PRIVACY POLICY

1) Introduction and Contact Details of the Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data is all data with which you can be personally identified.

1.2 The controller for data processing on this website in the sense of the General Data Protection Regulation (GDPR) is Steve Pawlowski, ForgeLoqX, c/o MDC Management#5320, Welserstraße 3, 87463 Dietmannsried, Germany, Tel.: Upon request, E-mail: info@forgeloqx.com. The controller for the processing of personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

2) Data Collection When Visiting Our Website

2.1 When using our website for informational purposes only, i.e., if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to the page server (so-called "server log files"). When you access our website, we collect the following data, which are technically necessary for us to display the website to you:

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/reference from which you reached the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. No disclosure or other use of the data takes place. However, we reserve the right to retrospectively check the server log files if there are concrete indications of illegal use.

2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.

3) Hosting & Content Delivery Network

3.1 Shopify

For hosting our website and displaying the page content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

All data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

3.2 Cloudflare

We use a Content Delivery Network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA

This service allows us to deliver large media files such as graphics, page content or scripts faster via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision of the European Commission.

3.3 imgix

We use a Content Delivery Network from the following provider: Zebrafish Labs Inc., 423 Tehama St., San Francisco, CA 94103. USA

This service allows us to deliver large media files such as graphics, page content or scripts faster via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision of the European Commission.

3.4 Shopify

We use a Content Delivery Network from the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")

Data may also be transferred to:

  • Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada
  • Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA

This service allows us to deliver large media files such as graphics, page content or scripts faster via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

For data transfers to the USA, the data recipient has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision of the European Commission.

4) Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device for a longer period and allow storing page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of your web browser's cookie settings.

If personal data is also processed by individual cookies we use, the processing is carried out either in accordance with Art. 6 para. 1 lit. b GDPR for the execution of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the case of a given consent, or in accordance with Art. 6 para. 1 lit. f GDPR for the protection of our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general.

Please note that if cookies are not accepted, the functionality of our website may be limited.

5) Contacting Us

5.1 Shopify Inbox

This website uses the live chat system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

The processing of personal data transmitted via chat is carried out either in accordance with Art. 6 para. 1 lit b GDPR, because it is necessary for the initiation or execution of a contract, or in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in the effective support of our site visitors.
Your data transmitted in this way will be deleted, subject to statutory retention periods, once the matter concerned has been finally clarified.

In addition, for the purpose of creating pseudonymized usage profiles with the help of cookies, further information may be collected and evaluated, which, however, does not serve your personal identification and is not merged with other data sets. If this information contains a personal reference, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization purposes.

The setting of cookies can be prevented by appropriate browser settings. In this case, however, the functionality of our website may be limited.
You can object to the collection and storage of data for the purpose of creating a pseudonymized usage profile at any time with effect for the future.

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

5.2 Judge.me

For review reminders, we use the services of the following provider: Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom

Exclusively on the basis of your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, we transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder via email.

You can revoke your consent at any time with effect for the future to us or the provider.

We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the provider's location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

5.3 Reviews.io

For review reminders, we use the services of the following provider: REVIEWS.io 2020 GmbH, Skalitzer Str. 104, 10997 Berlin, Germany

Exclusively on the basis of your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, we transmit your email address and possibly other customer data to the provider so that they can contact you with a review reminder via email.

You can revoke your consent at any time with effect for the future to us or the provider.

We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

5.4 WhatsApp Business

You have the option to contact us via the messaging service WhatsApp of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For this purpose, we use the so-called "Business Version" of WhatsApp.

If you contact us via WhatsApp regarding a specific transaction (for example, a placed order), we store and use your mobile number used on WhatsApp and – if provided – your first and last name in accordance with Art. 6 para. 1 lit. b. GDPR to process and respond to your request. Based on the same legal basis, we may ask you via WhatsApp to provide further data (order number, customer number, address or email address) in order to be able to assign your request to a specific process.

If you use our WhatsApp contact for general inquiries (e.g., about the range of services, availability, or our website), we store and use your mobile number used on WhatsApp and – if provided – your first and last name in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the efficient and timely provision of the requested information.

Your data will always only be used to respond to your request via WhatsApp. No disclosure to third parties takes place.

Please note that WhatsApp Business obtains access to the address book of the mobile device we use for this purpose and automatically transfers phone numbers stored in the address book to a server of the parent company Meta Platforms Inc. in the USA. For the operation of our WhatsApp Business account, we use a mobile device whose address book exclusively stores the WhatsApp contact details of users who have also contacted us via WhatsApp.

This ensures that every person whose WhatsApp contact details are stored in our address book has already consented to the transmission of their WhatsApp phone number from the address books of their chat contacts in accordance with Art. 6 para. 1 lit. a GDPR when first using the app on their device by accepting the WhatsApp terms of use. The transmission of data of users who do not use WhatsApp and/or have not contacted us via WhatsApp is thus excluded.

For the purpose and scope of data collection and the further processing and use of the data by WhatsApp, as well as your related rights and setting options for protecting your privacy, please refer to WhatsApp's privacy policy: https://www.whatsapp.com/legal/?eea=1#privacy-policy

We have concluded a data processing agreement with the provider, which protects the data of our site visitors and prohibits disclosure to third parties.

As part of the processing mentioned above, data transfers to Meta Platforms Inc. servers in the USA may occur.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision of the European Commission.

5.5 When you contact us (e.g. via contact form or e-mail), personal data is processed - exclusively for the purpose of processing and answering your request and only to the extent necessary for this purpose.

The legal basis for the processing of this data is our legitimate interest in answering your request in accordance with Art. 6 para. 1 lit. f GDPR. If your contact aims at concluding a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter concerned has been finally clarified and provided that no statutory retention obligations conflict with this.

