Skip to main content Skip to search Skip to main navigation
Shipping from €7.90
Delivery within 1-3 working days
Break-proof shipping

Data Protection

1) Introduction and contact details of the responsible party

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data is any data that can be used to personally identify you.

1.2 The data controller for this website within the meaning of the General Data Protection Regulation (GDPR) is Bierothek Marketplace GmbH, An der Spinnerei 3, 96047 Bamberg, Germany, Tel.: 0800243768435, E-mail: info@bierothek.de . The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

2) Data collection when visiting our website

2.1 When you use our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the website server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

- Our visited website

- Date and time of access

- Amount of data sent in bytes

- Source/referrer from which you accessed this page

- Browser used

- Operating system used

- IP address used (possibly in anonymized form)

The processing is carried out in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be disclosed or used for any other purpose. However, we reserve the right to subsequently review the server log files should there be concrete indications of unlawful use.

2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the data controller). You can recognize an encrypted connection by the " https://" prefix and the padlock symbol in your browser's address bar.

3) Cookies

To make your visit to our website more enjoyable and to enable the use of certain features, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device for a longer period and allow us to save your website settings (so-called "persistent cookies"). In the latter case, you can find information about the storage duration in your web browser's cookie settings.

If any of the cookies we use process personal data, this processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the case of consent given, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the website visit.

You can configure your browser to notify you when cookies are set and allow you to decide whether to accept them individually, or to block cookies in certain cases or entirely.

Please note that if you do not accept cookies, the functionality of our website may be limited.

4) Making contact

When you contact us (e.g. via contact form or email), personal data is processed – exclusively for the purpose of processing and responding to your request and only to the extent necessary.

The legal basis for processing this data is our legitimate interest in responding to your inquiry pursuant to Article 6(1)(f) GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Article 6(1)(b) GDPR. Your data will be deleted when it is clear from the circumstances that the matter has been resolved and provided that no statutory retention obligations apply.

5) Comment function

When you use the comment function on this website, your comment, the date and time it was posted, and your chosen username will be stored and published on this website. Your IP address will also be logged and stored. This IP address is stored for security reasons and in case you, as the person posting the comment, infringes the rights of third parties or posts illegal content. We need your email address to contact you if a third party objects to your published content as being unlawful.

The legal basis for storing your data is Art. 6 para. 1 lit. b and f GDPR. We reserve the right to delete comments if they are objected to as unlawful by third parties.

6) Data processing when opening a customer account

In accordance with Article 6(1)(b) GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. You can find out which data is required for account opening in the input fields of the corresponding form on our website.

You can delete your customer account at any time by sending a message to the above address of the data controller. After your customer account is deleted, your data will be deleted provided that all contracts concluded through it have been fully processed, no statutory retention periods apply, and we have no legitimate interest in continuing to store it.

7) Use of customer data for direct marketing

7.1 Registration for our email newsletter

When you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required to send you the newsletter is your email address. Providing any further information is voluntary and is used to personalize our communications with you. We use the double opt-in procedure for newsletter distribution, which ensures that you only receive newsletters after you have explicitly confirmed your consent to receive them by clicking a verification link sent to the email address you provided.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Article 6 Paragraph 1 Letter a of the GDPR. We store your IP address, which is registered by your Internet Service Provider (ISP), as well as the date and time of registration, in order to be able to trace any potential misuse of your email address at a later date. The data we collect when you subscribe to the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a message to the data controller named above. After unsubscribing, your email address will be immediately deleted from our newsletter mailing list, unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes permitted by law, which we will inform you about in this privacy policy.

7.2 Product availability notification via email

For items that are temporarily unavailable, you can sign up to receive email notifications when the item you selected is back in stock. We will then send you a one-time email notification informing you when it becomes available. The only required information for receiving this notification is your email address. Providing any other information is voluntary and may be used to personalize our communications with you. We use a double opt-in process for sending these emails. This ensures that you will only receive a notification after you have explicitly confirmed your consent by clicking a verification link sent to the email address you provided.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Article 6 Paragraph 1 Letter a of the GDPR. We store your IP address, registered by your Internet Service Provider (ISP), as well as the date and time of registration, in order to be able to trace any potential misuse of your email address at a later date. The data we collect when you register for our email notification service regarding product availability is used strictly for this purpose.

