Privacy policy

Privacy Policy

Table of Contents

Table of Contents. 1

We take data protection seriously. 2

1. Data controller 2

2. Data Protection Officer 2

3. Categories of personal data processed. 2

3.1 Categories of data by data subject group. 3

3.2 Other data processed. 3

3.3 Special categories of personal data (Art. 9 GDPR) 3

4. Legal bases for processing. 4

5. Recipients of your data. 4

5.1 Joint controllership (Art. 26 GDPR) 5

6. Retention period. 5

7. Data transfers to third countries. 6

8. Automatically stored data. 6

8.1 Server log files. 6

8.2 SSL/TLS encryption. 7

9. Cookies and services used. 7

9.1 Web analytics and tracking. 7

9.2 Newsletters and email marketing. 8

9.3 Technical services and security. 10

9.4 Social media plug-ins and integrations. 12

10. Orders in our online shop. 14

10.1 Payment methods and payment service providers. 14

10.2 Dispatch and delivery. 15

10.3 Returns, Cancellation and Warranty. 15

10.4 Uncompleted orders. 15

11. Contacting us. 15

12. Registration on the website. 15

13. Processing of personal data for marketing purposes. 16

13.1 Newsletters and promotional offers. 16

14. Automated decision-making, including profiling. 16

15. Necessity of providing personal data. 16

16. Our presence on social media. 17

17. Your rights as a data subject 18

17.1 Information on your right to object under Article 21 of the GDPR. 18

18. Data security. 19

19. Changes to this privacy policy. 19

 

We are serious about data protection.

The protection of your personal data is of particular importance to us. This privacy policy provides you with comprehensive information about the processing of your personal data within our organisation and about your rights under the European General Data Protection Regulation (GDPR) and supplementary national regulations.

1. Data controller

The data controller responsible for the processing of personal data within the meaning of Article 4(7) of the GDPR is:

Bavarian Caps GmbH

Donaupark 26

93309 Kelheim

Email: info@heronox.com

Telephone: 09441 208950

This privacy policy applies to the heronox brand’s online shop www.heronox.com.

2. Data Protection Officer

You can contact our external Data Protection Officer at:

Projekt 29 GmbH & Co. KG

Ostengasse 14

93047 Regensburg

Email: anfrage@projekt29.de

Tel.: 0941 2986930

3. Categories of personal data processed

We process personal data that we have received in the course of contract initiation, contract fulfilment, on the basis of consent, legal obligations or within the framework of the business relationship. Where you use one of our services, we generally only collect the data necessary to provide the respective service.

3.1 Categories of data by data subject group

Data subjects

Data processed

Customers

First name and surname, address, email address, telephone number, bank details, IP address, contract and order details

Job applicants

First name and surname, address, email address, telephone number, date of birth, details from CVs, references and other application documents

Employees

Master data, contract details, wage and salary details, social security details, working time records – see separate information for employees

Business partners

Company name, company registration number, VAT number, address, contact details of the contact person, bank details

Website visitors

IP address, browser type, operating system, time of access, referrer URL, pages viewed

Event participants

First name and surname, address, email address, photographs or video recordings from the event (where applicable)

3.2 Other data processed

In addition, depending on the business relationship, we process contract data, order data, turnover and transaction data, as well as customer and supplier histories. This is supplemented by marketing and sales data, electronic communication data such as IP addresses and login details, data from customer conversations and business relationships, and documentation of declarations of consent.

3.3 Special categories of personal data (Art. 9 GDPR)

Where we process special categories of personal data within the meaning of Article 9(1) of the GDPR (e.g. health data, data relating to religious beliefs, trade union membership, or information on severe disability), this is done exclusively on the basis of one of the exceptions set out in Article 9(2) of the GDPR. This includes, in particular, the explicit consent of the data subject (point (a)), the fulfilment of obligations under labour, social and social security law – for example, in the case of health data in an employment relationship in conjunction with Section 26(3) of the Federal Data Protection Act (BDSG) (point (b)) – and the protection of vital interests (point (c)).