6) Comment Function

When using the comment function on this website, in addition to your comment, information about the time of creation of the comment and the commenter name you chose are stored and published on this website. Furthermore, your IP address is logged and stored. This storage of the IP address takes place for security reasons and in case the person concerned violates the rights of third parties or posts illegal content through a submitted comment. We need your email address to contact you if a third party complains that your published content is illegal.

Legal bases for the storage of your data are Art. 6 para. 1 lit. b and f GDPR. We reserve the right to delete comments if they are complained about by third parties as illegal.

You can subscribe to follow-up comments. You will receive a confirmation email for this purpose to ensure that you are the owner of the email address provided (double opt-in procedure). The legal basis for data processing in the case of subscribing to comments is Art. 6 para. 1 lit. a GDPR. You can unsubscribe from ongoing comment subscriptions at any time with effect for the future; further information on how to unsubscribe can be found in the confirmation email.

7) Data Processing When Opening a Customer Account

In accordance with Art. 6 para. 1 lit. b GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. You can find out which data is required for opening an account from the input mask of the corresponding form on our website.

Your customer account can be deleted at any time and can be done by sending a message to the above address of the controller. After deletion of your customer account, your data will be deleted, provided that all contracts concluded through it have been completely processed, no statutory retention periods conflict with this, and we no longer have a legitimate interest in continued storage.

8) Use of Customer Data for Direct Marketing

8.1 Newsletter Subscription

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. The provision of further data is voluntary and will be used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure, which ensures that you only receive the newsletter when you have expressly confirmed your consent to receive the newsletter by activating a verification link sent to the specified email address.

By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6 para. 1 lit. a GDPR. In this context, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace a possible misuse of your e-mail address at a later date. The data collected by us when registering for the newsletter will be used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a message to the controller mentioned above. After unsubscribing, your e-mail address will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to further use data, which is legally permitted and about which we inform you in this declaration.

8.2 Shopify Email

Our e-mail newsletters are sent via this provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

Based on our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provide when registering for the newsletter to this provider in accordance with Art. 6 para. 1 lit. f GDPR, so that they can send the newsletter on our behalf.

Subject to your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the provider also carries out a statistical performance evaluation of newsletter campaigns by means of web beacons or tracking pixels in the sent e-mails, which can measure opening rates and specific interactions with the content of the newsletter. Device information (e.g., time of access, IP address, browser type and operating system) is also collected and evaluated but not merged with other data.
You can revoke your consent to newsletter tracking at any time with effect for the future.

We have concluded an order processing agreement with the provider, which protects the data of our site visitors and prohibits disclosure to third parties.

When data is transferred to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.

8.3 E-mail notification of product availability

For temporarily unavailable items, you can sign up to receive e-mail notifications of product availability. In this case, we will send you a one-time e-mail message about the availability of the item you have selected. The only mandatory information for sending this notification is your e-mail address. The provision of further data is voluntary and may be used to address you personally. For sending mail, we use the so-called double opt-in procedure, which ensures that you only receive a notification if you have explicitly confirmed your consent by clicking on a verification link sent to the e-mail address provided.

By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6 para. 1 lit. a GDPR. In this context, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace a possible misuse of your e-mail address at a later date. The data collected by us when registering for our e-mail notification service for product availability will be used strictly for the intended purpose.

You can unsubscribe from the availability notifications at any time by sending a message to the controller mentioned above. After unsubscribing, your e-mail address will be immediately deleted from our distribution list set up for this purpose, unless you have expressly consented to further use of your data or we reserve the right to further use data, which is legally permitted and about which we inform you in this declaration.

8.4 Shopping cart reminders via e-mail

If you abandon your purchase with us before completing the order, you have the option of being reminded once via e-mail of the contents of your virtual shopping cart.

The only mandatory information for sending this reminder is your e-mail address. The provision of further data is voluntary and may be used to address you personally. For sending mail, we use the so-called double opt-in procedure, which ensures that you only receive a notification if you have explicitly confirmed your consent by clicking on a verification link sent to the e-mail address provided.

By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6 para. 1 lit. a GDPR for sending a shopping cart reminder. In this context, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace a possible misuse of your e-mail address at a later date. The data collected by us when registering for our e-mail notification service will be used strictly for the intended purpose.

You can unsubscribe from the shopping cart reminders at any time by sending a message to the controller mentioned above. After unsubscribing, your e-mail address will be immediately deleted from our distribution list set up for this purpose, unless you have expressly consented to further use of your data or we reserve the right to further use data, which is legally permitted and about which we inform you in this declaration.

9) Data processing for order fulfillment

9.1 Transmission of image files for order processing by e-mail

On our website, we offer customers the option of requesting product personalization by sending image files via e-mail. The submitted image is used as a template for personalizing the selected product.

The customer can send one or more image files from the storage of the used end device to us via the e-mail address provided on the website. We then collect, store and use the files transmitted in this way exclusively for the production of the personalized product in the sense of the respective service description on our website. If the transmitted image files are passed on to special service providers for the production and processing of the order, you will be explicitly informed about this in the following paragraphs. No further disclosure takes place. If the transmitted files or the digital motifs contain personal data (in particular images of identifiable persons), all the processing operations just mentioned are carried out exclusively for the purpose of processing your online order in accordance with Art. 6 para. 1 lit. b GDPR.

After final processing of the order, the transmitted image files are automatically and completely deleted.

9.2 Transmission of image files for order processing via message function

If the customer has the option of commissioning the personalization of products by transmitting image files via the message function, the submitted image motif is used as a template for the personalization of the selected product.

The customer can send one or more image files from the storage of the used end device to us via the available message function. We then collect, store and use the files transmitted in this way exclusively for the production of the personalized product in the sense of the respective description of our services.

If the transmitted image files are passed on to special service providers for the production and processing of the order, you will be explicitly informed about this in the following paragraphs. No further disclosure takes place. If the transmitted files or the digital motifs contain personal data (in particular images of identifiable persons), all the processing operations just mentioned are carried out exclusively for the purpose of processing your online order in accordance with Art. 6 para. 1 lit. b GDPR.