You can unsubscribe from availability notifications at any time by sending a message to the responsible party mentioned above. After unsubscribing, your email address will be immediately deleted from our mailing list, unless you have expressly consented to further use of your data or we reserve the right to use your data beyond this scope, which is permitted by law and about which we inform you in this statement.

7.3 Advertising by postal mail

Based on our legitimate interest in personalized direct marketing, we reserve the right to store your first and last name, your postal address and – insofar as we have received this additional information from you within the framework of the contractual relationship – your title, academic degree, year of birth and your professional, industry or business designation in accordance with Art. 6 para. 1 lit. f GDPR and to use it for sending you interesting offers and information about our products by post.

You can object to the storage and use of your data for this purpose at any time.

8) Data processing for order processing

8.1 Insofar as necessary for the processing of the contract for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR.

If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details you provided when placing your order (name, address, email address) in order to personally inform you about upcoming updates within the legally prescribed period, in accordance with our legal information obligations pursuant to Art. 6 para. 1 lit. c GDPR, via a suitable communication channel (e.g., by post or email). Your contact details will be used strictly for the purpose of notifying you about updates we owe you and will only be processed by us to the extent necessary for the respective information.

To process your order, we also work with the following service provider(s), who support us in whole or in part in fulfilling concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

8.2 Paqato

We use the following provider for order processing: PAQATO GmbH, Johann-Krane-Weg 6, 48149 Münster, Germany

Your name, address, and any other personal data will be forwarded to the provider in accordance with Article 6 Paragraph 1 Letter b of the GDPR for the purpose of processing your online order. Your data will only be shared to the extent that this is actually necessary for processing the order. The provider is also used for accounting purposes. Specifically, the provider processes incoming and outgoing invoices, as well as, where applicable, our company's bank transactions, in order to automatically record invoices, match them to transactions, and generate the financial accounting records in a semi-automated process.

If personal data is processed in this context, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in an efficient organization and documentation of our business processes.

8.3 Transfer of personal data to shipping service providers

- DHL

We use the following provider as our transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany

We will forward your email address and/or telephone number to the supplier before delivery of the goods in accordance with Article 6 Paragraph 1 Letter a of the GDPR for the purpose of coordinating a delivery date or announcing the delivery, provided you have given your express consent during the ordering process. Otherwise, for the purpose of delivery in accordance with Article 6 Paragraph 1 Letter b of the GDPR, we will only forward the recipient's name and delivery address to the supplier. This data is only shared to the extent necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the supplier or delivery notification is not possible.

Consent can be withdrawn at any time with effect for the future by contacting the controller named above or the provider.

8.4 Use of payment service providers (payment services)

- Klarna

This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden

When you select a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number), as well as information about the contents of your order, will be transmitted to the provider in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider makes an advance payment (such as invoice, installment purchase or direct debit), you will also be asked to provide certain personal data during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, data on an alternative payment method).

To protect our legitimate interest in assessing our customers' creditworthiness, we forward this data to the provider for the purpose of a credit check in accordance with Article 6(1)(f) GDPR. Based on the personal data you provide, as well as other data (such as shopping cart contents, invoice amount, order history, and payment history), the provider checks whether your selected payment method can be granted with regard to payment and/or default risks.

In addition to internal provider criteria pursuant to Art. 6 para. 1 lit. f GDPR, identity and creditworthiness information from the following credit agencies may also be included in the decision-making process for the application review:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is among the factors, but not the only factor, used in calculating the score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for processing payments in accordance with the contract.

- Mollie

This website offers one or more online payment methods from the following provider: Mollie BV, Keizersgracht 313, 1016 EE Amsterdam, Netherlands

When you select a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number), as well as information about the contents of your order, will be transmitted to the provider in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

- Paypal

This website offers one or more online payment methods from the following provider: PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg

When you select a payment method from the provider that requires you to pay in advance, your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the contents of your order will be transmitted to the provider in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

When selecting a payment method where we make advance payments, you will also be asked to provide certain personal data during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, details of an alternative payment method).

In order to protect our legitimate interest in assessing your creditworthiness in such cases, we forward this data to the provider for the purpose of a credit check in accordance with Article 6(1)(f) GDPR. Based on the personal data you provide, as well as other data (such as shopping cart contents, invoice amount, order history, and payment history), the provider checks whether the payment option you have selected can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is among the factors, but not the only factor, used in calculating the score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for processing payments in accordance with the contract.

