at the latest at the time of video playback to load the content. Certain information, including your IP address, is transmitted to the provider.
If the playback of embedded videos is initiated via the plugin, the provider also uses cookies to collect information about user behavior, create playback statistics, and prevent abusive behavior.
If you are logged into a user account with the provider during your site visit, your data will be directly associated with your account when you click on a video. If you do not wish for this association with your account, you must log out before pressing the play button.
All of the aforementioned processing, especially the setting of cookies for reading information on the device used, only occurs if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.You can revoke the consent granted at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.
10.2 Apple Single Sign-On
On our website, we provide a Single Sign-On function from the following provider: Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland.
If you have an account with the provider, you can log in with these account details to create a user account or to register on our website.
When visiting this page, a direct connection can be established between your browser and the provider's servers through this login function, even if you do not have an account with the provider or are not logged into one. The provider receives the information that you have visited our page. The information collected in this regard (possibly including your IP address) is transmitted directly from your browser to a server of the provider and stored there. However, the information is not used to personally identify you and is not shared with third parties.
These data processing operations are carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a user-friendly and interactive design of our online presence.
By clicking the registration button, you register with the data of your account with the provider on our website. The provider transmits the general and publicly accessible information stored in your account (user ID, name, address, email address, age, and gender) to us solely based on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
We store and use the data transmitted by the provider to set up a user account with the necessary information (salutation, first name, last name, address data, country, email address, date of birth), provided you have shared this with the provider. Conversely, based on your consent, data (z.B. information about your browsing or purchasing behavior) can be transferred from us to your account with the provider.
The consent granted can be revoked at any time with effect for the future.
10.3 Google Sign-In
On our website, we provide a single sign-on feature from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
In addition to transmitting data to the o.g. provider location, data may also be transmitted to: Google LLC, USA
If you have an account with the provider, you can log in with these account details to create a user account or to register on our website.
When visiting this page, a direct connection may be established between your browser and the provider's servers through this login function, even if you do not have an account with the provider or are not logged into one. The provider thereby receives the information that you have visited our page. The information collected in this regard (if applicableincluding your IP address) are transmitted directly from your browser to a server of the provider and stored there. However, the information is not used to personally identify you and is not shared with third parties.
This data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in a user-friendly and interactive design of our online presence.
If you press the registration button to register with the data of your account with the provider on our website, the provider transmits the general and publicly accessible information stored in your account (user ID, name, address, email address, age, and gender) to us solely based on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
We store and use the data provided by the provider to set up a user account with the necessary information (salutation, first name, last name, address details, country, email address, date of birth), provided you have shared this with the provider. Conversely, based on your consent, data (z.B. information about your browsing or purchasing behavior) can be transferred from us to your account with the provider.
The consent granted can be revoked at any time with effect for the future against us.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.
Further information on Google's data protection can be found here: https://business.safety.google/intl/en/privacy/
10.4 Judge.me
On our website, graphic elements from the following provider are integrated to display external customer reviews and/or an externally awarded quality seal: Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom
When you access a page of our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers to load the elements properly. In this process, certain browser information, including your IP address, is transmitted to the provider.
If personal data is also processed in this context, this is done in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the optimal marketing of our offerings and the appealing design of our online presence.
We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
In the case of data transfer to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
10.5 Google Web Fonts
This page uses web fonts from the following provider for a uniform display of fonts: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
When you access a page, your browser loads the required web fonts into its browser cache to correctly display texts and fonts and establishes a direct connection to the provider's servers. In this process, certain browser information, including your IP address, is transmitted to the provider.
Data may also be transmitted to: Google LLC, USA
The processing of personal data in the course of establishing a connection with the font provider only takes place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.You can revoke your consent at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website. If your browser does not support web fonts, a standard font from your computer will be used.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.
Further information on Google's privacy policy can be found here: https://business.safety.google/intl/en/privacy/
11) Tools and Others
Judge.me
To verify and publish customer reviews, we use the services of the following provider: Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom
If you submit a review on our website, your first and last name, email address, order date and number, as well as name and international references (GTIN/ISDNF) will be collected, transmitted to the provider, and evaluated there to determine the legitimacy of a customer review for a specific order. These processes are carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in ensuring the authenticity of customer reviews by ensuring transaction relevance and preventing review abuse. After the review has been checked and approved, the data will be deleted by the provider.
An appropriate level of data protection is ensured by an adequacy decision of the European Commission when data is transmitted to the provider's location.
12) Rights of the Data Subject
12.1 The applicable data protection law grants you the following rights as a data subject regarding the processing of your personal data (rights to information and intervention), with reference to the respective conditions for exercise based on the cited legal basis:
- Right to information according to Art. 15 GDPR;
- Right to rectification according to Art. 16 GDPR;
- Right to erasure according to Art. 17 GDPR;
- Right to restriction of processing according to Art. 18 GDPR;
- Right to notification according to Art. 19 GDPR;
- Right to data portability according to Art. 20 GDPR;
- Right to withdraw consent given according to Art. 7 para. 3 GDPR;
- Right to lodge a complaint according to Art. 77 GDPR.
12.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR PREVAILING LEGITIMATE INTEREST AS PART OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING PROTECTABLE REASONS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FUNDAMENTAL FREEDOMS, OR IF THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING AT ANY TIME. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE THE PROCESSING OF THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.
13) Duration of storage of personal data
The duration of storage of personal data is determined by the respective legal basis, the purpose of processing, and – if applicable – additionally by the respective statutory retention period (z.B. commercial and tax law retention periods).
When processing personal data based on explicit consent in accordance with Art. 6 para. 1 lit.According to the GDPR, the affected data will be stored until you revoke your consent.
If there are legal retention periods for data processed in the context of contractual or contract-like obligations based on Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the retention periods have expired, provided that it is no longer necessary for contract fulfillment or contract initiation and/or we have no legitimate interest in further storage.
When processing personal data based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para.1 Exercise your rights under the GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
When processing personal data for the purpose of direct marketing based on Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 2 GDPR.
Unless otherwise stated in the additional information of this declaration regarding specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.