After final processing of the order, the transmitted image files are automatically and completely deleted.

9.3 Transmission of image files for order processing via upload function

On our website, we offer customers the option of commissioning the personalization of products by transmitting image files via an upload function. The submitted image motif is used as a template for personalizing the selected product.

Via the upload form on the website, the customer can directly send one or more image files from the storage of the used end device to us via automated, encrypted data transmission. We then collect, store and use the transmitted files exclusively for the production of the personalized product in the sense of the respective service description on our website. If the transmitted image files are passed on to special service providers for the production and processing of the order, you will be explicitly informed about this in the following paragraphs. No further disclosure takes place. If the transmitted files or the digital motifs contain personal data (in particular images of identifiable persons), all the processing operations just mentioned are carried out exclusively for the purpose of processing your online order in accordance with Art. 6 para. 1 lit. b GDPR.

After final processing of the order, the transmitted image files are automatically and completely deleted.

9.4 Insofar as necessary for the fulfillment of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR.

If, based on a corresponding contract, we owe you updates for goods with digital elements or for digital products, we process the contact data you provided when ordering to inform you personally within the framework of our legal information obligations in accordance with Art. 6 para. 1 lit. c GDPR. Your contact data will be used strictly for the intended purpose for communications about updates owed by us and will only be processed by us to the extent necessary for the respective information.

To process your order, we also work with the following service provider(s), who support us wholly or partially in the execution of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.

9.5 To fulfill our contractual obligations to our customers, we cooperate with external shipping partners. We pass on your name and delivery address and, if necessary for delivery, your telephone number, exclusively for the purpose of goods delivery in accordance with Art. 6 para. 1 lit. b GDPR to a shipping partner selected by us.

9.6 Printful

For order processing, we use the following provider: Printful, Inc. 11025 Westlake Drive, Charlotte, NC28273, USA

Name, address and, if applicable, other personal data are passed on to the provider in accordance with Art. 6 para. 1 lit. b GDPR exclusively for the purpose of processing the online order. Your data will only be passed on if this is actually necessary for the processing of the order.

For the transfer of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.

9.7 Shirtigo

For order processing, we use the following provider: Shirtigo GmbH, Siemensstraße 2, 50354 Hürth, Germany

Name, address and, if applicable, other personal data are passed on to the provider in accordance with Art. 6 para. 1 lit. b GDPR exclusively for the purpose of processing the online order. Your data will only be passed on if this is actually necessary for the processing of the order.

9.8 Printegy

For order processing, we use the following provider: Printegy GmbH, Herkulesstr. 9-11, 45127 Essen

Name, address and, if applicable, other personal data are passed on to the provider in accordance with Art. 6 para. 1 lit. b GDPR for the purpose of processing the online order. Your data will only be passed on if this is actually necessary for the processing of the order. The provider is also used for accounting. Thus, the provider processes incoming and outgoing invoices and, if applicable, also the bank movements of our company to automatically record invoices, match them to transactions and thus create financial accounting in a semi-automated process.

If personal data is also processed in this context, the processing takes place in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in an efficient organization and documentation of our business processes.

9.9 Disclosure of personal data to shipping service providers

- DHL

As a transport service provider, we use the following provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany

We pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent for this in the order process. Otherwise, we only pass on the recipient's name and delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The transfer only takes place insofar as this is necessary for the delivery of the goods. In this case, a prior coordination of the delivery date with the provider or the delivery announcement is not possible.

Consent can be revoked at any time with effect for the future towards the controller named above or towards the provider.
- DPD

As a transport service provider, we use the following provider: DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany

We pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent for this in the order process. Otherwise, we only pass on the recipient's name and delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The transfer only takes place insofar as this is necessary for the delivery of the goods. In this case, a prior coordination of the delivery date with the provider or the delivery announcement is not possible.

Consent can be revoked at any time with effect for the future towards the controller named above or towards the provider.
- Hermes

As a transport service provider, we use the following provider: Hermes Logistik Gruppe Deutschland GmbH, Essener Straße 89, 22419 Hamburg, Germany

We pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided you have given your express consent for this in the order process. Otherwise, we only pass on the recipient's name and delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The transfer only takes place insofar as this is necessary for the delivery of the goods. In this case, a prior coordination of the delivery date with the provider or the delivery announcement is not possible.

Consent can be revoked at any time with effect for the future towards the controller named above or towards the provider.

9.10 Use of payment service providers (payment services)

- Apple Pay

If you choose the "Apple Pay" payment method from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing takes place via the "Apple Pay" function of your iOS, watchOS or macOS device by debiting a payment card stored in "Apple Pay". Apple Pay uses security features integrated into the hardware and software of your device to protect your transactions. To authorize a payment, you must enter a code previously set by you and verify it using the "Face ID" or "Touch ID" function of your device.

For the purpose of payment processing, your information communicated during the order process, along with information about your order, is transmitted to Apple in encrypted form. Apple then encrypts this data again with a developer-specific key before the data is transmitted to the payment service provider of the payment card stored in Apple Pay for payment execution. The encryption ensures that only the website through which the purchase was made can access the payment data. After the payment has been made, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the success of the payment.

If personal data is processed in the described transmissions, the processing takes place exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.

Apple stores anonymized transaction data, including the approximate purchase amount, approximate date and time, and whether the transaction was successfully completed. Anonymization completely excludes any personal reference. Apple uses the anonymized data to improve "Apple Pay" and other Apple products and services.

When you use Apple Pay on your iPhone or Apple Watch to complete a purchase you made via Safari on your Mac, your Mac and the authorization device communicate via an encrypted channel on Apple's servers. Apple does not process or store any of this information in a format that can identify you personally. You can disable the option to use Apple Pay on your Mac in your iPhone settings. Go to "Wallet & Apple Pay" and disable "Allow Payments on Mac".