- Stripe

This website offers one or more online payment methods from the following provider: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

When you select a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number), as well as information about the contents of your order, will be transmitted to the provider in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

When selecting a payment method where the provider makes an advance payment (such as invoice, installment purchase or direct debit), you will also be asked to provide certain personal data during the ordering process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, data on an alternative payment method).

To protect our legitimate interest in assessing our customers' creditworthiness, we forward this data to the provider for the purpose of a credit check in accordance with Article 6(1)(f) GDPR. Based on the personal data you provide, as well as other data (such as shopping cart contents, invoice amount, order history, and payment history), the provider checks whether your selected payment method can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is among the factors, but not the only factor, used in calculating the score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for processing payments in accordance with the contract.

9) Web analytics services

9.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, Google Analytics sets four cookies when you visit the website. These cookies are small text files stored on your device and collect certain information. This information includes your IP address, which Google, however, shortens by removing the last digits to prevent direct identification of individuals.

The information is transferred to Google servers and processed there. This may also involve transfers to Google LLC, which is based in the USA.

Google uses the collected information on our behalf to evaluate your use of the website, to compile reports on website activity for us, and to provide other services related to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics and shortened will not be merged with other Google data. The data collected as part of the use of Google Analytics 4 is stored for a period of two months and then deleted.

All processing described above, in particular the setting of cookies on the device used, will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.

Without your consent, Google Analytics 4 will not be used during your visit to our website. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service using the "Cookie Consent Tool" provided on the website.

We have entered into a data processing agreement with Google that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information regarding Google Analytics 4 can be found at https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites

Demographic characteristics

Google Analytics 4 uses the special feature "demographic characteristics" to generate statistics that provide information about the age, gender, and interests of website visitors. This is achieved by analyzing advertising and information from third-party providers. This allows for the identification of target groups for marketing activities. However, the collected data cannot be linked to any specific individual and is deleted after a storage period of two months.

Google Signals

As an extension to Google Analytics 4, this website may use Google Signals to generate cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google may, subject to your consent to the use of Google Analytics pursuant to Art. 6 para. 1 lit. a GDPR, analyze your usage behavior across devices and create database models, including those related to cross-device conversions. We do not receive any personally identifiable information from Google, only statistics. If you wish to stop cross-device analysis, you can deactivate the "Personalized advertising" feature in your Google account settings. To do so, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=de Further information about Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de

UserIDs

As an extension to Google Analytics 4, the "UserIDs" function may be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Art. 6 para. 1 lit. a GDPR, have created an account on this website, and log in with this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

9.2 Matomo

This website uses a web analytics service provided by: InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand, (“Matomo”)

To protect website visitors, Matomo uses a so-called "config_id" to enable various analyses of website usage within a short timeframe of up to 24 hours. The website's "config_id" is a randomly generated, time-limited hash of a limited set of the visitor's settings and attributes. The config_id, or config hash, is a string calculated for each visitor based on their operating system, browser, browser plugins, IP address, and browser language. Matomo does not use device fingerprinting and uses an anonymized IP address of the website visitor to generate the "config_id."

If the information processed in this way includes personal user data, the processing is carried out in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes. To object to the processing of your visitor data in the future, we provide you with a separate opt-out option on our website.

If data collected using Matomo technology (including your pseudonymized IP address) is transferred to Matomo servers in New Zealand and processed for usage analysis purposes, we inform you that the European Commission has issued an adequacy decision for New Zealand, which attests to compliance with European data protection standards for international data transfers.

If data is also transferred to the provider's servers and the web analytics service is not installed locally on our server, we have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

10) Retargeting/remarketing and conversion tracking

10.1 Meta Pixel with enhanced data matching

Within our online service, we use the "Meta Pixel" service from the following provider in extended data matching mode: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Meta")

When a user clicks on one of our ads on Facebook or Instagram, the URL of our linked page is extended with a parameter using "Meta Pixel." This URL parameter is then entered into the user's browser after redirection via a cookie set by our linked page itself. Furthermore, this cookie collects specific customer data, such as the email address, which we collect on our website linked to the Facebook or Instagram ad during processes like purchases, account logins, or registrations (extended matching). The cookie is then read and enables the transmission of the data, including the specific customer data, to Meta.