3.4 Source of the data (Article 14 of the GDPR)

Where we collect personal data not directly from you but from other sources, we obtain it in particular from:

•         publicly accessible sources (e.g. commercial registers, registers of associations, population registers, insolvency registers and debtors’ registers, the press, the internet)

•         credit reference agencies and business information services

•         business partners, suppliers and intermediaries who provide us with your data for the purpose of initiating a contract

•         career portals and social media platforms as part of active recruitment (active sourcing) – only insofar as you have published your data there for professional purposes

We will inform you of the specific source upon request in accordance with Article 14(2)(f) of the GDPR.

4. Legal basis for processing

We process your data in accordance with the GDPR and supplementary national regulations:

Legal basis

Description

Article 6(1)(a) of the GDPR

Consent (e.g. newsletters, tracking cookies, publication of images)

Article 6(1)(b) of the GDPR

Fulfilment of (pre-)contractual obligations (e.g. orders, job applications, handling enquiries)

Article 6(1)(c) of the GDPR

Compliance with legal obligations (e.g. tax and commercial law retention obligations, anti-money laundering legislation)

Article 6(1)(d) of the GDPR

Protection of vital interests

Article 6(1)(f) of the GDPR

Legitimate interests (e.g. IT security, direct marketing, assertion of legal claims, intra-group reporting)

Article 9(2) of the GDPR

Processing of special categories of data (see section 3.3)

Section 26 of the Federal Data Protection Act

Processing of employees’ data for the purposes of the employment relationship

Section 25 of the TDDDG

Storage of and access to information on users’ devices (cookies, etc.)

5. Recipients of your data

As part of our business activities, we work with various external organisations. We only disclose personal data where this is necessary for the performance of a contract, where we are legally obliged to do so, where there is a legitimate interest, or where another legal basis permits such disclosure. When using data processors, we only disclose data on the basis of a valid data processing agreement in accordance with Article 28 of the GDPR.

Recipients or categories of recipients may include, in particular:

•         IT service providers for hosting, maintenance, support and IT security

•         Providers of email services, marketing automation and customer relationship management

•         Payment processors, banks and debt collection agencies

•         Shipping and logistics service providers

•         Analytics and tracking services

•         Credit reference agencies and business information services

•         Insurance companies, external advisers (tax advisers, auditors, solicitors)

•         Public authorities and courts where required by law

•         Affiliated companies within the group, where permitted

5.1 Joint controllership (Article 26 of the GDPR)

Where we process personal data jointly with other organisations, we have entered into an agreement with them in accordance with Article 26 of the GDPR. We will provide separate information on the key provisions of the agreement and the respective responsibilities. You may exercise your rights as a data subject independently of this vis-à-vis any of the joint controllers.

Joint controller: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The key provisions of the agreement are available at: https://www.facebook.com/legal/terms/page_controller_addendum

6. Retention period

We process and store your personal data only for as long as is necessary to fulfil the relevant purpose or as required by statutory retention obligations. The specific storage and retention periods are based on the following criteria:

Data category

Retention period

Contract and billing data

10 years after the end of the contract (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB))

Business correspondence

6 years (Section 257 of the German Commercial Code (HGB))

Applicant data (rejected applicants)

Usually 6 months after the conclusion of the recruitment process (for evidential purposes under the AGG); longer retention only with consent (talent pool)

Server log files

Anonymisation after 7 days at the latest (see section 8.1)

Cookie consents

Until revoked, but no longer than as specified by the consent tool used

Other data

Until the purpose of processing ceases to apply or until a legitimate request for erasure is made

 

If you make a legitimate request for erasure or withdraw your consent, your data will be erased, provided that there are no statutory retention obligations or legitimate interests that prevent this. Once these grounds no longer apply, the data will be erased.