Further information on data protection for Apple Pay can be found at the following internet address: https://support.apple.com/de-de/HT203027
- Google Pay

If you choose "Google Pay" as the payment method from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), payment processing is carried out via the "Google Pay" application on your mobile device (running at least Android 4.4 ("KitKat") and equipped with an NFC function) by charging a payment card stored with Google Pay or a verified payment system there (e.g. PayPal). To authorize a payment via Google Pay exceeding €25, your mobile device must first be unlocked using the respective verification method (such as facial recognition, password, fingerprint, or pattern).

For the purpose of payment processing, the information you provide during the order process, along with information about your order, will be forwarded to Google. Google then transmits your payment information stored in Google Pay in the form of a uniquely assigned transaction number to the originating website, which verifies a completed payment. This transaction number contains no information about the real payment data of your payment methods stored with Google Pay, but is created and transmitted as a unique numeric token. For all transactions via Google Pay, Google merely acts as an intermediary for processing the payment. The transaction is carried out exclusively between the user and the originating website by debiting the payment method stored with Google Pay.

Insofar as personal data is processed during the described transmissions, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.

Google reserves the right to collect, store and evaluate certain transaction-specific information for every transaction made via Google Pay. This includes the date, time and amount of the transaction, merchant location and description, a description of the purchased goods or services provided by the merchant, photos you have attached to the transaction, the name and email address of the seller and buyer or sender and recipient, the payment method used, your description of the reason for the transaction and, if applicable, the offer associated with the transaction.

According to Google, this processing is carried out exclusively in accordance with Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in proper accounting, verification of transaction data and the optimization and maintenance of the Google Pay service.

Google also reserves the right to combine the processed transaction data with other information collected and stored by Google when using other Google services.

The Google Pay terms of use can be found here:

https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=de
Further information on data protection for Google Pay can be found at the following internet address:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=de
- Klarna

One or more online payment methods from the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden

If you select a payment method from the provider that requires you to make an advance payment (e.g., credit card payment), your payment data provided during the order process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be transmitted to this provider in accordance with Art. 6 para. 1 lit. b GDPR. In this case, the transmission of your data is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider makes an advance payment (e.g., invoice purchase, installment purchase, or direct debit), you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly data for an alternative payment method) during the order process.

In order to protect our legitimate interest in assessing the creditworthiness of our customers, we forward this data to the provider for the purpose of a credit check in accordance with Art. 6 para. 1 lit. f GDPR. Based on the personal data you provide and other data (such as shopping cart, invoice amount, order history, payment experiences), the provider checks whether the payment option you selected can be granted with regard to payment and/or default risks.

In addition to internal provider criteria, identity and creditworthiness information from the following credit agencies may be included in the decision-making process for the application review in accordance with Art. 6 para. 1 lit. f GDPR:

https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but not exclusively, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.
- Paypal

One or more online payment methods from the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

If you select a payment method from the provider that requires you to make an advance payment, your payment data provided during the order process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be transmitted to this provider in accordance with Art. 6 para. 1 lit. b GDPR. In this case, the transmission of your data is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

If you select a payment method where we make an advance payment, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly data for an alternative payment method) during the order process.

In such cases, to protect our legitimate interest in assessing your creditworthiness, we forward this data to the provider for the purpose of a credit check in accordance with Art. 6 para. 1 lit. f GDPR. Based on the personal data you provide and other data (such as shopping cart, invoice amount, order history, payment experiences), the provider checks whether the payment option you selected can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but not exclusively, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.
- Paypal Checkout

This website uses PayPal Checkout, an online payment system from PayPal that consists of PayPal's own payment methods and local third-party payment methods.

When paying via PayPal, credit card via PayPal, direct debit via PayPal or – if offered – "Pay Later" via PayPal, we transmit your payment data within the framework of payment processing to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"). The transmission takes place in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for payment processing.

PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or – if offered – "Pay Later" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 para. 1 lit. f GDPR on the basis of PayPal's legitimate interest in determining your creditworthiness. PayPal uses the result of the credit check regarding the statistical probability of payment default for the purpose of deciding whether to provide the respective payment method. The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but not exclusively, address data. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.

If the PayPal payment method "invoice purchase" is available and selected, your payment data will first be transmitted to PayPal for payment preparation, whereupon PayPal will forward it to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin ("Ratepay") for payment execution. The legal basis in each case is Art. 6 para. 1 lit. b GDPR. In this case, RatePay carries out an identity and creditworthiness check on its own behalf to determine creditworthiness in accordance with the principle already mentioned above and transmits your payment data to credit agencies based on its legitimate interest in determining creditworthiness in accordance with Art. 6 para. 1 lit. f GDPR. A list of credit agencies that Ratepay may use can be found here: https://www.ratepay.com/legal-payment-creditagencies/

When using a local third-party payment method, your payment data is first transmitted to PayPal in accordance with Art. 6 para. 1 lit. b GDPR for payment preparation. Depending on your selection of an available local payment method, PayPal then transmits your payment data to the corresponding provider for payment execution in accordance with Art. 6 para. 1 lit. b GDPR:

- Apple Pay (Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
- Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)
- iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
- bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
- blik (Polski Standard Płatności sp. z o.o., ul. Czerniakowska 87A, 00-718 Warsaw, Poland)
- eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2
1200 Vienna, Austria)
- MyBank (PRETA S.A.S, 40 Rue de Courcelles, F-75008 Paris, France)
- Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)

Further data protection information can be found in PayPal's privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full
- Shopify Payments

One or more online payment methods from the following provider are available on this website: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

If you select a payment method from the provider that requires you to make an advance payment (e.g., credit card payment), your payment data provided during the order process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be transmitted to this provider in accordance with Art. 6 para. 1 lit. b GDPR. In this case, the transmission of your data is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- Stripe

One or more online payment methods from the following provider are available on this website: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

If you select a payment method from the provider that requires you to make an advance payment (e.g., credit card payment), your payment data provided during the order process (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order will be transmitted to this provider in accordance with Art. 6 para. 1 lit. b GDPR. In this case, the transmission of your data is solely for the purpose of payment processing with the provider and only to the extent necessary for this purpose.