We use "Meta Pixel" with advanced matching to make our advertisements (so-called "Ads") on Facebook and/or Instagram more effective and to ensure that they match the interests of users or have certain characteristics (e.g. interests in certain topics or products, which are determined based on the websites visited) that we transmit to Meta (so-called "Custom Audiences").

Furthermore, we analyze the effectiveness of our advertisements by tracking whether users were redirected to our website after clicking on an ad (conversion). Compared to the standard "Meta Pixel" feature, the enhanced matching function helps us better measure the effectiveness of our advertising campaigns by capturing more attributed conversions.

All transmitted data is stored and processed by Meta, allowing it to be associated with the respective user profile and enabling Meta to use the data for its own advertising purposes in accordance with Meta's data policy ( https://www.facebook.com/about/privacy/ ). This data may allow Meta and its partners to display ads on and off Facebook.

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "cookie consent tool" provided on the website.

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

The information generated by Meta is usually transferred to and stored on a Meta server; in this context, data may also be transferred to servers of Meta Platforms Inc. in the USA.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

10.2 Google Ads Remarketing

This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

For this purpose, Google places a cookie in your browser, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you visit. Further data processing only takes place if you have consented to Google linking your internet and app browsing history to your Google account and using information from your Google account to personalize ads you see on the web. If you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define target audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked by Google with Google Analytics data to create target audiences. When using Google Ads Remarketing, personal data may also be transferred to the servers of Google LLC in the USA.

All processing described above, in particular the setting of cookies for reading information on your device, will only be carried out if you have given us your explicit consent in accordance with Article 6(1)(a) GDPR. Without this consent, retargeting technology will not be used during your visit to our website.

You can withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, please deactivate this service in the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

10.3 Google Ads Conversion Tracking

This website uses the online advertising program "Google Ads" and, within the framework of Google Ads, the conversion tracking service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use Google Ads to draw attention to our attractive offers on external websites using advertising materials (so-called Google AdWords). Based on the data from the advertising campaigns, we can determine the success of individual advertising measures. Our aim is to show you advertising that is relevant to you, to make our website more interesting for you, and to ensure a fair calculation of the advertising costs incurred.

The conversion tracking cookie is set when a user clicks on a Google ad. Cookies are small text files that are stored on your device. These cookies typically expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Therefore, cookies cannot be tracked across the websites of different Google Ads customers. The information obtained using the conversion cookie is used to generate conversion statistics for Google Ads customers who have opted for conversion tracking. These customers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can personally identify users. When using Google Ads, personal data may also be transferred to the servers of Google LLC in the USA.

Details about the processing triggered by Google Ads Conversion Tracking and how Google handles website data can be found here: https://policies.google.com/technologies/partner-sites

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "cookie consent tool" provided on the website.

You can also permanently object to the setting of cookies by Google Ads conversion tracking by downloading and installing the browser plug-in from Google available at the following link:

https://www.google.com/settings/ads/plugin?hl=de

Please note that certain features of this website may not be available or may be limited if you have disabled the use of cookies.

Google's privacy policy can be viewed here: https://www.google.de/policies/privacy/

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

11) Page functionalities

11.1 YouTube

This website uses plugins to display and play videos from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

Data may also be transferred to: Google LLC, USA

When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to the provider's servers in order to load the plugin. In doing so, certain information, including your IP address, is transmitted to the provider.

When embedded videos are played via the plugin, the provider also uses cookies to collect information about user behavior, create playback statistics and prevent abusive behavior.

If you are logged into a user account with the provider during your visit to the site, your data will be directly associated with your account when you click on a video. If you do not want this association with your account, you must log out before clicking the play button.

All of the aforementioned processing activities, in particular the setting of cookies for reading information on the device used, will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

11.2 Trusted Shops Trustbadge

Our website uses graphic elements from the following provider to display external customer reviews and/or an externally awarded quality seal: Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne, Germany

When you access a page on our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers in order to load the elements correctly. In doing so, certain browser information, including your IP address, is transmitted to the provider.

If personal data is processed in this context, this is done in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the optimal marketing of our offer and the appealing design of our website.

In the case of an online order with us, further processing may take place.

Depending on your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, your order information (order amount, order number, possibly purchased product) and your email address will be transmitted in encrypted form to the provider via the Trustbadge after completion of an order in order to verify an existing registration for the provider's services (in particular the "buyer protection") and, if necessary, to enable a new registration.