7. Data transfers to third countries

As a general rule, no personal data is transferred to countries outside the European Union (EU) or the European Economic Area (EEA). However, if a transfer to a third country is nevertheless necessary in individual cases (e.g. when using certain service providers), this will take place exclusively on the basis of one of the following safeguards:

•         An adequacy decision by the European Commission pursuant to Article 45 of the GDPR (for the USA, currently based on the EU-US Data Privacy Framework in relation to certified organisations)

•         Standard contractual clauses of the European Commission pursuant to Article 46(2)(c) of the GDPR, supplemented by a risk assessment (Transfer Impact Assessment) and, where necessary, additional safeguards

•         Binding Corporate Rules in accordance with Article 47 of the GDPR

•         Your explicit consent in accordance with Article 49(1)(a) of the GDPR

8. Automatically stored data

8.1 Server log files

The provider of our website automatically collects and stores information in server log files that your browser transmits automatically. This includes the date and time of the request, the name of the file requested, the page from which the file was requested (referrer), the access status, the web browser and operating system used, the full IP address of the requesting computer, and the amount of data transferred.

This data is not combined with other data sources. Processing is carried out in accordance with Article 6(1)(f) of the GDPR on the basis of our legitimate interest in the stability and security of our website. For technical security reasons, this data is stored temporarily; after seven days at the latest, it is anonymised by truncating the IP address.

8.2 SSL/TLS encryption

For security reasons, our website uses SSL or TLS encryption. You can recognise an encrypted connection by ‘https://’ in the address bar and by the padlock icon in your browser.

9. Cookies and services used

Our website uses so-called cookies and similar technologies (e.g. LocalStorage, pixels). Cookies are small data packets that are stored on your device. Session cookies are automatically deleted at the end of your visit; persistent cookies remain stored until you delete them or your browser removes them automatically.

The storage of information on your device and access to information already stored are governed by Section 25 of the TDDDG. Insofar as their use is not technically essential, it takes place exclusively with your prior consent in accordance with Section 25(1) of the TDDDG. The subsequent processing of the personal data collected in this way is carried out on the basis of your consent in accordance with Article 6(1)(a) of the GDPR. Cookies that are technically essential and access in accordance with Section 25(2)(2) of the TDDDG are used on the basis of our legitimate interest in the technically fault-free provision of our services in accordance with Article 6(1)(f) of the GDPR.

You may withdraw any consent you have given at any time with effect for the future. The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.

You can configure your browser so that you are notified when cookies are set and only allow cookies on a case-by-case basis. If you disable cookies, the functionality of the website may be restricted.

9.1 Web analytics and tracking

Google Analytics (4)

This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited (‘Google’), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyse the behaviour of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the site, operating systems used and the user’s origin. This data is aggregated into a user ID and assigned to the website visitor’s respective device.

Furthermore, Google Analytics enables us, amongst other things, to record your mouse and scroll movements and clicks. Google Analytics also uses various modelling approaches to supplement the collected data sets and employs machine learning technologies in its data analysis.

Google Analytics uses technologies that enable the user to be recognised for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google regarding the use of this website is generally transferred to a Google server in the USA and stored there. The use of this service is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time.

The transfer of data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.

Google is also certified under the ‘EU-US Data Privacy Framework’ (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards.

Browser plug-in

You can prevent Google from collecting and processing your data by downloading and installing the browser plug-in available via the following link: https://tools.google.com/dlpage/gaoptout?hl=de. Further information on how Google Analytics handles user data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.

Google Tag Manager

We use Google Tag Manager on our website, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that enables us to manage website tags via a user interface. Tag Manager itself does not process any personal data; in particular, it does not create user profiles, store cookies or carry out its own analyses. It serves solely to manage and deploy other tools (e.g. tracking or statistics tools). However, these tools may themselves collect data under certain circumstances – you can find information on this in the relevant sections of this privacy policy.

When using Tag Manager, your IP address may be transferred to servers belonging to the parent company, Google LLC, in the USA. There is currently no adequacy decision from the European Commission regarding the USA. Data is therefore transferred on the basis of EU Standard Contractual Clauses and, where applicable, your consent, where required.

The use of Google Tag Manager is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in the technically flawless and efficient integration and management of third-party services on our website.

Further information: https://policies.google.com/privacy

9.2 Newsletters and email marketing

Mailjet

This website uses Mailjet to send newsletters. The provider is Mailgun Technologies Inc., 112 E Pecan Sr. #1135, San Antonio, Texas 78205, USA.