If you select a payment method where the provider makes an advance payment (e.g., invoice or installment purchase or direct debit), you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, phone number, and possibly data for an alternative payment method) during the order process.

In order to protect our legitimate interest in assessing the creditworthiness of our customers, we forward this data to the provider for the purpose of a credit check in accordance with Art. 6 para. 1 lit. f GDPR. Based on the personal data you provide and other data (such as shopping cart, invoice amount, order history, payment experiences), the provider checks whether the payment option you selected can be granted with regard to payment and/or default risks.

The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things, but not exclusively, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

9.11 Electronic termination option for continuing obligations with consumers

Consumers who have entered into contracts for chargeable continuing obligations (e.g., subscription contracts) on this website have the option to terminate them via an electronic button in accordance with the applicable notice periods.

Clicking the button leads to a confirmation page where the consumer can provide further details about the termination, clearly identify themselves, and then declare their termination electronically.

The collection of personal data and its transmission to us takes place here in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for the proper processing of the termination. Also based on Art. 6 para. 1 lit. b GDPR, the provided personal data is used to confirm the receipt of the termination declaration and the time of termination electronically in text form. Another legal basis for the processing is Art. 6 para. 1 lit. c GDPR. We are legally obliged to provide an electronic termination option for consumer contracts for chargeable continuing obligations concluded electronically.

10) Web analytics services

10.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

By default, when you visit the website, Google Analytics 4 sets cookies, which are small text modules stored on your device and collect certain information. This information also includes your IP address, which Google shortens by the last digits to exclude direct personal reference.

The information is transmitted to Google servers and processed there. Transfers to Google LLC based in the USA are also possible.

Google uses the information collected on our behalf to evaluate your use of the website, compile reports on website activities for us, and provide other services related to website and internet usage. The truncated IP address transmitted by your browser within Google Analytics will not be merged with other Google data. Data collected within the scope of using Google Analytics 4 will be stored for two months and then deleted.

All processing described above, in particular the setting of cookies on the device used, only takes place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
Without your consent, Google Analytics 4 will not be used during your visit to the site. You can revoke your given consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service via the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with Google, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

Further legal information on Google Analytics 4 can be found at https://business.safety.google/intl/de/privacy/, https://policies.google.com/privacy?hl=de&gl=de and at https://policies.google.com/technologies/partner-sites

Demographic characteristics
Google Analytics 4 uses the special feature "demographic characteristics" and can use it to create statistics that provide information about the age, gender and interests of website visitors. This is done by analyzing advertising and third-party information. This allows target groups for marketing activities to be identified. However, the collected data cannot be assigned to any specific person and will be deleted after being stored for two months.

Google Signals
As an extension to Google Analytics 4, Google Signals may be used on this website to generate cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google may, subject to your consent to the use of Google Analytics pursuant to Art. 6 para. 1 lit. a GDPR, analyze your usage behavior across devices and create database models, including cross-device conversions. We do not receive personal data from Google, only statistics. If you wish to stop cross-device analysis, you can deactivate the "Personalized advertising" feature in your Google account settings. To do so, follow the instructions on this page: https://support.google.com/My-Ad-Center-Help/answer/12155764?hl=de
Further information on Google Signals can be found at the following link: https://support.google.com/analytics/answer/7532985?hl=de

User IDs
As an extension to Google Analytics 4, the "User IDs" feature can be used on this website. If you have consented to the use of Google Analytics 4 in accordance with Art. 6 para. 1 lit. a GDPR, have set up an account on this website, and log in to this account on different devices, your activities, including conversions, can be analyzed across devices.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

10.2 Google Tag Manager

This website uses "Google Tag Manager", a service from the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").

Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analysis services, and for calibrating, controlling, and linking them to conditions via a uniform user interface. Google Tag Manager itself does not store any information on user devices or read it out. The service also does not carry out any independent data analyses. However, when a page is called up, your IP address is transmitted to Google via Google Tag Manager and may be stored there. A transfer to servers of Google LLC in the USA is also possible.

This processing will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, Google Tag Manager will not be used during your visit to the site. You can revoke your given consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

Further legal information on Google Tag Manager can be found at https://business.safety.google/intl/de/privacy/ and https://policies.google.com/privacy?hl=de&gl=de

10.3 PayPal Marketing Solutions

This website uses the web analysis service of the following provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used, such as the IP address and browser information, to evaluate it for statistical analyses of user behavior on our website and to create pseudonymized usage profiles. Among other things, this allows for the evaluation of movement patterns (so-called heatmaps), which show the duration of page visits and interactions with page content (e.g., text input, scrolling, clicks, and mouse-overs). Pseudonymization generally excludes direct personal identification. No merging with otherwise collected clear data about you takes place.

All processing described above, in particular the reading or storing of information on the device used, will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

10.4 Shopify Analytics

This website uses the web analysis service of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada

Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used, such as the IP address and browser information, to evaluate it for statistical analyses of user behavior on our website and to create pseudonymized usage profiles. Among other things, this allows for the evaluation of movement patterns (so-called heatmaps), which show the duration of page visits and interactions with page content (e.g., text input, scrolling, clicks, and mouse-overs). Pseudonymization generally excludes direct personal identification. No merging with otherwise collected clear data about you takes place.

All processing described above, in particular the reading or storing of information on the device used, will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider, which protects the data of our site visitors and prohibits disclosure to third parties.

In the case of data transfer to Canada, an adequate level of data protection is guaranteed by an adequacy decision of the European Commission.