In the event of an existing registration or in the event of a new registration with the provider for its services (in particular buyer protection), your order information (order amount, order number, purchased product) and your email address will be transmitted to the provider and further processed by the provider in accordance with the contractual agreement pursuant to Art. 6 para. 1 lit. b GDPR in order to grant the services (in particular buyer protection).

We are jointly responsible with the provider for the processing described above in accordance with Article 26 GDPR. The joint controllership agreement can be viewed here: https://help.etrusted.com/hc/de/articles/4402587369105-Vertrag-%C3%BCber-die-gemeinsame-Verantwortlichkeit-nach-DSGVO

11.3 Google Maps

This website uses an online map service provided by the following provider: Google Maps (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

Google Maps is a web service for displaying interactive maps to visually represent geographical information. Using this service will show you our location and make it easier for you to find us.

When you access pages on our website that include a Google Maps map, information about your use of our website (such as your IP address) is transmitted to and stored on Google servers. This may also involve transmission to the servers of Google LLC in the USA. This occurs regardless of whether you have a Google account and are logged in. If you are logged into Google, your data will be directly associated with your account. If you do not want this association with your Google profile, you must log out before activating the button. Google stores and analyzes your data (even for users who are not logged in) as usage profiles.

The collection, storage, and analysis of your data are carried out in accordance with Article 6(1)(f) of the GDPR, based on Google's legitimate interest in displaying personalized advertising, conducting market research, and/or tailoring Google websites to user needs. You have the right to object to the creation of these user profiles, and to exercise this right, you must contact Google. If you do not agree to the future transfer of your data to Google in connection with the use of Google Maps, you can also completely deactivate the Google Maps web service by disabling JavaScript in your browser. Google Maps, and therefore the map display on this website, will then be unavailable.

Where legally required, we have obtained your consent for the processing of your data as described above, in accordance with Article 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, please follow the instructions for submitting an objection as described above.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

11.4 OpenStreetMap

This website uses an online map service provided by: OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, UK

The online map service is a tool for displaying interactive maps to visually represent geographical information. Using this service will show you our location and facilitate geolocation.

When you access the subpages where the provider's map is integrated, information about your use of our website (such as your IP address) is transmitted to the provider's servers and stored there.

Your personal data is processed in accordance with Article 6(1)(f) GDPR based on our legitimate interest in designing our website to meet user needs. If you do not agree to the future transfer of your data to the provider, you can completely deactivate the provider's online map service by disabling JavaScript in your browser. The online map service on this website will then no longer be available.

Where legally required, we have obtained your consent for the processing of your data as described above, in accordance with Article 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, please follow the instructions for submitting an objection as described above.

When data is transferred to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

11.5 Google Translate

This website uses the "Google Translate" service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") via an API integration. To automatically display the translation in your chosen language, your browser connects to Google's servers. Google uses "cookies" for this purpose; these are text files placed on your computer to help the website analyze how users use the site. The information generated by the cookie about your use of the website (including your truncated IP address) is generally transmitted to and stored by Google on servers in the United States.

If personal data is processed, this is done in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in barrier-free and universal accessibility of our website.

Where legally required, we have obtained your consent for the processing of your data as described above, in accordance with Article 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, deactivate this service in the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.

11.6 Applications for job postings via email

On our website, we list currently vacant positions in a separate section, for which interested parties can apply by email to the provided contact address.

Applicants must provide all personal data necessary for a thorough assessment, including general information such as name, address, and contact details, as well as performance-related evidence and, where applicable, health-related information. Further details regarding the application process can be found in the job posting.

Upon receipt of your application via email, the data will be stored and evaluated solely for the purpose of processing your application. For any follow-up questions, we will use either the applicant's email address or telephone number. This processing is based on Article 6 Paragraph 1 Letter b GDPR (or Section 26 Paragraph 1 BDSG), according to which the application process is considered the initiation of an employment contract.

Insofar as special categories of personal data within the meaning of Art. 9 para. 1 GDPR (e.g. health data such as information about severe disability) are requested from applicants during the application process, the processing is carried out in accordance with Art. 9 para. 2 lit. b GDPR so that we can exercise the rights arising from employment law and the law of social security and social protection and comply with our obligations in this regard.