Mailjet is a service that enables, amongst other things, the organisation and analysis of newsletter distribution. The data you provide for the purpose of subscribing to the newsletter is stored on Mailjet’s servers.

With the help of Mailjet, we are able to analyse our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links, if any, have been clicked. In this way, we can determine, amongst other things, which links have been clicked particularly often.

We can also see whether certain pre-defined actions were carried out after the newsletter was opened or a link was clicked (conversion rate). For example, we can see whether you made a purchase after clicking a link in the newsletter.

Mailjet also enables us to categorise newsletter recipients into different groups (‘cluster’ them). Newsletter recipients can, for example, be categorised by age, gender or place of residence. This enables us to tailor the newsletters more effectively to the respective target groups. If you do not wish to be analysed by Mailjet, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message.

For detailed information on Mailjet’s features, please see the following link:

https://www.mailjet.de/funktion/.

Mailjet’s privacy policy can be found at:

https://www.mailjet.de/sicherheit-datenschutz/.

Data processing is carried out on the basis of your consent (Article 6(1)(a) of the GDPR). You may withdraw this consent at any time. The lawfulness of any data processing operations that have already taken place remains unaffected by the withdrawal.

Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses.

Further details can be found here:

https://www.mailjet.de/av-vertrag/.

The data you have provided to us for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter, and will be deleted from the newsletter distribution list once you have unsubscribed. Data stored by us for other purposes remains unaffected by this.

Once you have unsubscribed from the newsletter distribution list, your email address will be stored by us or the

newsletter service provider, where necessary, provided this is required to prevent future

mailings. The data from the blacklist is used solely for this purpose and is not combined with any other data. This serves both your interests and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). There is no time limit on storage on the blacklist . You may object to this storage provided that your interests override our legitimate interest.

We have entered into a data processing agreement (DPA) in accordance with Article 28 of the GDPR with the aforementioned provider. This is a contract required under data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

9.3 Technical Services and Security

Shopify

We host our website with Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter ‘Shopify’).

Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address as well as information about the device and browser you are using. Shopify is also used to analyse visitor numbers, visitor sources and customer behaviour, as well as to compile user statistics. When you make a purchase on our website, Shopify also collects your name, email address, delivery and billing addresses, payment details and other

Data relating to the purchase (e.g. telephone number, total amount spent, etc.). Shopify stores cookies in your browser for analytical purposes.

For further details, please refer to Shopify’s privacy policy:

https://www.shopify.de/legal/datenschutz.

The use of Shopify is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in ensuring that our website is presented as reliably as possible. Where consent has been sought, processing takes place exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.

We have entered into a data processing agreement (DPA) in accordance with Article 28 of the GDPR with the aforementioned provider. This is a contract required under data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Cloudflare

We use the ‘Cloudflare’ service. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter ‘Cloudflare’).

Cloudflare offers a globally distributed content delivery network with DNS. Technically, this means that the transfer of information between your browser and our website is routed via Cloudflare’s network. This enables Cloudflare to analyse the data traffic between your browser and our website and to act as a filter between our servers and potentially malicious data traffic from the internet. In doing so, Cloudflare may also use cookies or other technologies to recognise internet users; however, these are used solely for the purpose described here.

The use of Cloudflare is based on our legitimate interest in providing our website as error-free and secure as possible (Article 6(1)(f) of the GDPR).

Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here:

https://www.cloudflare.com/privacypolicy/.

Further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.

We have entered into a data processing agreement (DPA) in accordance with Article 28 of the GDPR with the aforementioned provider. This is a contract required under data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

jsDelivr CDN

This website uses a so-called “Content Delivery Network” (CDN) provided by jsDelivr.

A CDN is a service that enables content from our online offering – in particular large media files such as graphics or scripts – to be delivered more quickly via regionally distributed servers connected via the internet. User data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of the CDN.

To this end, the browser you are using must establish a connection to the CDN’s servers. As a result, the CDN becomes aware that our website has been accessed via your IP address.