11) Retargeting/ Remarketing and Conversion Tracking

11.1 Meta Pixel

Within our online offering, we use the "Meta Pixel" service from the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Meta")

If a user clicks on an advertisement placed by us on Facebook and/or Instagram, the URL of our linked page is extended by a parameter using "Meta Pixel". This URL parameter is then entered into the user's browser after redirection by a cookie that our linked page itself sets.

This allows Meta, on the one hand, to define the visitors to our online offering as a target group for the display of advertisements (so-called "Ads"). Accordingly, we use the service to display the Facebook and/or Instagram Ads placed by us only to users who have shown an interest in our online offering or who have certain characteristics (e.g., interests in certain topics or products, which are determined based on the websites visited) that we transmit to Meta (so-called "Custom Audiences").

On the other hand, the "Meta Pixel" can be used to track whether users have been redirected to our website after clicking on an advertisement and what actions they perform there (so-called "Conversion Tracking").

The collected data is anonymous to us, meaning it does not allow us to draw conclusions about the identity of the users. However, the data is stored and processed by Meta, so that a connection to the respective user profile is possible and Meta can use the data for its own advertising purposes.

All processing described above, in particular the setting of cookies for reading information on the device used, will only take place if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.

We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

The information generated by Meta is usually transferred to a Meta server and stored there; in this context, a transfer to Meta Platforms Inc. servers in the USA may also occur.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

11.2 Google Ads Remarketing

This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

For this purpose, Google sets a cookie in your device's browser, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Further data processing only takes place if you have agreed with Google that your internet and app browsing history will be linked to your Google account and information from your Google account will be used to personalize ads you see on the web. If you are logged into Google during your visit to our website in this case, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked with Google Analytics data by Google to form target groups. Within the scope of using Google Ads Remarketing, personal data may also be transmitted to the servers of Google LLC. in the USA.

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, retargeting technology will not be used during your visit to the site.

You can revoke your given consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.

Details on the processing initiated by Google and Google's handling of data from websites can be found here: https://policies.google.com/technologies/partner-sites

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

11.3 Pinterest Retargeting Pixel

This website uses retargeting technology from the following provider: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland

This allows us to specifically address visitors to our websites with personalized, interest-based advertising who have already shown an interest in our shop and our products. The advertising material is displayed based on a cookie-based analysis of past and current user behavior.

In the case of retargeting technology, a cookie is stored on your computer or mobile device to collect pseudonymized data about your interests and thus adapt the advertising individually to the stored information. These cookies are small text files that are stored on your computer or mobile device. You are thus shown advertising that is highly likely to match your product and information interests.

All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, retargeting technology will not be used during your visit to the site.

You can revoke your given consent at any time with effect for the future. To exercise your right of revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

11.4 Google Ads Conversion Tracking without cookies

This website uses the "Google Ads" online advertising program and, within the scope of Google Ads, the conversion tracking of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").

We use the Google Ads offer to draw attention to our attractive offers on external websites using advertising materials (so-called Google Adwords). We can determine how successful the individual advertising measures are in relation to the data of the advertising campaigns. Our aim is to show you advertising that is of interest to you, to make our website more interesting for you and to achieve a fair calculation of the advertising costs incurred.

This website uses Google Ads Conversion Tracking exclusively without the use of cookies, which means that the service does not set cookies on your device at any time.

Instead, your browser's local storage is used to store an individual ID assigned by Google, which enables an analysis of your use of the website. For this purpose, certain user information is processed via the ID.

The ID is set when a user clicks on an ad served by Google. If the user visits certain pages of this website, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Cookies can therefore not be tracked across the websites of Google Ads customers. The information thus obtained is used to generate conversion statistics for Google Ads customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag.

However, you do not receive any information that personally identifies users. In the context of using Google Ads, personal data may also be transferred to the servers of Google LLC. in the USA. Details on the processing initiated by Google Ads Conversion Tracking and Google's handling of data from websites can be found here: https://policies.google.com/technologies/partner-sites

Insofar as the collected information relates to a person, the processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the statistical evaluation of the success of our advertising campaigns.
Google's privacy policy can be viewed here: https://business.safety.google/intl/de/privacy/ and https://www.google.de/policies/privacy/

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

12) Page functionalities

12.1 Facebook Plugins

Our website uses plugins from the social network of the following provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

These plugins enable direct interactions with content on the social network.

To increase the protection of your data when visiting our website, the plugins are initially integrated into the page deactivated by means of a so-called "2-click" or "Shariff" solution.

This integration ensures that no connection is established with the provider's servers when a page of our website containing such plugins is accessed.

Only when you activate the plugins and thereby give your consent to the data transfer in accordance with Art. 6 para. 1 lit. a GDPR, does your browser establish a direct connection to the provider's servers. In this process, regardless of a login to an existing user profile, certain information about your used end device (including your IP address), your browser and your page history are transmitted to the provider and, if applicable, further processed there.

If you are logged into an existing user profile on the provider's social network, information about interactions made via the plugins will also be published there and displayed to your contacts.
You can revoke your consent at any time by reactivating the activated plugin by clicking on it again. However, the revocation has no influence on the data already transferred to the provider.

Data may also be transferred to: Meta Platforms Inc., USA

We have concluded a data processing agreement with the provider that ensures the protection of our page visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

12.2 Instagram Plugins

Our website uses plugins from the social network of the following provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland

These plugins enable direct interactions with content on the social network.

To increase the protection of your data when visiting our website, the plugins are initially integrated into the page deactivated by means of a so-called "2-click" or "Shariff" solution.

This integration ensures that no connection is established with the provider's servers when a page of our website containing such plugins is accessed.

Only when you activate the plugins and thereby give your consent to the data transfer in accordance with Art. 6 para. 1 lit. a GDPR, does your browser establish a direct connection to the provider's servers. In this process, regardless of a login to an existing user profile, certain information about your used end device (including your IP address), your browser and your page history are transmitted to the provider and, if applicable, further processed there.