Alternatively or cumulatively, the processing of special categories of data may also be based on Article 9(1)(h) GDPR if it is carried out for the purposes of preventive or occupational medicine, for the assessment of the applicant's fitness for work, for medical diagnosis, for the provision of health or social care or treatment or for the management of health or social care systems and services.

If an applicant is not selected or withdraws their application prematurely, their submitted data and all electronic correspondence, including the application email, will be deleted no later than six months after notification. This period is based on our legitimate interest in being able to answer any follow-up questions regarding the application and, if necessary, to comply with our obligations to provide evidence under the regulations on equal treatment of applicants.

In the event of a successful application, the data provided will be processed on the basis of Art. 6 para. 1 lit. b GDPR (in the case of processing in Germany in conjunction with § 26 para. 1 BDSG) for the purpose of carrying out the employment relationship.

12) Tools and other items

12.1 - DATEV

For our accounting, we use the cloud-based accounting software service of the following provider: DATEV eG, Paumgartnerstr. 6-14, 90429 Nuremberg, Germany

The provider processes incoming and outgoing invoices as well as, if applicable, our company's bank transactions in order to automatically record invoices, match them to transactions and create the financial accounting from this in a semi-automated process.

If personal data is processed in this context, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in an efficient organization and documentation of our business processes.

12.2 Cookie Consent Tool

This website uses a "cookie consent tool" to obtain valid user consent for cookies and cookie-based applications that require consent. The cookie consent tool is displayed to users upon visiting the site as an interactive interface, where consent for specific cookies and/or cookie-based applications can be granted by ticking boxes. By using this tool, all cookies/services requiring consent are only loaded if the respective user grants the corresponding consent by ticking the boxes. This ensures that such cookies are only placed on the user's device if consent has been given.

This tool uses technically necessary cookies to store your cookie preferences. No personal user data is processed in this process.

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in a legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.

A further legal basis for processing is Article 6(1)(c) GDPR. As data controllers, we are subject to the legal obligation to make the use of cookies that are not technically necessary dependent on the respective user's consent.

Where necessary, we have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

Further information about the operator and the settings options of the cookie consent tool can be found directly in the corresponding user interface on our website.

13) Rights of the data subject

13.1 The applicable data protection law grants you the following rights as a data subject (rights of access and intervention) vis-à-vis the controller with regard to the processing of your personal data, whereby reference is made to the legal basis stated for the respective conditions for exercising these rights:

- Right of access pursuant to Art. 15 GDPR;

- Right to rectification pursuant to Art. 16 GDPR;

- Right to erasure pursuant to Art. 17 GDPR;

- Right to restriction of processing pursuant to Art. 18 GDPR;

- Right to information pursuant to Art. 19 GDPR;

- Right to data portability pursuant to Art. 20 GDPR;

- Right to withdraw consent pursuant to Art. 7 para. 3 GDPR;

- Right to lodge a complaint pursuant to Art. 77 GDPR.

13.2 Right of objection

If we process your personal data based on our overriding legitimate interest as part of a balancing of interests, you have the right to object to this processing at any time, on grounds relating to your particular situation, with effect for the future.

If you exercise your right to object, we will cease processing the data in question. However, further processing remains possible if we can demonstrate compelling legitimate grounds for the processing which override your interests, fundamental rights and freedoms, or if the processing serves the purpose of establishing, exercising or defending legal claims.

If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. You can exercise your right to object as described above.

If you exercise your right to object, we will cease processing the data in question for direct marketing purposes.

14) Duration of storage of personal data

The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing and – if applicable – additionally by the respective statutory retention period (e.g. commercial and tax law retention periods).

When processing personal data on the basis of explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, the data concerned will be stored until you withdraw your consent.

If statutory retention periods exist for data processed in the context of contractual or quasi-contractual obligations on the basis of Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the expiry of the retention periods, provided that it is no longer required for the performance of a contract or for initiating a contract and/or we no longer have a legitimate interest in its continued storage.

When processing personal data on the basis of Article 6(1)(f) GDPR, this data will be stored until you exercise your right to object pursuant to Article 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of establishing, exercising or defending legal claims.

When processing personal data for direct marketing purposes on the basis of Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object pursuant to Art. 21 para. 2 GDPR.

Unless otherwise stated in the other information in this declaration regarding specific processing situations, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.