This processing is carried out on the basis of our legitimate interests, namely the interest in the secure and efficient provision, analysis and optimisation of our online services in accordance with Article 6(1)(f) of the GDPR.

Further information can be found in jsDelivr’s privacy policy: https://www.jsdelivr.com/privacy-policy-jsdelivr-net/

Google APIs

We use Google’s application programming interfaces (APIs), for example to deliver embedded content. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you access the site, your IP address and technical information about your device are transmitted to the provider.

The transfer of personal data to the USA cannot be ruled out; the provider bases this on the adequacy decision regarding the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

The legal basis is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time via the cookie settings with effect for the future.

GStatic

We use the GStatic content delivery network to deliver static content such as scripts, images or fonts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you access the site, your IP address is transmitted to the provider. This is generally a technical component of another Google service.

The transfer of personal data to the USA cannot be ruled out; the provider bases this on the adequacy decision regarding the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

The legal basis is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time via the cookie settings with effect for the future.

9.4 Social media plug-ins and integrations

YouTube

On certain pages, we embed videos from the YouTube platform. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The entity responsible for the platform is YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA.

When you access a page containing an embedded video, a connection is established with YouTube’s servers. In the process, your IP address, as well as device and browser information, are processed, and cookies or similar identifiers are set. If you are logged in to YouTube, the provider may associate your usage behaviour with your account. For technical reasons, Google APIs and GStatic are also accessed alongside the videos.

The transfer of personal data to the USA cannot be ruled out; the provider bases this on the adequacy decision relating to the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

The legal basis is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time via the cookie settings with effect for the future.

For further details, please refer to the provider’s privacy policy: https://policies.google.com/privacy

Google Fonts

We incorporate fonts from the Google Fonts service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you visit a page, your browser loads the required font files from one of the provider’s servers. In doing so, your IP address is transmitted to the provider; according to the provider, the requests are logged but not combined with any other data.

The transfer of personal data to the USA cannot be ruled out; the provider bases this on the adequacy decision regarding the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

The legal basis is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time via the cookie settings with effect for the future.

For further details, please refer to the provider’s privacy policy: https://policies.google.com/privacy

Note on implementation: If the fonts are embedded locally on your own server, there is no transmission to the provider and therefore no obligation to obtain consent.

Google Ads

We use the Google Ads advertising network, including conversion tracking and remarketing. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Cookies are set and identifiers are processed to measure the effectiveness of our advertising and to display interest-based adverts to you on third-party websites and services. This results in the creation of usage profiles that are linked to your usage behaviour. We receive aggregated analyses from the provider and cannot identify individual users from them.

The transfer of personal data to the USA cannot be ruled out; the provider bases this on the adequacy decision regarding the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

The legal basis is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time via the cookie settings with effect for the future.

For further details, please refer to the provider’s privacy policy: https://policies.google.com/privacy

Meta / Facebook

We use services provided by Meta, in particular the Meta Pixel. The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

The Pixel tracks your interactions on our website (e.g. pages and products viewed, shopping basket, completion of an order) and, where applicable, associates them with your Meta account. This enables us to display adverts on Facebook and Instagram, create target groups (Custom Audiences) and measure the success of our advertising.

We and the provider are jointly responsible for the collection and transfer of data via the pixel (Article 26 of the GDPR); subsequent processing is carried out under the provider’s sole responsibility. The key provisions of the agreement are available at https://www.facebook.com/legal/controller_addendum

The transfer of personal data to the USA cannot be ruled out; the provider bases this on the adequacy decision regarding the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

The legal basis is your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time via the cookie settings with effect for the future.

For further details, please refer to the provider’s privacy policy: https://www.facebook.com/privacy/policy

10. Orders in our online shop

When you place an order in our online shop, we process the data necessary to establish and fulfil the contract of sale: first name and surname, delivery and billing addresses, email address, your telephone number (on a voluntary basis), and the order, payment and delivery details. The legal basis is Article 6(1)(b) of the GDPR; for the fulfilment of tax and commercial law obligations, Article 6(1)(c) of the GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).