If you are logged into an existing user profile on the provider's social network, information about interactions made via the plugins will also be published there and displayed to your contacts.
You can revoke your consent at any time by reactivating the activated plugin by clicking on it again. However, the revocation has no influence on the data already transferred to the provider.

Data may also be transferred to: Meta Platforms Inc., USA

We have concluded a data processing agreement with the provider that ensures the protection of our page visitors' data and prohibits unauthorized disclosure to third parties.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

12.3 Pinterest Plugins

Our website uses plugins from the social network of the following provider: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland

These plugins enable direct interactions with content on the social network.

To increase the protection of your data when visiting our website, the plugins are initially integrated into the page deactivated by means of a so-called "2-click" or "Shariff" solution.

This integration ensures that no connection is established with the provider's servers when a page of our website containing such plugins is accessed.

Only when you activate the plugins and thereby give your consent to the data transfer in accordance with Art. 6 para. 1 lit. a GDPR, does your browser establish a direct connection to the provider's servers. In this process, regardless of a login to an existing user profile, certain information about your used end device (including your IP address), your browser and your page history are transmitted to the provider and, if applicable, further processed there.

If you are logged into an existing user profile on the provider's social network, information about interactions made via the plugins will also be published there and displayed to your contacts.
You can revoke your consent at any time by reactivating the activated plugin by clicking on it again. However, the revocation has no influence on the data already transferred to the provider.

Data may also be transferred to: Pinterest Inc., USA

We have concluded a data processing agreement with the provider that ensures the protection of our page visitors' data and prohibits unauthorized disclosure to third parties.

For the transfer of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European data protection level.

12.4 Youtube

This website uses plugins for displaying and playing videos from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

Data may also be transferred to: Google LLC., USA

When you access a page of our website that contains such a plugin, your browser establishes a direct connection to the provider's servers at the latest when the video is played, in order to load the content. Certain information, including your IP address, is transmitted to the provider in this process.

If the playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, create playback statistics and prevent abusive behavior.

If you are logged into a user account with the provider during your visit to the page, your data will be directly assigned to your account when you click on a video. If you do not wish for your data to be assigned to your account, you must log out before pressing the playback button.

All the aforementioned processing operations, in particular the setting of cookies for reading information on the terminal device used, only take place if you have given us your express consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

12.5 Apple Maps

This website uses an online map service from the following provider: Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland

The online map service is a tool for displaying interactive (country) maps to visually represent geographical information. By using this service, our location is displayed to you and any geolocalization is facilitated.

Already when accessing the subpages on which the provider's map is embedded, information about your use of our website (such as your IP address) is transmitted to the provider's servers and stored there.

The processing of your personal data is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the needs-based design of our website. If you do not agree to the future transmission of your data to the provider, you can completely deactivate the provider's online map service by switching off the JavaScript application in your browser. The online map service on this website can then no longer be used.

Insofar as legally required, we have obtained your consent for the processing of your data described above in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future. To exercise your revocation, please follow the possibility described above to object.

For the transfer of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European data protection level.

12.6 Google Maps

This website uses an online map service from the following provider: Google Maps (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

Google Maps is a web service for displaying interactive (country) maps to visually represent geographical information. By using this service, our location is displayed to you and any route planning is facilitated.

Already when accessing the subpages on which the Google Maps map is embedded, information about your use of our website (such as your IP address) is transmitted to Google's servers and stored there. This may also involve a transfer to the servers of Google LLC. in the USA. This occurs regardless of whether Google provides a user account through which you are logged in or whether a user account exists. If you are logged in to Google, your data will be directly assigned to your account. If you do not wish for your data to be assigned to your profile with Google, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates these.

The collection, storage and evaluation are carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of Google's legitimate interest in displaying personalized advertising, market research and/or the needs-based design of Google websites. You have a right to object to the creation of these user profiles, whereby you must contact Google to exercise this right. If you do not agree to the future transmission of your data to Google within the scope of using Google Maps, you can also completely deactivate the Google Maps web service by switching off the JavaScript application in your browser. Google Maps and thus also the map display on this website can then no longer be used.

Insofar as legally required, we have obtained your consent for the processing of your data described above in accordance with Art. 6 para. 1 lit. a DSGVO. You can revoke your given consent at any time with effect for the future. To exercise your revocation, please follow the possibility described above to object.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

12.7 Google Web Fonts

This site uses so-called web fonts from the following provider for the uniform display of fonts: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

When you access a page, your browser loads the necessary web fonts into its browser cache to display texts and fonts correctly and establishes a direct connection to the provider's servers. Certain browser information, including your IP address, is transmitted to the provider in this process.

Data may also be transferred to: Google LLC, USA

The processing of personal data in the course of establishing a connection with the font provider is only carried out if you have given us your express consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website. If your browser does not support web fonts, a standard font from your computer will be used.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level on the basis of an adequacy decision by the European Commission.

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

12.8 hCaptcha

On this website, we use the CAPTCHA service from the following provider: Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, USA

The service checks whether an input is made by a natural person or abusively by machine and automated processing, and blocks spam, DDoS attacks and similar automated malicious access. To ensure that an action is performed by a human and not by an automated bot, the provider collects the IP address of the end device used, identification data of the browser and operating system type used, and the date and duration of the visit, and transmits these to the provider's servers for evaluation.

The legal basis is our legitimate interest in determining individual responsibility on the internet and preventing abuse and spam in accordance with Art. 6 para. 1 lit. f GDPR.

We have concluded a data processing agreement with the provider that ensures the protection of our page visitors' data and prohibits unauthorized disclosure to third parties.

For the transfer of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European data protection level.

12.9 Google Customer Reviews (formerly Google Certified Shop Program)

We work with Google as part of the "Google Customer Reviews" program. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This program gives us the opportunity to collect customer reviews from users of our website. After a purchase on our website, you will be asked if you would like to participate in an email survey from Google.