The provision of this data is necessary for the conclusion of the contract; without it, we cannot accept or fulfil your order.

10.1 Payment methods and payment service providers

Depending on the payment method selected, we pass on the data required for processing to the relevant payment service provider. You usually enter payment details such as card or bank account details directly with the payment service provider; we do not receive this data, but only confirmation of the payment status. The legal basis is Article 6(1)(b) of the GDPR; with regard to the prevention of fraud and misuse, Article 6(1)(f) of the GDPR applies.

The relevant payment service provider processes your data, in part, under its own responsibility in accordance with its own privacy policy, in particular for payment processing, identity and credit checks in the case of purchase on account or instalment purchases, and for fraud prevention.

10.2 Dispatch and delivery

To arrange delivery of your order, we will pass on your name and delivery address to the contracted delivery company. The legal basis for this is Article 6(1)(b) of the GDPR. We will only pass on your email address or telephone number insofar as this is necessary for sending delivery notifications or to arrange a delivery time, and you have given your consent to this (Article 6(1)(a) of the GDPR) or there is a legitimate interest in ensuring smooth delivery (Article 6(1)(f) of the GDPR).

10.3 Returns, withdrawal and warranty

If you exercise your right of withdrawal, return goods or assert rights arising from defects, we will process the information required for this purpose, including your bank details for the refund. The legal basis is Article 6(1)(b) and (c) of the GDPR; for the defence against unjustified claims and the detection of misuse of the returns process, the legal basis is Article 6(1)(f) of the GDPR. The statutory retention periods apply to this data (see section 6).

10.4 Uncompleted orders

If you abandon the ordering process, the data you have already entered and the contents of your shopping basket will be temporarily stored so that you can continue the process. We will only send a reminder by email if you have consented to this (Article 6(1)(a) of the GDPR) or if the conditions of Section 7(3) of the Unfair Commercial Practices Act (UWG) are met; you may object to this at any time.

11. Contacting us

When you contact us, for example via the contact form, by email, telephone or via social media, the details of the person making the enquiry are processed to the extent necessary to respond to the enquiry and any requested actions. This may involve the processing of personal data such as name and address, contact details such as email address and telephone number, and content-related data. The legal basis is Article 6(1)(b) of the GDPR for contractual or pre-contractual enquiries, and Article 6(1)(f) of the GDPR on the basis of our legitimate interest in responding to your enquiry.

12. Registration on the website

You can register on our website to create a user account. In doing so, data such as your name, address, telephone number, email address and, where applicable, date of birth and bank details are collected. In addition, your IP address and the date and time of registration are stored to prevent misuse. The legal basis is Article 6(1)(b) of the GDPR (pre-contractual measures) and Article 6(1)(f) of the GDPR (prevention of misuse).

You undertake to treat your personal login details as confidential and not to make them accessible to any unauthorised third party. Registered users are free to amend or have the personal data provided during registration completely deleted at any time.

13. Processing of personal data for marketing purposes

You may object at any time to the use of your personal data for marketing purposes, either in full or in relation to specific measures, without incurring any costs other than the transmission costs in accordance with standard rates.

We are entitled, subject to the legal requirements of Section 7(3) of the Unfair Competition Act (UWG), to use the email address you provided when entering into the contract for direct marketing of our own similar goods or services. We draw your attention to this option and to your right to object at the time your email address is collected. You may object to this use at any time without incurring any costs other than the standard transmission charges. Every promotional email contains an unsubscribe link.

13.1 Newsletters and promotional offers

If you subscribe to our newsletter, we will process your email address and any further data you have voluntarily provided in order to send you information about our services, new products and special offers. Registration takes place via a double opt-in procedure: after registering, you will receive an email asking you to confirm your subscription. For verification purposes, we log the time of registration and confirmation, as well as the IP address used.

The legal basis is your consent under Article 6(1)(a) of the GDPR; for the logging, our legitimate interest in providing evidence of consent under Article 6(1)(f) of the GDPR applies. You can unsubscribe from the newsletter at any time via the unsubscribe link in every email or by sending us a message. To process your unsubscription, we store your email address in a block list.