If you give your consent in accordance with Art. 6 para. 1 lit. a GDPR, we will transmit your e-mail address to Google. You will receive an e-mail from Google Customer Reviews asking you to rate your shopping experience on our website. The rating you submit will then be summarized with our other ratings and displayed in our Google Customer Reviews logo and in our Merchant Center dashboard. Your rating will also be used for Google Seller Ratings. As part of the use of Google Customer Reviews, personal data may also be transferred to the servers of Google LLC. in the USA.

You can revoke your consent at any time by sending a message to the data controller or to Google.

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

Further information on Google's privacy policy can be found here: https://business.safety.google/intl/de/privacy/

12.10 Shopsync for Shopify

This website uses the Shopify app "Shopsync" from ShopSync LLC, PO Box 252, Jefferson City, TN 37760, USA.
ShopSync synchronizes the newsletter service "Mailchimp" with our Shopify account in such a way that, on the one hand, updates in Mailchimp's e-mail lists (e.g. an opt-out by a newsletter recipient) are automatically stored on Shopify and, on the other hand, new contact data generated via contracts on Shopify is automatically transferred to Mailchimp's e-mail lists.

In the former case, data processing takes place in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the effective and cross-system maintenance of advertising recipient files and the efficient observance of legally relevant status changes.

In the second case, only on the basis of explicit consent from the user in accordance with Art. 6 para. 1 lit. a GDPR after a contract has been concluded on Shopify for inclusion in the Mailchimp list, their first and last name, address and e-mail address are transferred to Mailchimp by ShopSync together with transaction-related information (purchase amount, time and date of purchase).

Data transferred in this way is not stored or retained by ShopSync after synchronization. All information synchronized between Shopify and Mailchimp is transmitted using SSL (Secure Socket Layer) technology, and all transmitted information remains encrypted during the synchronization process.

The synchronization process requires the transfer of information via a secure connection to servers hosted by Amazon Web Services in the USA.

Further data protection information on ShopSync can be found here: https://www.shop-sync.com/privacy-policy

12.11 GetSiteControl

We use the provider GetSiteControl (GetWebCraft Limited Klimentos 41-43, Klimentos Tower, Flat/Office 25, 1061, Nicosia, Cyprus). GetSiteControl is a program that displays pop-ups and overlay windows for information purposes and better user guidance on the website. The windows can be controlled according to certain rules (e.g. number of page visits).

For this purpose, cookies are set by GetSiteControl. These processing operations are carried out exclusively with the explicit consent pursuant to Art. 6 para. 1 lit. a GDPR.

13) Tools and miscellaneous

13.1 - DATEV

For bookkeeping purposes, we use the cloud-based accounting software service of the following provider: DATEV eG, Paumgartnerstr. 6-14, 90429 Nuremberg, Germany

The provider processes incoming and outgoing invoices and, if applicable, also our company's bank transactions in order to automatically record invoices, match them to transactions and generate financial accounting from this in a semi-automated process.

Insofar as personal data is processed in this context, the processing is carried out on the basis of our legitimate interest in the efficient organization and documentation of our business processes in accordance with Art. 6 para. 1 lit. f GDPR.

13.2 Cookie consent tool

This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users when they access the page in the form of an interactive user interface, on which consent for certain cookies and/or cookie-based applications can be given by checking a box. The tool ensures that all cookies/services requiring consent are only loaded if the respective user gives their consent by checking the box. This ensures that such cookies are only placed on the user's end device if consent has been given.

The tool sets technically necessary cookies to save your cookie preferences. Personal user data is generally not processed in this context.

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.

A further legal basis for the processing is Art. 6 para. 1 lit. c GDPR. As the controller, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user's consent.

Where necessary, we have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.

Further information on the operator and the setting options of the cookie consent tool can be found directly in the corresponding user interface on our website.

13.3 Judge.me

To verify and publish customer reviews, we use the services of the following provider: Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom

If you submit a review on our website, your first and last name, e-mail address, order date and number, as well as the name and international references (GTIN/ISDNF) will be collected, transmitted to the provider and evaluated there to decide on the legitimacy of a customer review for a specific order. These processing operations are carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in ensuring the authenticity of customer reviews by ensuring transaction relatedness and preventing review misuse. After the review has been checked and approved, the data will be deleted by the provider.

In the event of data transfer to the provider's location, an adequate level of data protection is guaranteed by an adequacy decision of the European Commission.

14) Rights of the data subject

14.1 The applicable data protection law grants you the following data subject rights (rights of access and intervention) with regard to the processing of your personal data by the controller, whereby reference is made to the legal basis cited for the respective exercise conditions:

  • Right of access in accordance with Art. 15 GDPR;
  • Right to rectification in accordance with Art. 16 GDPR;
  • Right to erasure in accordance with Art. 17 GDPR;
  • Right to restriction of processing in accordance with Art. 18 GDPR;
  • Right to notification in accordance with Art. 19 GDPR;
  • Right to data portability in accordance with Art. 20 GDPR;
  • Right to withdraw granted consents in accordance with Art. 7 para. 3 GDPR;
  • Right to lodge a complaint in accordance with Art. 77 GDPR.

14.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST IN THE CONTEXT OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSES OF SUCH MARKETING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

15) Duration of storage of personal data

The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing and - if applicable - additionally by the respective statutory retention period (e.g. commercial and tax law retention periods).

When processing personal data on the basis of explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.

If statutory retention periods exist for data processed within the framework of legal or quasi-legal obligations on the basis of Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the retention periods have expired, provided it is no longer required for contract fulfillment or contract initiation and/or we no longer have a legitimate interest in continued storage.

When processing personal data on the basis of Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the assertion, exercise or defense of legal claims.

When processing personal data for direct marketing purposes on the basis of Art. 6 para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 para. 2 GDPR.

Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.

As of: 30.05.2026