14. Automated decision-making, including profiling

As a general rule, no decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you will be made (Article 22 of the GDPR). Should this be the case in individual instances (e.g. as part of a credit check, risk scoring or other automated procedures), we will inform you of this separately, as well as of the logic involved, the scope and the intended effects of such processing. In such cases, you have the right to request a review by a person, to set out your point of view and to contest the decision.

15. Necessity of providing personal data

As part of our business relationship, you must provide the personal data necessary for the establishment, performance and termination of the business relationship, as well as for the fulfilment of the associated contractual or statutory obligations. Without this data, we will generally not be able to enter into or perform a contract with you. Where statutory provisions (e.g. relating to tax, commercial or money laundering legislation) require the collection of certain data, we will draw your attention to this separately at the time of collection.

16. Our social media presence

We maintain corporate profiles on social media platforms to provide information about our services and to communicate with customers and prospective customers: Facebook and Instagram (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland) and TikTok (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland).

When you visit our websites, the relevant network operator also processes your usage data (in particular your IP address, device and browser information, and your interactions with our content) for its own purposes, notably for market research and advertising, and uses this data to create usage profiles. We have no influence over this processing and are technically unable to prevent it. The transfer of personal data to third countries cannot be ruled out; the provider bases this on the adequacy decision relating to the EU-US Data Privacy Framework or on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

The legal basis for the operation of the websites and the analysis of reach is our legitimate interest in public image and needs-based communication (Article 6(1)(f) of the GDPR); where the network operator obtains consent, Article 6(1)(a) of the GDPR applies.

We are jointly responsible with Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, for the Page Insights provided by Meta — summarised statistics on the use of our websites — (Article 26 of the GDPR). The key provisions of this agreement are available at https://www.facebook.com/legal/terms/page_controller_addendum

The provider of TikTok for users in the European Economic Area is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. According to the provider, data may be transferred to third countries outside the EEA — including the USA, Singapore and China — or made accessible from there; the provider bases this on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

If you contact us via the platforms (e.g. via comments or direct messages), we process your details to deal with your enquiry on the basis of Article 6(1)(b) or (f) of the GDPR. Posts that you publish yourself are visible to other users.

You may exercise your rights as a data subject both with us and with the relevant social media platform operator. We can only respond to a limited extent to enquiries regarding data processed exclusively by the social media platform operator and will forward such enquiries where necessary.

17. Your rights as a data subject

You have the right at any time to access, rectify, erase or restrict the processing of your stored data, the right to object to the processing, as well as the right to data portability and the right to lodge a complaint in accordance with the provisions of data protection law.

Right

Description

Right of access (Art. 15)

You may request information as to whether and to what extent we process your data.

Rectification (Art. 16)

You may request the rectification of inaccurate data or the completion of incomplete data.

Erasure (Art. 17)

You may request the erasure of your data, provided that there are no statutory retention obligations preventing this.

Restriction (Art. 18)

You may request the restriction of processing, for example if you dispute the accuracy of the data.

Data portability (Art. 20)

You may request that we provide you with your data in a structured, commonly used, machine-readable format.

Objection (Art. 21)

See separate information under section 17.1

Withdrawal (Art. 7(3))

You may withdraw any consent you have given at any time with effect for the future.

Complaints (Art. 77)

You have the right to lodge a complaint with a data protection supervisory authority.

 

In case of doubt, we may request additional information to verify your identity.

17.1 Information on your right to object under Article 21 of the GDPR

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where your personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

18. Data security

We have implemented comprehensive technical and organisational measures in accordance with Article 32 of the GDPR to protect your personal data against loss, destruction, manipulation and unauthorised access. All employees and service providers working on our behalf are bound by the applicable data protection laws and are obliged to maintain confidentiality. Personal data is encrypted during transmission. Our security measures are continuously reviewed and updated to reflect the latest technological standards.

19. Changes to this Privacy Policy

We reserve the right to amend this privacy policy to ensure it remains in line with current legal requirements and technical developments. Please ensure that you have the latest version. We will announce any significant changes on our website.

Last updated: September 2026